verify-boundaries.sh (1103B)
1 #!/usr/bin/env bash 2 set -euo pipefail 3 4 repo_root="$(git rev-parse --show-toplevel)" 5 cd "$repo_root" 6 7 cargo test --locked --offline --test source_lock 8 9 for forbidden_root in docs .github .act; do 10 test ! -e "$forbidden_root" 11 test ! -L "$forbidden_root" 12 done 13 test "$(cargo public-api --version)" = "cargo-public-api 0.52.0" 14 temporary_api="$(mktemp)" 15 trap 'rm -f "$temporary_api"' EXIT 16 cargo +nightly-2026-07-16 public-api --all-features -sss -p radrootsd >"$temporary_api" 17 cmp "$temporary_api" contracts/api_baselines/radrootsd.txt 18 19 if git ls-files | grep -E -i '(^|/)(\.env|id_rsa|id_ed25519|credentials|[^/]+\.(pem|key|p12|pfx|jks|keystore))$' >/dev/null; then 20 echo "boundary_invalid: sensitive credential path is tracked" >&2 21 exit 1 22 fi 23 if git grep -I -n -E -e '-----BEGIN ([A-Z0-9 ]+ )?PRIVATE KEY-----|AKIA[0-9A-Z]{16}|gh[pousr]_[A-Za-z0-9_]{36,}|nsec1[023456789acdefghjklmnpqrstuvwxyz]{40,}' -- src >/dev/null; then 24 echo "boundary_invalid: production source contains credential material" >&2 25 exit 1 26 fi 27 28 echo "boundary ok: root-only API, fresh baseline, no forbidden or credential surface"