verify-boundaries.sh (1042B)
1 #!/usr/bin/env bash 2 set -euo pipefail 3 4 repo_root="$(git rev-parse --show-toplevel)" 5 cd "$repo_root" 6 7 test "$(cargo public-api --version)" = "cargo-public-api 0.52.0" 8 temporary_api="$(mktemp)" 9 trap 'rm -f "$temporary_api"' EXIT 10 cargo +nightly-2026-07-16 public-api --all-features -sss -p myc >"$temporary_api" 11 cmp "$temporary_api" contracts/api_baselines/myc.txt 12 13 for forbidden_root in docs .github .act; do 14 test ! -e "$forbidden_root" 15 test ! -L "$forbidden_root" 16 done 17 18 if git ls-files | grep -E -i '(^|/)(\.env|id_rsa|id_ed25519|credentials|[^/]+\.(pem|key|p12|pfx|jks|keystore))$' >/dev/null; then 19 echo "boundary_invalid: sensitive credential path is tracked" >&2 20 exit 1 21 fi 22 if git grep -I -n -E -e '-----BEGIN ([A-Z0-9 ]+ )?PRIVATE KEY-----|AKIA[0-9A-Z]{16}|gh[pousr]_[A-Za-z0-9_]{36,}|nsec1[023456789acdefghjklmnpqrstuvwxyz]{40,}' -- src >/dev/null; then 23 echo "boundary_invalid: production source contains credential material" >&2 24 exit 1 25 fi 26 27 echo "boundary ok: root-only API, fresh baseline, no forbidden or credential surface"