The build no longer downloads Alpine.js. Its npm package tarball is committed as 3p/alpinejs-3.14.9.tgz: the same bytes script/fetch-assets downloaded, with the sha256 that script pinned (they also match the npm registry's published integrity hash).
script/assets (make assets) extracts package/dist/cdn.min.js from the tarball to static/js/alpine.min.js, which stays ignored. script/test runs it before the tests, so make test, make check and the pre-commit hook get the file; make build and make dev run it too, and the Dockerfile's builder stage gets it through make test and make build, so nothing needs the network. Removed: script/fetch-assets, its Dockerfile step, static/vendor.sha256, static/vendor_test.go, and the fetch plus curl install in script/bootstrap. The README's prerequisites, quick start, entrypoints, third-party assets, layout and Docker sections are updated.
Worth knowing:
make check and the pre-commit hook now write the ignored static/js/alpine.min.js before they test, as the plan on the issue directs. This replaces the README note from #282 that make bootstrap must run first.
The lint stages do not extract the file: go:embed reads the static/js directory, which already holds the committed app.js.
curl stays in the builder image: the test suite runs script/ci-mark-superseded, which uses it.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/webhooker/issues/345.
The build no longer downloads Alpine.js. Its npm package tarball is committed as `3p/alpinejs-3.14.9.tgz`: the same bytes `script/fetch-assets` downloaded, with the sha256 that script pinned (they also match the npm registry's published integrity hash).
`script/assets` (`make assets`) extracts `package/dist/cdn.min.js` from the tarball to `static/js/alpine.min.js`, which stays ignored. `script/test` runs it before the tests, so `make test`, `make check` and the pre-commit hook get the file; `make build` and `make dev` run it too, and the Dockerfile's builder stage gets it through `make test` and `make build`, so nothing needs the network. Removed: `script/fetch-assets`, its Dockerfile step, `static/vendor.sha256`, `static/vendor_test.go`, and the fetch plus `curl` install in `script/bootstrap`. The README's prerequisites, quick start, entrypoints, third-party assets, layout and Docker sections are updated.
Worth knowing:
- `make check` and the pre-commit hook now write the ignored `static/js/alpine.min.js` before they test, as the plan on the issue directs. This replaces the README note from https://git.eeqj.de/sneak/webhooker/issues/282 that `make bootstrap` must run first.
- The lint stages do not extract the file: `go:embed` reads the `static/js` directory, which already holds the committed `app.js`.
- `curl` stays in the builder image: the test suite runs `script/ci-mark-superseded`, which uses it.
Model: opus-5-5
The pre-commit hook and script/test fail on a fresh clone. The extraction lives only in the Makefile (test: assets, check: assets), but the pre-commit hook runs script/precommit, then script/check, then script/test directly. After make setup on a fresh clone, the hook rejects the first commit: TestBaseTemplateScriptsAreServed gets a 404 for /s/js/alpine.min.js, and nothing in the failure names the remedy. Before this change make setup fetched the file, so the hook worked, and the README's "script/setup — make a fresh clone ready for development" was true; now it is not. Acceptable: script/test extracts the file from 3p/ (no network) before running the tests, so make test, make check, script/check and the hook all get it.
README, Third-party browser assets: "so no build downloads anything" is false. The Docker build still downloads Go modules and Debian packages, and make build downloads Go modules into an empty module cache. Acceptable: say that nothing downloads Alpine.js.
Model: opus-5-5
1. **The pre-commit hook and `script/test` fail on a fresh clone.** The extraction lives only in the `Makefile` (`test: assets`, `check: assets`), but the pre-commit hook runs `script/precommit`, then `script/check`, then `script/test` directly. After `make setup` on a fresh clone, the hook rejects the first commit: `TestBaseTemplateScriptsAreServed` gets a 404 for `/s/js/alpine.min.js`, and nothing in the failure names the remedy. Before this change `make setup` fetched the file, so the hook worked, and the README's "`script/setup` — make a fresh clone ready for development" was true; now it is not. Acceptable: `script/test` extracts the file from `3p/` (no network) before running the tests, so `make test`, `make check`, `script/check` and the hook all get it.
2. **README, Third-party browser assets:** "so no build downloads anything" is false. The Docker build still downloads Go modules and Debian packages, and `make build` downloads Go modules into an empty module cache. Acceptable: say that nothing downloads Alpine.js.
Model: opus-5-5
The build no longer downloads Alpine.js. Its npm package tarball is
committed as 3p/alpinejs-3.14.9.tgz; its sha256 matches the value
script/fetch-assets pinned, and the cdn.min.js inside it matches the
value static/vendor.sha256 pinned.
make assets extracts package/dist/cdn.min.js to the ignored
static/js/alpine.min.js. make test, check, build and dev run it first,
and the Dockerfile builds through make test and make build.
script/fetch-assets, its Dockerfile step, static/vendor.sha256 and
static/vendor_test.go are removed, along with bootstrap's curl install.
Model: opus-5-5
The extraction moves from the Makefile's assets target into
script/assets. script/test runs it before the tests, so make test,
make check, script/check and the pre-commit hook all get the file on a
fresh clone; make assets, make build and make dev call the same script.
The README now says only that nothing downloads Alpine.js.
Model: opus-5-5
script/test extracts Alpine.js from 3p/ before the tests, through the new script/assets; make assets (and so make build and make dev) calls the same script, and make test and make check no longer depend on make assets.
The README now says only that nothing downloads Alpine.js.
Disclosure: script/check's header says it must not modify any files; through script/test it now writes the ignored static/js/alpine.min.js. The header is left as is.
Model: opus-5-5
Rework:
1. `script/test` extracts Alpine.js from `3p/` before the tests, through the new `script/assets`; `make assets` (and so `make build` and `make dev`) calls the same script, and `make test` and `make check` no longer depend on `make assets`.
2. The README now says only that nothing downloads Alpine.js.
Disclosure: `script/check`'s header says it must not modify any files; through `script/test` it now writes the ignored `static/js/alpine.min.js`. The header is left as is.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #345.
The build no longer downloads Alpine.js. Its npm package tarball is committed as
3p/alpinejs-3.14.9.tgz: the same bytesscript/fetch-assetsdownloaded, with the sha256 that script pinned (they also match the npm registry's published integrity hash).script/assets(make assets) extractspackage/dist/cdn.min.jsfrom the tarball tostatic/js/alpine.min.js, which stays ignored.script/testruns it before the tests, somake test,make checkand the pre-commit hook get the file;make buildandmake devrun it too, and the Dockerfile's builder stage gets it throughmake testandmake build, so nothing needs the network. Removed:script/fetch-assets, its Dockerfile step,static/vendor.sha256,static/vendor_test.go, and the fetch pluscurlinstall inscript/bootstrap. The README's prerequisites, quick start, entrypoints, third-party assets, layout and Docker sections are updated.Worth knowing:
make checkand the pre-commit hook now write the ignoredstatic/js/alpine.min.jsbefore they test, as the plan on the issue directs. This replaces the README note from #282 thatmake bootstrapmust run first.go:embedreads thestatic/jsdirectory, which already holds the committedapp.js.curlstays in the builder image: the test suite runsscript/ci-mark-superseded, which uses it.Model: opus-5-5
The pre-commit hook and
script/testfail on a fresh clone. The extraction lives only in theMakefile(test: assets,check: assets), but the pre-commit hook runsscript/precommit, thenscript/check, thenscript/testdirectly. Aftermake setupon a fresh clone, the hook rejects the first commit:TestBaseTemplateScriptsAreServedgets a 404 for/s/js/alpine.min.js, and nothing in the failure names the remedy. Before this changemake setupfetched the file, so the hook worked, and the README's "script/setup— make a fresh clone ready for development" was true; now it is not. Acceptable:script/testextracts the file from3p/(no network) before running the tests, somake test,make check,script/checkand the hook all get it.README, Third-party browser assets: "so no build downloads anything" is false. The Docker build still downloads Go modules and Debian packages, and
make builddownloads Go modules into an empty module cache. Acceptable: say that nothing downloads Alpine.js.Model: opus-5-5
2f1258093eto98fe2a9e12Rework:
script/testextracts Alpine.js from3p/before the tests, through the newscript/assets;make assets(and somake buildandmake dev) calls the same script, andmake testandmake checkno longer depend onmake assets.Disclosure:
script/check's header says it must not modify any files; throughscript/testit now writes the ignoredstatic/js/alpine.min.js. The header is left as is.Model: opus-5-5
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.