commit d7e702defaa7af1af8fdafa91d1f0ed087540cf1
parent 15d2df5d646b38bdc0ddc8ad88fa6d4416c8203c
Author: triesap <tyson@radroots.org>
Date: Tue, 25 Aug 2026 07:17:43 +0000
security: enforce standalone supply-chain policy
Diffstat:
3 files changed, 41 insertions(+), 5 deletions(-)
diff --git a/AGENTS.md b/AGENTS.md
@@ -86,11 +86,13 @@ protocols/adapters, all relevant tests, and public routing text before editing.
Make one coherent, reviewable target-state change at a time and preserve
unrelated work.
-The standalone package lanes are `swift build` and `swift test`; run the
-smallest relevant test selection while iterating and the complete suite before
-a checkpoint. Verify `Package.swift` and `Package.resolved` still select the
-same exact dependency revision, inspect privacy-manifest changes, prove no
-forbidden root exists, run `git diff --check`, and review final status and diff.
+The standalone package lanes are `tools/verify-supply-chain.sh`, `swift build`,
+and `swift test`; run the smallest relevant selection while iterating and the
+complete suite before a checkpoint. The supply-chain gate proves the exact
+single remote dependency revision and repository license authority. Verify
+`Package.swift` and `Package.resolved` still agree, inspect privacy-manifest
+changes, prove no forbidden root exists, run `git diff --check`, and review
+final status and diff.
In an extbuild-enabled checkout, run `cargo extbuild doctor` before the first
mutating build, test, dependency, package, install, or generated-artifact
diff --git a/README b/README
@@ -3,6 +3,13 @@
This is the README for `apple_kit` which contains `RadrootsKit`, the shared
Swift package for native Rad Roots Apple-platform application services.
+## Verification
+
+Run `tools/verify-supply-chain.sh`, `swift build`, and `swift test` from a
+standalone clone. In an extbuild-enabled checkout, first run
+`cargo extbuild doctor` and route those commands through
+`cargo extbuild run --`.
+
## Copyright
Except as otherwise noted, all files in the `apple_kit` distribution are
diff --git a/tools/verify-supply-chain.sh b/tools/verify-supply-chain.sh
@@ -0,0 +1,27 @@
+#!/usr/bin/env bash
+set -euo pipefail
+
+repo_root="$(git rev-parse --show-toplevel)"
+cd "$repo_root"
+
+dependency_url="https://github.com/21-DOT-DEV/swift-secp256k1.git"
+dependency_revision="e70a10e036a55fffea31568f0af92d69b6d449cd"
+
+test "$(grep -F -c "url: \"$dependency_url\"" Package.swift)" -eq 1
+test "$(grep -F -c "revision: \"$dependency_revision\"" Package.swift)" -eq 1
+test "$(grep -E -c '^[[:space:]]*\.package\(' Package.swift)" -eq 1
+test "$(grep -F -c "\"location\" : \"$dependency_url\"" Package.resolved)" -eq 1
+test "$(grep -F -c "\"revision\" : \"$dependency_revision\"" Package.resolved)" -eq 1
+
+if grep -E -q '\.package\((path:|.*branch:|.*from:|.*exact:)' Package.swift; then
+ echo "supply_chain_invalid: dependency must use only the governed immutable revision" >&2
+ exit 1
+fi
+
+test "$(grep -F -c '"identity" : "swift-secp256k1"' Package.resolved)" -eq 1
+test "$(grep -F -c '"identity" :' Package.resolved)" -eq 1
+test "$(grep -F -c '"kind" : "remoteSourceControl"' Package.resolved)" -eq 1
+grep -F -q 'GPL-3.0-or-later' README
+grep -F -q 'GNU GENERAL PUBLIC LICENSE' LICENSE
+
+echo "supply-chain ok: one immutable Swift dependency"