sdk

Radroots SDK and bindings
git clone https://radroots.dev/git/sdk.git
Log | Files | Refs | README

radroots_sdk_supply_chain.mjs (3844B)


      1 import { readFileSync, readdirSync } from "node:fs";
      2 import { basename, dirname, join } from "node:path";
      3 import { fileURLToPath } from "node:url";
      4 
      5 import { validateGeneratedPackageLicenses } from "./radroots_sdk_package_license_lib.mjs";
      6 
      7 const root = dirname(dirname(fileURLToPath(import.meta.url)));
      8 const expectedLicense = "MIT OR Apache-2.0";
      9 const expectedRepository = "git+https://github.com/radrootslabs/sdk.git";
     10 const expectedPackages = [
     11   "core-bindings",
     12   "event-bindings",
     13   "event-codec-wasm",
     14   "identity-bindings",
     15   "replica-schema-bindings",
     16   "replica-store-wasm",
     17   "replica-sync-wasm",
     18   "trade-bindings",
     19 ];
     20 
     21 function fail(message) {
     22   throw new Error(`supply_chain_invalid: ${message}`);
     23 }
     24 
     25 function readJson(path) {
     26   return JSON.parse(readFileSync(path, "utf8"));
     27 }
     28 
     29 function packageDirectories() {
     30   return readdirSync(join(root, "packages"), { withFileTypes: true })
     31     .filter((entry) => entry.isDirectory())
     32     .map((entry) => join(root, "packages", entry.name))
     33     .filter((path) => {
     34       try {
     35         readFileSync(join(path, "package.json"));
     36         return true;
     37       } catch {
     38         return false;
     39       }
     40     })
     41     .sort();
     42 }
     43 
     44 function verifyManifest(path) {
     45   const manifest = readJson(join(path, "package.json"));
     46   if (manifest.license !== expectedLicense) fail("package license drifted");
     47   if (
     48     manifest.repository?.type !== "git" ||
     49     manifest.repository?.url !== expectedRepository ||
     50     manifest.repository?.directory !== `packages/${basename(path)}`
     51   ) {
     52     fail("package repository identity drifted");
     53   }
     54   if (
     55     !Array.isArray(manifest.files) ||
     56     !manifest.files.includes("LICENSE-MIT") ||
     57     !manifest.files.includes("LICENSE-APACHE")
     58   ) {
     59     fail("package artifact omits governed license files");
     60   }
     61   for (const section of ["dependencies", "devDependencies", "optionalDependencies", "peerDependencies"]) {
     62     for (const value of Object.values(manifest[section] ?? {})) {
     63       if (!String(value).startsWith("workspace:")) {
     64         fail("package dependency is not workspace-locked");
     65       }
     66     }
     67   }
     68 }
     69 
     70 const manifest = readJson(join(root, "package.json"));
     71 if (manifest.packageManager !== "pnpm@10.25.0") fail("package manager drifted");
     72 if (manifest.devDependencies?.typescript !== "^5.9.0") fail("TypeScript input drifted");
     73 if (Object.keys(manifest.devDependencies ?? {}).length !== 1) fail("root dependency inventory drifted");
     74 
     75 const lock = readFileSync(join(root, "pnpm-lock.yaml"), "utf8");
     76 for (const required of [
     77   "lockfileVersion: '9.0'",
     78   "typescript@5.9.3:",
     79   "specifier: ^5.9.0",
     80   "sha512-jl1vZzPDinLr9eUt3J/t7V6FgNEw9QjvBPdysz9KfQDD41fQrC2Y4vKQdiaUpFT4bXlb1RHhLpp8wtm6M5TgSw==",
     81 ]) {
     82   if (!lock.includes(required)) fail("pnpm lock authority drifted");
     83 }
     84 for (const forbidden of ["git+", "github:", "http://"]) {
     85   if (lock.includes(forbidden)) fail("pnpm lock contains an unapproved source");
     86 }
     87 
     88 const sourceLock = readFileSync(join(root, "radroots.lib.source-lock.v1.toml"), "utf8");
     89 if (!/^repository = "https:\/\/github\.com\/radrootslabs\/lib"$/m.test(sourceLock)) {
     90   fail("Lib repository identity drifted");
     91 }
     92 if (!/^revision = "[0-9a-f]{40}"$/m.test(sourceLock)) fail("Lib revision is not immutable");
     93 if (!/^lockfile_sha256 = "[0-9a-f]{64}"$/m.test(sourceLock)) fail("Cargo lock digest is absent");
     94 const sourceRevision = sourceLock.match(/^revision = "([0-9a-f]{40})"$/m)?.[1];
     95 if (!sourceRevision) fail("Lib revision is not immutable");
     96 
     97 const packages = packageDirectories();
     98 if (
     99   packages.length !== expectedPackages.length ||
    100   packages.some((path, index) => basename(path) !== expectedPackages[index])
    101 ) {
    102   fail("package inventory drifted");
    103 }
    104 for (const path of packages) verifyManifest(path);
    105 validateGeneratedPackageLicenses(root, packages, sourceRevision);
    106 
    107 console.log(`supply-chain ok: ${packages.length} packages`);