app

Local-first trade for farms and co-ops
git clone https://radroots.dev/git/app.git
Log | Files | Refs | README | LICENSE

commit 281c5081904857399701d8b37132bebc6faade09
parent f7de844fc6c3833faa31e42ac7abf287d18fe32b
Author: triesap <tyson@radroots.org>
Date:   Thu, 13 Aug 2026 15:16:42 +0000

deps: admit HarvestCircle design assets

- add version-aligned Compose animation and resource APIs
- own exact Inter font binaries with OFL notices and digests
- verify design dependency checksums and license reports
- keep Material3 platformtools JS and Wasm outside the design graph

Diffstat:
ALICENSES/OFL-1.1.txt | 92+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
MMakefile | 4++--
MNOTICE | 5+++++
Aapp/design_system/src/commonMain/composeResources/files/licenses/inter-OFL-1.1.txt | 92+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Aapp/design_system/src/commonMain/composeResources/font/inter_bold.ttf | 0
Aapp/design_system/src/commonMain/composeResources/font/inter_medium.ttf | 0
Aapp/design_system/src/commonMain/composeResources/font/inter_regular.ttf | 0
Aapp/design_system/src/commonMain/composeResources/font/inter_semibold.ttf | 0
Mbuild-logic/plugins/src/main/kotlin/org/harvestcircle/buildlogic/plugins/DesktopDesignKmp.kt | 33+++++++++++++++++++++++++++++++++
Mbuild-logic/plugins/src/main/kotlin/org/harvestcircle/buildlogic/plugins/HarvestCircleDesignSystemPlugin.kt | 8++++++++
Mgradle/libs.versions.toml | 2++
Mgradle/verification-metadata.xml | 22++++++++++++++++++++++
Mtools/xtask/Cargo.lock | 86+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Mtools/xtask/Cargo.toml | 3+++
Mtools/xtask/src/lib.rs | 57+++++++++++++++++++++++++++++++++++++++++++++++++++++++++
15 files changed, 402 insertions(+), 2 deletions(-)

diff --git a/LICENSES/OFL-1.1.txt b/LICENSES/OFL-1.1.txt @@ -0,0 +1,92 @@ +Copyright (c) 2016 The Inter Project Authors (https://github.com/rsms/inter) + +This Font Software is licensed under the SIL Open Font License, Version 1.1. +This license is copied below, and is also available with a FAQ at: +http://scripts.sil.org/OFL + +----------------------------------------------------------- +SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007 +----------------------------------------------------------- + +PREAMBLE +The goals of the Open Font License (OFL) are to stimulate worldwide +development of collaborative font projects, to support the font creation +efforts of academic and linguistic communities, and to provide a free and +open framework in which fonts may be shared and improved in partnership +with others. + +The OFL allows the licensed fonts to be used, studied, modified and +redistributed freely as long as they are not sold by themselves. The +fonts, including any derivative works, can be bundled, embedded, +redistributed and/or sold with any software provided that any reserved +names are not used by derivative works. The fonts and derivatives, +however, cannot be released under any other type of license. The +requirement for fonts to remain under this license does not apply +to any document created using the fonts or their derivatives. + +DEFINITIONS +"Font Software" refers to the set of files released by the Copyright +Holder(s) under this license and clearly marked as such. This may +include source files, build scripts and documentation. + +"Reserved Font Name" refers to any names specified as such after the +copyright statement(s). + +"Original Version" refers to the collection of Font Software components as +distributed by the Copyright Holder(s). + +"Modified Version" refers to any derivative made by adding to, deleting, +or substituting -- in part or in whole -- any of the components of the +Original Version, by changing formats or by porting the Font Software to a +new environment. + +"Author" refers to any designer, engineer, programmer, technical +writer or other person who contributed to the Font Software. + +PERMISSION AND CONDITIONS +Permission is hereby granted, free of charge, to any person obtaining +a copy of the Font Software, to use, study, copy, merge, embed, modify, +redistribute, and sell modified and unmodified copies of the Font Software, +subject to the following conditions: + +1) Neither the Font Software nor any of its individual components, +in Original or Modified Versions, may be sold by itself. + +2) Original or Modified Versions of the Font Software may be bundled, +redistributed and/or sold with any software, provided that each copy +contains the above copyright notice and this license. These can be +included either as stand-alone text files, human-readable headers or +in the appropriate machine-readable metadata fields within text or +binary files as long as those fields can be easily viewed by the user. + +3) No Modified Version of the Font Software may use the Reserved Font +Name(s) unless explicit written permission is granted by the corresponding +Copyright Holder. This restriction only applies to the primary font name as +presented to the users. + +4) The name(s) of the Copyright Holder(s) or the Author(s) of the Font +Software shall not be used to promote, endorse or advertise any +Modified Version, except to acknowledge the contribution(s) of the +Copyright Holder(s) and the Author(s) or with their explicit written +permission. + +5) The Font Software, modified or unmodified, in part or in whole, +must be distributed entirely under this license, and must not be +distributed under any other license. The requirement for fonts to +remain under this license does not apply to any document created using +the Font Software. + +TERMINATION +This license becomes null and void if any of the above conditions are not +met. + +DISCLAIMER +THE FONT SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT +OF COPYRIGHT, PATENT, TRADEMARK, OR OTHER RIGHT. IN NO EVENT SHALL THE +COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, +INCLUDING ANY GENERAL, SPECIAL, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL +DAMAGES, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING +FROM, OUT OF THE USE OR INABILITY TO USE THE FONT SOFTWARE OR FROM OTHER +DEALINGS IN THE FONT SOFTWARE. diff --git a/Makefile b/Makefile @@ -99,11 +99,11 @@ run: doctor audit: doctor $(BUILD_RUNNER) $(CARGO) audit --file core/Cargo.lock $(BUILD_RUNNER) $(CARGO) deny --manifest-path $(CARGO_MANIFEST) check --config core/deny.toml advisories - $(BUILD_RUNNER) $(GRADLE) --no-daemon --no-configuration-cache :app:desktop:dependencyCheckAnalyze + $(BUILD_RUNNER) $(GRADLE) --no-daemon --no-configuration-cache :app:desktop:dependencyCheckAnalyze :app:design_system:dependencyCheckAnalyze :tools:design_catalog:dependencyCheckAnalyze licenses: doctor $(BUILD_RUNNER) $(CARGO) deny --manifest-path $(CARGO_MANIFEST) check --config core/deny.toml licenses sources - $(BUILD_RUNNER) $(GRADLE) --no-daemon --no-parallel --no-configuration-cache :app:desktop:checkLicense + $(BUILD_RUNNER) $(GRADLE) --no-daemon --no-parallel --no-configuration-cache :app:desktop:checkLicense :app:design_system:checkLicense :tools:design_catalog:checkLicense foundation-check: design-source-check HARVESTCIRCLE_BUILD_MODE=$(BUILD_MODE) $(BUILD_RUNNER) $(CARGO) run --manifest-path $(XTASK_MANIFEST) --locked -- qualification-report diff --git a/NOTICE b/NOTICE @@ -14,3 +14,8 @@ Canonical reusable Radroots dependencies remain sourced from the public Third-party licence notices are governed by the checked-in dependency and licence verification configuration. + +Inter font software +Copyright (c) 2016 The Inter Project Authors (https://github.com/rsms/inter) +Licensed under the SIL Open Font License, Version 1.1. The complete licence is +available at `LICENSES/OFL-1.1.txt` and is packaged with the font resources. diff --git a/app/design_system/src/commonMain/composeResources/files/licenses/inter-OFL-1.1.txt b/app/design_system/src/commonMain/composeResources/files/licenses/inter-OFL-1.1.txt @@ -0,0 +1,92 @@ +Copyright (c) 2016 The Inter Project Authors (https://github.com/rsms/inter) + +This Font Software is licensed under the SIL Open Font License, Version 1.1. +This license is copied below, and is also available with a FAQ at: +http://scripts.sil.org/OFL + +----------------------------------------------------------- +SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007 +----------------------------------------------------------- + +PREAMBLE +The goals of the Open Font License (OFL) are to stimulate worldwide +development of collaborative font projects, to support the font creation +efforts of academic and linguistic communities, and to provide a free and +open framework in which fonts may be shared and improved in partnership +with others. + +The OFL allows the licensed fonts to be used, studied, modified and +redistributed freely as long as they are not sold by themselves. The +fonts, including any derivative works, can be bundled, embedded, +redistributed and/or sold with any software provided that any reserved +names are not used by derivative works. The fonts and derivatives, +however, cannot be released under any other type of license. The +requirement for fonts to remain under this license does not apply +to any document created using the fonts or their derivatives. + +DEFINITIONS +"Font Software" refers to the set of files released by the Copyright +Holder(s) under this license and clearly marked as such. This may +include source files, build scripts and documentation. + +"Reserved Font Name" refers to any names specified as such after the +copyright statement(s). + +"Original Version" refers to the collection of Font Software components as +distributed by the Copyright Holder(s). + +"Modified Version" refers to any derivative made by adding to, deleting, +or substituting -- in part or in whole -- any of the components of the +Original Version, by changing formats or by porting the Font Software to a +new environment. + +"Author" refers to any designer, engineer, programmer, technical +writer or other person who contributed to the Font Software. + +PERMISSION AND CONDITIONS +Permission is hereby granted, free of charge, to any person obtaining +a copy of the Font Software, to use, study, copy, merge, embed, modify, +redistribute, and sell modified and unmodified copies of the Font Software, +subject to the following conditions: + +1) Neither the Font Software nor any of its individual components, +in Original or Modified Versions, may be sold by itself. + +2) Original or Modified Versions of the Font Software may be bundled, +redistributed and/or sold with any software, provided that each copy +contains the above copyright notice and this license. These can be +included either as stand-alone text files, human-readable headers or +in the appropriate machine-readable metadata fields within text or +binary files as long as those fields can be easily viewed by the user. + +3) No Modified Version of the Font Software may use the Reserved Font +Name(s) unless explicit written permission is granted by the corresponding +Copyright Holder. This restriction only applies to the primary font name as +presented to the users. + +4) The name(s) of the Copyright Holder(s) or the Author(s) of the Font +Software shall not be used to promote, endorse or advertise any +Modified Version, except to acknowledge the contribution(s) of the +Copyright Holder(s) and the Author(s) or with their explicit written +permission. + +5) The Font Software, modified or unmodified, in part or in whole, +must be distributed entirely under this license, and must not be +distributed under any other license. The requirement for fonts to +remain under this license does not apply to any document created using +the Font Software. + +TERMINATION +This license becomes null and void if any of the above conditions are not +met. + +DISCLAIMER +THE FONT SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT +OF COPYRIGHT, PATENT, TRADEMARK, OR OTHER RIGHT. IN NO EVENT SHALL THE +COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, +INCLUDING ANY GENERAL, SPECIAL, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL +DAMAGES, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING +FROM, OUT OF THE USE OR INABILITY TO USE THE FONT SOFTWARE OR FROM OTHER +DEALINGS IN THE FONT SOFTWARE. diff --git a/app/design_system/src/commonMain/composeResources/font/inter_bold.ttf b/app/design_system/src/commonMain/composeResources/font/inter_bold.ttf Binary files differ. diff --git a/app/design_system/src/commonMain/composeResources/font/inter_medium.ttf b/app/design_system/src/commonMain/composeResources/font/inter_medium.ttf Binary files differ. diff --git a/app/design_system/src/commonMain/composeResources/font/inter_regular.ttf b/app/design_system/src/commonMain/composeResources/font/inter_regular.ttf Binary files differ. diff --git a/app/design_system/src/commonMain/composeResources/font/inter_semibold.ttf b/app/design_system/src/commonMain/composeResources/font/inter_semibold.ttf Binary files differ. diff --git a/build-logic/plugins/src/main/kotlin/org/harvestcircle/buildlogic/plugins/DesktopDesignKmp.kt b/build-logic/plugins/src/main/kotlin/org/harvestcircle/buildlogic/plugins/DesktopDesignKmp.kt @@ -1,5 +1,7 @@ package org.harvestcircle.buildlogic.plugins +import com.github.jk1.license.LicenseReportExtension +import com.github.jk1.license.filter.SpdxLicenseBundleNormalizer import org.gradle.api.Project import org.gradle.api.artifacts.VersionCatalog import org.gradle.api.artifacts.VersionCatalogsExtension @@ -8,6 +10,7 @@ import org.jlleitschuh.gradle.ktlint.KtlintExtension import org.jetbrains.kotlin.gradle.dsl.JvmTarget import org.jetbrains.kotlin.gradle.dsl.KotlinMultiplatformExtension import org.jetbrains.kotlin.gradle.plugin.KotlinPlatformType +import org.owasp.dependencycheck.gradle.extension.DependencyCheckExtension internal fun Project.applyDesktopDesignKmp() { pluginManager.apply("org.jetbrains.kotlin.multiplatform") @@ -15,11 +18,18 @@ internal fun Project.applyDesktopDesignKmp() { pluginManager.apply("org.jetbrains.kotlin.plugin.compose") pluginManager.apply("dev.detekt") pluginManager.apply("org.jlleitschuh.gradle.ktlint") + pluginManager.apply("com.github.jk1.dependency-license-report") + pluginManager.apply("org.owasp.dependencycheck") extensions.configure(KtlintExtension::class.java) { extension -> extension.additionalEditorconfig.set( mapOf("ktlint_function_naming_ignore_when_annotated_with" to "Composable"), ) + extension.filter { filter -> + filter.exclude { element -> + element.file.invariantSeparatorsPath.contains("/build/generated/") + } + } } extensions.configure(KotlinMultiplatformExtension::class.java) { kotlin -> kotlin.jvm("desktop") { jvm -> @@ -34,6 +44,29 @@ internal fun Project.applyDesktopDesignKmp() { "$path must declare exactly one KMP platform target named desktop" } } + extensions.configure(LicenseReportExtension::class.java) { extension -> + extension.projects = arrayOf(this@applyDesktopDesignKmp) + extension.configurations = arrayOf("desktopRuntimeClasspath") + extension.excludeGroups = arrayOf("harvestcircle.app") + extension.filters = arrayOf(SpdxLicenseBundleNormalizer()) + extension.allowedLicensesFile = + rootProject.layout.projectDirectory.file("config/licenses/allowed-licenses.json") + } + extensions.configure(DependencyCheckExtension::class.java) { extension -> + extension.failBuildOnCVSS.set(0.0F) + extension.failOnError.set(true) + extension.formats.set(listOf("HTML", "JSON")) + extension.scanConfigurations.set(listOf("desktopRuntimeClasspath")) + extension.skipTestGroups.set(true) + providers.environmentVariable("NVD_API_KEY").orNull?.takeIf(String::isNotBlank)?.let { + extension.nvd.apiKey.set(it) + } + } + tasks.matching { it.name.startsWith("dependencyCheck") }.configureEach { + it.notCompatibleWithConfigurationCache( + "Advisory data and environment-only credentials must not be cached", + ) + } } internal fun Project.versionCatalog(): VersionCatalog = diff --git a/build-logic/plugins/src/main/kotlin/org/harvestcircle/buildlogic/plugins/HarvestCircleDesignSystemPlugin.kt b/build-logic/plugins/src/main/kotlin/org/harvestcircle/buildlogic/plugins/HarvestCircleDesignSystemPlugin.kt @@ -25,6 +25,14 @@ public class HarvestCircleDesignSystemPlugin : Plugin<Project> { ) target.dependencies.add("commonMainApi", catalog.findLibrary("compose-ui").get()) target.dependencies.add( + "commonMainApi", + catalog.findLibrary("compose-components-resources").get(), + ) + target.dependencies.add( + "commonMainImplementation", + catalog.findLibrary("compose-animation").get(), + ) + target.dependencies.add( "commonTestImplementation", "org.jetbrains.kotlin:kotlin-test:$kotlinVersion", ) diff --git a/gradle/libs.versions.toml b/gradle/libs.versions.toml @@ -9,6 +9,8 @@ license-report = "3.1.4" owasp-dependency-check = "12.2.2" [libraries] +compose-animation = { module = "org.jetbrains.compose.animation:animation", version.ref = "compose" } +compose-components-resources = { module = "org.jetbrains.compose.components:components-resources", version.ref = "compose" } compose-foundation = { module = "org.jetbrains.compose.foundation:foundation", version.ref = "compose" } compose-runtime = { module = "org.jetbrains.compose.runtime:runtime", version.ref = "compose" } compose-ui = { module = "org.jetbrains.compose.ui:ui", version.ref = "compose" } diff --git a/gradle/verification-metadata.xml b/gradle/verification-metadata.xml @@ -2063,6 +2063,17 @@ <sha256 value="c1bca73c782a47dd24e44ac3c37e3dffc79a4bb9df95471a94968d79980d25d7" origin="Generated by Gradle"/> </artifact> </component> + <component group="org.jetbrains.compose.components" name="components-resources" version="1.11.1"> + <artifact name="components-resources-1.11.1.module"> + <sha256 value="158d143d3f415d5b27f271d13f8c1aab06df97765e0937f230ef07dd9d4bf33a" origin="Generated by Gradle"/> + </artifact> + <artifact name="components-resources-1.11.1.pom"> + <sha256 value="712bae3c122876f607cb591e970859b4b7e80ac70d89a8418229843d8edfbff7" origin="Generated by Gradle"/> + </artifact> + <artifact name="library-metadata-1.11.1.jar"> + <sha256 value="6ab4a950f0663d763ce6a66c367d9fe54776553f6c92bceb6ce5d328db44588e" origin="Generated by Gradle"/> + </artifact> + </component> <component group="org.jetbrains.compose.components" name="components-resources-desktop" version="1.10.0"> <artifact name="components-resources-desktop-1.10.0.module"> <sha256 value="506c48f0d14288465a76754e4cf429b8e6219012fc43c734f87eb179ee1d4535" origin="Generated by Gradle"/> @@ -2071,6 +2082,17 @@ <sha256 value="7dbbe06683befa8110b4ac926a7432b7e2ee446ed156adf55ad17e9c868ae0e2" origin="Generated by Gradle"/> </artifact> </component> + <component group="org.jetbrains.compose.components" name="components-resources-desktop" version="1.11.1"> + <artifact name="components-resources-desktop-1.11.1.module"> + <sha256 value="c20ff85ef2d3d56593254639443f805c3de01b2833e27b16719df94b04335175" origin="Generated by Gradle"/> + </artifact> + <artifact name="components-resources-desktop-1.11.1.pom"> + <sha256 value="07617f68caff8bb439cb3b83e3c1238c14aab8f5261ec4c3bfb6cf084e0a8738" origin="Generated by Gradle"/> + </artifact> + <artifact name="library-desktop-1.11.1.jar"> + <sha256 value="05e1cad77c8ede7930ad21223b819932b70d7ad969ebfef97ddf272fc1a7bc39" origin="Generated by Gradle"/> + </artifact> + </component> <component group="org.jetbrains.compose.desktop" name="desktop" version="1.10.0"> <artifact name="desktop-1.10.0.module"> <sha256 value="04729d88eadd7809b7a46c9f393a14b71f64ec04c93ff5b738371b7534889b37" origin="Generated by Gradle"/> diff --git a/tools/xtask/Cargo.lock b/tools/xtask/Cargo.lock @@ -3,5 +3,91 @@ version = 4 [[package]] +name = "block-buffer" +version = "0.10.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3078c7629b62d3f0439517fa394996acacc5cbc91c5a20d8c658e77abd503a71" +dependencies = [ + "generic-array", +] + +[[package]] +name = "cfg-if" +version = "1.0.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9330f8b2ff13f34540b44e946ef35111825727b38d33286ef986142615121801" + +[[package]] +name = "cpufeatures" +version = "0.2.17" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "59ed5838eebb26a2bb2e58f6d5b5316989ae9d08bab10e0e6d103e656d1b0280" +dependencies = [ + "libc", +] + +[[package]] +name = "crypto-common" +version = "0.1.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "78c8292055d1c1df0cce5d180393dc8cce0abec0a7102adb6c7b1eef6016d60a" +dependencies = [ + "generic-array", + "typenum", +] + +[[package]] +name = "digest" +version = "0.10.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9ed9a281f7bc9b7576e61468ba615a66a5c8cfdff42420a70aa82701a3b1e292" +dependencies = [ + "block-buffer", + "crypto-common", +] + +[[package]] +name = "generic-array" +version = "0.14.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "85649ca51fd72272d7821adaf274ad91c288277713d9c18820d8499a7ff69e9a" +dependencies = [ + "typenum", + "version_check", +] + +[[package]] name = "harvestcircle_xtask" version = "0.1.0-alpha" +dependencies = [ + "sha2", +] + +[[package]] +name = "libc" +version = "0.2.189" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3eaf3ede3fee6db1a4c2ee091bf8a8b4dccdc6d17f656fb07896ee72867612f2" + +[[package]] +name = "sha2" +version = "0.10.9" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a7507d819769d01a365ab707794a4084392c824f54a7a6a7862f8c3d0892b283" +dependencies = [ + "cfg-if", + "cpufeatures", + "digest", +] + +[[package]] +name = "typenum" +version = "1.20.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b6f5e870be6c3b371b77fe0ee0bafb859fa4964b4404c27de1d380043c4dda20" + +[[package]] +name = "version_check" +version = "0.9.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0b928f33d975fc6ad9f86c8f283853ad26bdd5b10b7f1542aa2fa15e2289105a" diff --git a/tools/xtask/Cargo.toml b/tools/xtask/Cargo.toml @@ -8,6 +8,9 @@ publish = false [workspace] +[dependencies] +sha2 = "0.10.9" + [lints.rust] unsafe_code = "forbid" diff --git a/tools/xtask/src/lib.rs b/tools/xtask/src/lib.rs @@ -1,3 +1,4 @@ +use sha2::{Digest, Sha256}; use std::collections::BTreeSet; use std::fs; use std::path::{Path, PathBuf}; @@ -174,6 +175,7 @@ fn repo_audit(root: &Path, inventory: &Inventory, findings: &mut Vec<String>) { "SECURITY.md", "LICENSE", "LICENSES/GPL-3.0-only.txt", + "LICENSES/OFL-1.1.txt", ]; for required_path in required { if !inventory.paths.iter().any(|path| path == required_path) { @@ -957,6 +959,56 @@ fn design_source_audit(root: &Path, inventory: &Inventory, findings: &mut Vec<St "{PATH}: source-to-owned mapping differs from the approved migration" )); } + let catalog = read_text(root, "gradle/libs.versions.toml"); + for required in [ + "compose-animation = { module = \"org.jetbrains.compose.animation:animation\", version.ref = \"compose\" }", + "compose-components-resources = { module = \"org.jetbrains.compose.components:components-resources\", version.ref = \"compose\" }", + ] { + if !catalog.contains(required) { + findings.push(format!( + "gradle/libs.versions.toml: missing approved design dependency: {required}" + )); + } + } + for forbidden in ["compose-material3", "platformtools", "js(", "wasm"] { + if catalog.to_ascii_lowercase().contains(forbidden) { + findings.push(format!( + "gradle/libs.versions.toml: forbidden design dependency or target: {forbidden}" + )); + } + } + for (path, sha256) in [ + ( + "app/design_system/src/commonMain/composeResources/font/inter_bold.ttf", + "288316099b1e0a47a4716d159098005eef7c0066921f34e3200393dbdb01947f", + ), + ( + "app/design_system/src/commonMain/composeResources/font/inter_medium.ttf", + "97ad806f526e41546d46365bb3a393145f75b7b1568913db74549ad8b8dba872", + ), + ( + "app/design_system/src/commonMain/composeResources/font/inter_regular.ttf", + "40d692fce188e4471e2b3cba937be967878f631ad3ebbbdcd587687c7ebe0c82", + ), + ( + "app/design_system/src/commonMain/composeResources/font/inter_semibold.ttf", + "78a843fade9d4612a5567302fb595b56976eb5fcebf4fea5a5912d638bafcde3", + ), + ] { + if sha256_file(&root.join(path)).as_deref() != Some(sha256) { + findings.push(format!( + "{path}: Inter font digest differs from the baseline" + )); + } + } + let font_license = read_text(root, "LICENSES/OFL-1.1.txt"); + let packaged_font_license = read_text( + root, + "app/design_system/src/commonMain/composeResources/files/licenses/inter-OFL-1.1.txt", + ); + if font_license.is_empty() || packaged_font_license != font_license { + findings.push("Inter font licence is missing or differs in packaged resources".to_owned()); + } } fn design_source_mappings( @@ -1197,6 +1249,11 @@ fn read_text(root: &Path, relative: &str) -> String { fs::read_to_string(root.join(relative)).unwrap_or_default() } +fn sha256_file(path: &Path) -> Option<String> { + let bytes = fs::read(path).ok()?; + Some(format!("{:x}", Sha256::digest(bytes))) +} + fn relative(root: &Path, path: &Path) -> Result<String, String> { path.strip_prefix(root) .map(|relative| relative.to_string_lossy().replace('\\', "/"))