4 Commits
Author SHA1 Message Date
clawbot 98fe2a9e12 Extract Alpine.js in script/test so the pre-commit hook works
check / check (push) Successful in 3m15s
The extraction moves from the Makefile's assets target into
script/assets. script/test runs it before the tests, so make test,
make check, script/check and the pre-commit hook all get the file on a
fresh clone; make assets, make build and make dev call the same script.
The README now says only that nothing downloads Alpine.js.

Model: opus-5-5
2026-09-29 10:21:23 +00:00
clawbot 4df11f5de8 Commit the Alpine.js tarball in 3p/ and extract it at build time (closes #345)
The build no longer downloads Alpine.js. Its npm package tarball is
committed as 3p/alpinejs-3.14.9.tgz; its sha256 matches the value
script/fetch-assets pinned, and the cdn.min.js inside it matches the
value static/vendor.sha256 pinned.

make assets extracts package/dist/cdn.min.js to the ignored
static/js/alpine.min.js. make test, check, build and dev run it first,
and the Dockerfile builds through make test and make build.
script/fetch-assets, its Dockerfile step, static/vendor.sha256 and
static/vendor_test.go are removed, along with bootstrap's curl install.

Model: opus-5-5
2026-09-29 10:19:37 +00:00
sneak 8ad2a86e4b Sneak/testdeploy (#356)
check / check (push) Successful in 11s
Reviewed-on: #356
2026-09-29 12:01:33 +02:00
sneak a891b726e5 Milestone: next into main (#342)
check / check (push) Successful in 9s
Reviewed-on: #342
2026-09-29 11:53:19 +02:00
5 changed files with 42 additions and 25 deletions
+1 -1
View File
@@ -51,7 +51,7 @@ RUN go mod download
# the lint stage above. # the lint stage above.
COPY . . COPY . .
# Run tests and build. Both first run `make assets`, which extracts Alpine.js # Run tests and build. Both first run script/assets, which extracts Alpine.js
# from its tarball in 3p/. # from its tarball in 3p/.
RUN make test RUN make test
+3 -6
View File
@@ -27,13 +27,10 @@ bootstrap:
setup: setup:
@script/setup @script/setup
# Alpine.js is committed as its npm package tarball in 3p/. This extracts
# the browser build from it to where go:embed reads it; the extracted file
# is not committed.
assets: assets:
tar -xzOf 3p/alpinejs-3.14.9.tgz package/dist/cdn.min.js >static/js/alpine.min.js @script/assets
test: assets test:
@script/test @script/test
lint: lint:
@@ -45,7 +42,7 @@ fmt:
fmt-check: fmt-check:
@script/fmt-check @script/fmt-check
check: assets check:
@script/check @script/check
build: assets build: assets
+21 -18
View File
@@ -1247,16 +1247,16 @@ What that means for an operator:
This repository adheres to the This repository adheres to the
[Scripts to Rule Them All](https://github.com/github/scripts-to-rule-them-all) [Scripts to Rule Them All](https://github.com/github/scripts-to-rule-them-all)
standard: normalized scripts in `script/` are the entrypoints for the standard: normalized scripts in `script/` are the entrypoints for the
development workflow. Nine of the Makefile's seventeen targets are thin development workflow. Ten of the Makefile's seventeen targets are thin
shims that call them; `assets`, `build`, `run`, `dev`, `deps`, `clean`, shims that call them; `build`, `run`, `dev`, `deps`, `clean`, `css` and
`css` and `version` are inline commands with no script behind them, `version` are inline commands with no script behind them, though `build`
though `build` and `version` both take their value from and `version` both take their value from `script/version`.
`script/version`.
`make test`, `make check`, `make build` and `make dev` each run `script/test`, `make build` and `make dev` each run `script/assets`
`make assets` first, which writes the ignored `static/js/alpine.min.js` first, which writes the ignored `static/js/alpine.min.js` (see
(see [Third-party browser assets](#third-party-browser-assets)), so [Third-party browser assets](#third-party-browser-assets)), so
`make check` works on a fresh clone without a separate setup step. `make test`, `make check` and the pre-commit hook work on a fresh clone
without a separate step.
We provide: We provide:
@@ -1264,6 +1264,8 @@ We provide:
- `script/setup` — make a fresh clone ready for development - `script/setup` — make a fresh clone ready for development
(bootstrap, then install-precommit) (bootstrap, then install-precommit)
- `script/projectname` — output the project name ("webhooker") - `script/projectname` — output the project name ("webhooker")
- `script/assets` — extract Alpine.js from its tarball in `3p/` (see
[Third-party browser assets](#third-party-browser-assets))
- `script/test` — run the test suite - `script/test` — run the test suite
- `script/lint` — run golangci-lint in Docker (see Linting below) - `script/lint` — run golangci-lint in Docker (see Linting below)
- `script/fmt` — format all code (writes) - `script/fmt` — format all code (writes)
@@ -1292,19 +1294,18 @@ publishes it. It is a dependency, not this repo's build output, so
The directory is `3p/` rather than `vendor/` because Go treats a root The directory is `3p/` rather than `vendor/` because Go treats a root
`vendor/` directory as its module vendor directory. `vendor/` directory as its module vendor directory.
`make assets` extracts the browser build, `package/dist/cdn.min.js`, from the `script/assets` (`make assets`) extracts the browser build,
tarball to `static/js/alpine.min.js`, where `go:embed` picks it up. `package/dist/cdn.min.js`, from the tarball to `static/js/alpine.min.js`,
`make test`, `make check`, `make build` and `make dev` run it first, and the where `go:embed` picks it up. `script/test`, `make build` and `make dev` run
Dockerfile builds through them, so no build downloads anything. The extracted it first, and the Dockerfile builds through `make test` and `make build`, so
file is not committed, and `.dockerignore` keeps any host copy out of the nothing downloads Alpine.js. The extracted file is not committed, and
build context. `.dockerignore` keeps any host copy out of the build context.
To move to a new version: download To move to a new version: download
`https://registry.npmjs.org/alpinejs/-/alpinejs-<version>.tgz`, check it `https://registry.npmjs.org/alpinejs/-/alpinejs-<version>.tgz`, check it
against the `dist.integrity` hash listed at against the `dist.integrity` hash listed at
`https://registry.npmjs.org/alpinejs/<version>`, replace the tarball in `3p/` `https://registry.npmjs.org/alpinejs/<version>`, replace the tarball in `3p/`
with it, update its file name in the Makefile's `assets` target, and run with it, update its file name in `script/assets`, and run `make check`.
`make check`.
## Rationale ## Rationale
@@ -2883,7 +2884,7 @@ webhooker/
├── script/ # Scripts to Rule Them All entrypoints ├── script/ # Scripts to Rule Them All entrypoints
├── Dockerfile # Three stages: lint, test+build, Alpine runtime ├── Dockerfile # Three stages: lint, test+build, Alpine runtime
├── Dockerfile.lint # Lint-only image built by script/lint ├── Dockerfile.lint # Lint-only image built by script/lint
├── Makefile # 9 of 17 targets shim script/; 8 are inline ├── Makefile # 10 of 17 targets shim script/; 7 are inline
├── go.mod / go.sum ├── go.mod / go.sum
└── .golangci.yml # Linter configuration └── .golangci.yml # Linter configuration
``` ```
@@ -3276,3 +3277,5 @@ MIT
## Author ## Author
[@sneak](https://sneak.berlin) [@sneak](https://sneak.berlin)
Executable
+16
View File
@@ -0,0 +1,16 @@
#!/bin/sh
# script/assets: extract Alpine.js from its npm package tarball, committed
# in 3p/, to static/js/alpine.min.js, where go:embed reads it. The
# extracted file is not committed. script/test, make build and make dev run
# this first.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
tar -xzOf 3p/alpinejs-3.14.9.tgz package/dist/cdn.min.js \
>static/js/alpine.min.js
}
main "$@"
+1
View File
@@ -28,6 +28,7 @@ ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() { main() {
cd "$ROOT" cd "$ROOT"
"$ROOT/script/assets"
go test -v -race -timeout 90s ./... go test -v -race -timeout 90s ./...
} }