radroots_sdk_supply_chain.mjs (3844B)
1 import { readFileSync, readdirSync } from "node:fs"; 2 import { basename, dirname, join } from "node:path"; 3 import { fileURLToPath } from "node:url"; 4 5 import { validateGeneratedPackageLicenses } from "./radroots_sdk_package_license_lib.mjs"; 6 7 const root = dirname(dirname(fileURLToPath(import.meta.url))); 8 const expectedLicense = "MIT OR Apache-2.0"; 9 const expectedRepository = "git+https://github.com/radrootslabs/sdk.git"; 10 const expectedPackages = [ 11 "core-bindings", 12 "event-bindings", 13 "event-codec-wasm", 14 "identity-bindings", 15 "replica-schema-bindings", 16 "replica-store-wasm", 17 "replica-sync-wasm", 18 "trade-bindings", 19 ]; 20 21 function fail(message) { 22 throw new Error(`supply_chain_invalid: ${message}`); 23 } 24 25 function readJson(path) { 26 return JSON.parse(readFileSync(path, "utf8")); 27 } 28 29 function packageDirectories() { 30 return readdirSync(join(root, "packages"), { withFileTypes: true }) 31 .filter((entry) => entry.isDirectory()) 32 .map((entry) => join(root, "packages", entry.name)) 33 .filter((path) => { 34 try { 35 readFileSync(join(path, "package.json")); 36 return true; 37 } catch { 38 return false; 39 } 40 }) 41 .sort(); 42 } 43 44 function verifyManifest(path) { 45 const manifest = readJson(join(path, "package.json")); 46 if (manifest.license !== expectedLicense) fail("package license drifted"); 47 if ( 48 manifest.repository?.type !== "git" || 49 manifest.repository?.url !== expectedRepository || 50 manifest.repository?.directory !== `packages/${basename(path)}` 51 ) { 52 fail("package repository identity drifted"); 53 } 54 if ( 55 !Array.isArray(manifest.files) || 56 !manifest.files.includes("LICENSE-MIT") || 57 !manifest.files.includes("LICENSE-APACHE") 58 ) { 59 fail("package artifact omits governed license files"); 60 } 61 for (const section of ["dependencies", "devDependencies", "optionalDependencies", "peerDependencies"]) { 62 for (const value of Object.values(manifest[section] ?? {})) { 63 if (!String(value).startsWith("workspace:")) { 64 fail("package dependency is not workspace-locked"); 65 } 66 } 67 } 68 } 69 70 const manifest = readJson(join(root, "package.json")); 71 if (manifest.packageManager !== "pnpm@10.25.0") fail("package manager drifted"); 72 if (manifest.devDependencies?.typescript !== "^5.9.0") fail("TypeScript input drifted"); 73 if (Object.keys(manifest.devDependencies ?? {}).length !== 1) fail("root dependency inventory drifted"); 74 75 const lock = readFileSync(join(root, "pnpm-lock.yaml"), "utf8"); 76 for (const required of [ 77 "lockfileVersion: '9.0'", 78 "typescript@5.9.3:", 79 "specifier: ^5.9.0", 80 "sha512-jl1vZzPDinLr9eUt3J/t7V6FgNEw9QjvBPdysz9KfQDD41fQrC2Y4vKQdiaUpFT4bXlb1RHhLpp8wtm6M5TgSw==", 81 ]) { 82 if (!lock.includes(required)) fail("pnpm lock authority drifted"); 83 } 84 for (const forbidden of ["git+", "github:", "http://"]) { 85 if (lock.includes(forbidden)) fail("pnpm lock contains an unapproved source"); 86 } 87 88 const sourceLock = readFileSync(join(root, "radroots.lib.source-lock.v1.toml"), "utf8"); 89 if (!/^repository = "https:\/\/github\.com\/radrootslabs\/lib"$/m.test(sourceLock)) { 90 fail("Lib repository identity drifted"); 91 } 92 if (!/^revision = "[0-9a-f]{40}"$/m.test(sourceLock)) fail("Lib revision is not immutable"); 93 if (!/^lockfile_sha256 = "[0-9a-f]{64}"$/m.test(sourceLock)) fail("Cargo lock digest is absent"); 94 const sourceRevision = sourceLock.match(/^revision = "([0-9a-f]{40})"$/m)?.[1]; 95 if (!sourceRevision) fail("Lib revision is not immutable"); 96 97 const packages = packageDirectories(); 98 if ( 99 packages.length !== expectedPackages.length || 100 packages.some((path, index) => basename(path) !== expectedPackages[index]) 101 ) { 102 fail("package inventory drifted"); 103 } 104 for (const path of packages) verifyManifest(path); 105 validateGeneratedPackageLicenses(root, packages, sourceRevision); 106 107 console.log(`supply-chain ok: ${packages.length} packages`);