apple_kit

Apple-native services for Radroots iOS and macOS apps
git clone https://radroots.dev/git/apple_kit.git
Log | Files | Refs | README | LICENSE

commit d7e702defaa7af1af8fdafa91d1f0ed087540cf1
parent 15d2df5d646b38bdc0ddc8ad88fa6d4416c8203c
Author: triesap <tyson@radroots.org>
Date:   Tue, 25 Aug 2026 07:17:43 +0000

security: enforce standalone supply-chain policy

Diffstat:
MAGENTS.md | 12+++++++-----
MREADME | 7+++++++
Atools/verify-supply-chain.sh | 27+++++++++++++++++++++++++++
3 files changed, 41 insertions(+), 5 deletions(-)

diff --git a/AGENTS.md b/AGENTS.md @@ -86,11 +86,13 @@ protocols/adapters, all relevant tests, and public routing text before editing. Make one coherent, reviewable target-state change at a time and preserve unrelated work. -The standalone package lanes are `swift build` and `swift test`; run the -smallest relevant test selection while iterating and the complete suite before -a checkpoint. Verify `Package.swift` and `Package.resolved` still select the -same exact dependency revision, inspect privacy-manifest changes, prove no -forbidden root exists, run `git diff --check`, and review final status and diff. +The standalone package lanes are `tools/verify-supply-chain.sh`, `swift build`, +and `swift test`; run the smallest relevant selection while iterating and the +complete suite before a checkpoint. The supply-chain gate proves the exact +single remote dependency revision and repository license authority. Verify +`Package.swift` and `Package.resolved` still agree, inspect privacy-manifest +changes, prove no forbidden root exists, run `git diff --check`, and review +final status and diff. In an extbuild-enabled checkout, run `cargo extbuild doctor` before the first mutating build, test, dependency, package, install, or generated-artifact diff --git a/README b/README @@ -3,6 +3,13 @@ This is the README for `apple_kit` which contains `RadrootsKit`, the shared Swift package for native Rad Roots Apple-platform application services. +## Verification + +Run `tools/verify-supply-chain.sh`, `swift build`, and `swift test` from a +standalone clone. In an extbuild-enabled checkout, first run +`cargo extbuild doctor` and route those commands through +`cargo extbuild run --`. + ## Copyright Except as otherwise noted, all files in the `apple_kit` distribution are diff --git a/tools/verify-supply-chain.sh b/tools/verify-supply-chain.sh @@ -0,0 +1,27 @@ +#!/usr/bin/env bash +set -euo pipefail + +repo_root="$(git rev-parse --show-toplevel)" +cd "$repo_root" + +dependency_url="https://github.com/21-DOT-DEV/swift-secp256k1.git" +dependency_revision="e70a10e036a55fffea31568f0af92d69b6d449cd" + +test "$(grep -F -c "url: \"$dependency_url\"" Package.swift)" -eq 1 +test "$(grep -F -c "revision: \"$dependency_revision\"" Package.swift)" -eq 1 +test "$(grep -E -c '^[[:space:]]*\.package\(' Package.swift)" -eq 1 +test "$(grep -F -c "\"location\" : \"$dependency_url\"" Package.resolved)" -eq 1 +test "$(grep -F -c "\"revision\" : \"$dependency_revision\"" Package.resolved)" -eq 1 + +if grep -E -q '\.package\((path:|.*branch:|.*from:|.*exact:)' Package.swift; then + echo "supply_chain_invalid: dependency must use only the governed immutable revision" >&2 + exit 1 +fi + +test "$(grep -F -c '"identity" : "swift-secp256k1"' Package.resolved)" -eq 1 +test "$(grep -F -c '"identity" :' Package.resolved)" -eq 1 +test "$(grep -F -c '"kind" : "remoteSourceControl"' Package.resolved)" -eq 1 +grep -F -q 'GPL-3.0-or-later' README +grep -F -q 'GNU GENERAL PUBLIC LICENSE' LICENSE + +echo "supply-chain ok: one immutable Swift dependency"