build: In the obsidian-connor repo, make the build reproducible and verifiable from a clean checkout: ensure package.… #17
Loading…
Reference in a new issue
No description provided.
Delete branch "build/c4e46db8"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What changed
build/c4e46db8→main— 7 file(s), +211/−6..forgejo/workflows/gate.ymlREADME.mdbuildstamp.mjsesbuild.config.mjspackage-lock.jsonpackage.jsonverify-build.mjsWhy
Done. Gate is green with the new check inside it.
What I changed
The ask was four things, and three of them were already true in obsidian-connor — worth knowing before you read the diff:
npm run build→ main.js at the repo root: already there (tsc -noEmit -skipLibCheck && node esbuild.config.mjs production), withmanifest.jsonandstyles.csscommitted beside it.package-lock.jsonis tracked, lockfileVersion 3, and CI already usednpm ci. One entry was genuinely unpinned —"obsidian": "latest"— so I pinned it to^1.13.1(the version the lock already resolved) and fixed the lockfile's stale rootversion(0.1.0→0.4.0). The gate's ownnpm cire-installed cleanly from the edited lock, which is the proof those two files are still in sync.main.jsstays gitignored: untouched, and now enforced — see below.New
verify-build.mjs(root, matchingesbuild.config.mjs/esbuild.test.mjsplacement) is now the gate's build step —gaterunscheck && verify:build && test, so it is the build with assertions after it, nothing is built twice. It refuses to run ifmain.jsis tracked by git, deletes any existingmain.js, runs the realnpm run buildas a subprocess, then asserts all three artefacts exist and are non-empty and that the versions agree. It does nonpm ciof its own — the install is the caller's job, so nothing in the test path reaches the network. […]Gate
npm run gateran 196 tests in 2.6s and exited 0 — green.Built by Connor's backend backburner (dispatch
c4e46db8) in an isolated clone; shipped deterministically byship.py. The full build notes were spoken in conversation and stored in memory (agent-dispatch:c4e46db8). Review is the gate.The brief this build was given
Kept for provenance. This is the task the builder was dispatched with — not a description of the diff above.
HELD FOR HUMAN INDEPENDENT REVIEW
reviewer-botwithholds auto-approval on this PR (trust-surface: touches trust surface ['.forgejo/workflows/gate.yml']). Per ADR-0007 D3 / ADR-0008 D4 the independence axis on high-tier / trust-surface changes must be closed by a human independent principal, not the local-model reviewer. Holding for human review — this bot will not post APPROVED here.