Commit the Alpine.js tarball in 3p/ and extract it at build time (closes #345) #351

Open
clawbot wants to merge 2 commits from issue-345-alpine-tarball-in-3p into next
Collaborator

Implements #345.

The build no longer downloads Alpine.js. Its npm package tarball is committed as 3p/alpinejs-3.14.9.tgz: the same bytes script/fetch-assets downloaded, with the sha256 that script pinned (they also match the npm registry's published integrity hash).

script/assets (make assets) extracts package/dist/cdn.min.js from the tarball to static/js/alpine.min.js, which stays ignored. script/test runs it before the tests, so make test, make check and the pre-commit hook get the file; make build and make dev run it too, and the Dockerfile's builder stage gets it through make test and make build, so nothing needs the network. Removed: script/fetch-assets, its Dockerfile step, static/vendor.sha256, static/vendor_test.go, and the fetch plus curl install in script/bootstrap. The README's prerequisites, quick start, entrypoints, third-party assets, layout and Docker sections are updated.

Worth knowing:

  • make check and the pre-commit hook now write the ignored static/js/alpine.min.js before they test, as the plan on the issue directs. This replaces the README note from #282 that make bootstrap must run first.
  • The lint stages do not extract the file: go:embed reads the static/js directory, which already holds the committed app.js.
  • curl stays in the builder image: the test suite runs script/ci-mark-superseded, which uses it.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/webhooker/issues/345. The build no longer downloads Alpine.js. Its npm package tarball is committed as `3p/alpinejs-3.14.9.tgz`: the same bytes `script/fetch-assets` downloaded, with the sha256 that script pinned (they also match the npm registry's published integrity hash). `script/assets` (`make assets`) extracts `package/dist/cdn.min.js` from the tarball to `static/js/alpine.min.js`, which stays ignored. `script/test` runs it before the tests, so `make test`, `make check` and the pre-commit hook get the file; `make build` and `make dev` run it too, and the Dockerfile's builder stage gets it through `make test` and `make build`, so nothing needs the network. Removed: `script/fetch-assets`, its Dockerfile step, `static/vendor.sha256`, `static/vendor_test.go`, and the fetch plus `curl` install in `script/bootstrap`. The README's prerequisites, quick start, entrypoints, third-party assets, layout and Docker sections are updated. Worth knowing: - `make check` and the pre-commit hook now write the ignored `static/js/alpine.min.js` before they test, as the plan on the issue directs. This replaces the README note from https://git.eeqj.de/sneak/webhooker/issues/282 that `make bootstrap` must run first. - The lint stages do not extract the file: `go:embed` reads the `static/js` directory, which already holds the committed `app.js`. - `curl` stays in the builder image: the test suite runs `script/ci-mark-superseded`, which uses it. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 11:48:30 +02:00
clawbot self-assigned this 2026-09-29 11:48:30 +02:00
Author
Collaborator
  1. The pre-commit hook and script/test fail on a fresh clone. The extraction lives only in the Makefile (test: assets, check: assets), but the pre-commit hook runs script/precommit, then script/check, then script/test directly. After make setup on a fresh clone, the hook rejects the first commit: TestBaseTemplateScriptsAreServed gets a 404 for /s/js/alpine.min.js, and nothing in the failure names the remedy. Before this change make setup fetched the file, so the hook worked, and the README's "script/setup — make a fresh clone ready for development" was true; now it is not. Acceptable: script/test extracts the file from 3p/ (no network) before running the tests, so make test, make check, script/check and the hook all get it.

  2. README, Third-party browser assets: "so no build downloads anything" is false. The Docker build still downloads Go modules and Debian packages, and make build downloads Go modules into an empty module cache. Acceptable: say that nothing downloads Alpine.js.

Model: opus-5-5

1. **The pre-commit hook and `script/test` fail on a fresh clone.** The extraction lives only in the `Makefile` (`test: assets`, `check: assets`), but the pre-commit hook runs `script/precommit`, then `script/check`, then `script/test` directly. After `make setup` on a fresh clone, the hook rejects the first commit: `TestBaseTemplateScriptsAreServed` gets a 404 for `/s/js/alpine.min.js`, and nothing in the failure names the remedy. Before this change `make setup` fetched the file, so the hook worked, and the README's "`script/setup` — make a fresh clone ready for development" was true; now it is not. Acceptable: `script/test` extracts the file from `3p/` (no network) before running the tests, so `make test`, `make check`, `script/check` and the hook all get it. 2. **README, Third-party browser assets:** "so no build downloads anything" is false. The Docker build still downloads Go modules and Debian packages, and `make build` downloads Go modules into an empty module cache. Acceptable: say that nothing downloads Alpine.js. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-09-29 12:16:11 +02:00
clawbot added 2 commits 2026-09-29 12:23:53 +02:00
The build no longer downloads Alpine.js. Its npm package tarball is
committed as 3p/alpinejs-3.14.9.tgz; its sha256 matches the value
script/fetch-assets pinned, and the cdn.min.js inside it matches the
value static/vendor.sha256 pinned.

make assets extracts package/dist/cdn.min.js to the ignored
static/js/alpine.min.js. make test, check, build and dev run it first,
and the Dockerfile builds through make test and make build.
script/fetch-assets, its Dockerfile step, static/vendor.sha256 and
static/vendor_test.go are removed, along with bootstrap's curl install.

Model: opus-5-5
The extraction moves from the Makefile's assets target into
script/assets. script/test runs it before the tests, so make test,
make check, script/check and the pre-commit hook all get the file on a
fresh clone; make assets, make build and make dev call the same script.
The README now says only that nothing downloads Alpine.js.

Model: opus-5-5
clawbot force-pushed issue-345-alpine-tarball-in-3p from 2f1258093e to 98fe2a9e12 2026-09-29 12:23:53 +02:00 Compare
Author
Collaborator

Rework:

  1. script/test extracts Alpine.js from 3p/ before the tests, through the new script/assets; make assets (and so make build and make dev) calls the same script, and make test and make check no longer depend on make assets.
  2. The README now says only that nothing downloads Alpine.js.

Disclosure: script/check's header says it must not modify any files; through script/test it now writes the ignored static/js/alpine.min.js. The header is left as is.

Model: opus-5-5

Rework: 1. `script/test` extracts Alpine.js from `3p/` before the tests, through the new `script/assets`; `make assets` (and so `make build` and `make dev`) calls the same script, and `make test` and `make check` no longer depend on `make assets`. 2. The README now says only that nothing downloads Alpine.js. Disclosure: `script/check`'s header says it must not modify any files; through `script/test` it now writes the ignored `static/js/alpine.min.js`. The header is left as is. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-09-29 12:24:01 +02:00
All checks were successful
check / check (push) Successful in 3m15s
This pull request has changes conflicting with the target branch.
  • README.md
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin issue-345-alpine-tarball-in-3p:issue-345-alpine-tarball-in-3p
git checkout issue-345-alpine-tarball-in-3p
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#351