From efde1eb920a535c414d6d55c30779e0d87aac6e9 Mon Sep 17 00:00:00 2001 From: LinzLos <223187540+LinzLos@users.noreply.github.com> Date: Mon, 28 Sep 2026 20:08:12 +0000 Subject: [PATCH 1/2] Add CI drift check for vendored Tiny Wire tokens Runs scripts/check-tinywire-drift.sh on every push and PR: checks out tiny-wire at the tag matching src/lib/.tinywire-version and verifies the pin and vendored files match the pinned release byte for byte. --- .github/workflows/tinywire-drift.yml | 32 ++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) create mode 100644 .github/workflows/tinywire-drift.yml diff --git a/.github/workflows/tinywire-drift.yml b/.github/workflows/tinywire-drift.yml new file mode 100644 index 0000000..a8daa7d --- /dev/null +++ b/.github/workflows/tinywire-drift.yml @@ -0,0 +1,32 @@ +name: Tiny Wire drift check + +on: + push: + pull_request: + +jobs: + drift: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + + - name: Read Tiny Wire version pin + id: pin + run: echo "version=$(tr -d '[:space:]' < src/lib/.tinywire-version)" >> "$GITHUB_OUTPUT" + + # Tiny Wire tags releases as vX.Y, so check out the tag matching this + # repo's pin. That verifies the vendored files in src/lib/ are + # byte-identical to the pinned release. If the pin ever names a version + # with no matching tag, this step fails — also a drift signal: fix the + # pin or tag the release upstream. + - name: Check out Tiny Wire at pinned version + uses: actions/checkout@v4 + with: + repository: LinzLos/tiny-wire + ref: v${{ steps.pin.outputs.version }} + path: tiny-wire + + # The script defaults to a sibling ../tiny-wire checkout; in Actions the + # source lives inside the workspace instead, so point TW_REPO_DIR at it. + - name: Run drift check + run: TW_REPO_DIR="$GITHUB_WORKSPACE/tiny-wire" ./scripts/check-tinywire-drift.sh From c445579a88340a069e1013cf5a425f6fc3974e42 Mon Sep 17 00:00:00 2001 From: LinzLos <223187540+LinzLos@users.noreply.github.com> Date: Mon, 28 Sep 2026 20:50:46 +0000 Subject: [PATCH 2/2] Add deploy script with Tiny Wire drift check as predeploy gate npm run deploy now runs scripts/check-tinywire-drift.sh before netlify deploy --prod --build, so a stale or hand-edited vendored tokens file blocks a manual deploy the same way it fails CI. --- README.md | 1 + package.json | 4 +++- 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 4a7db9d..e75103b 100644 --- a/README.md +++ b/README.md @@ -39,6 +39,7 @@ npm install npm run dev # start the dev server (Vite) npm run build # type-check + production build to dist/ npm run preview # serve the production build +npm run deploy # drift-check vendored Tiny Wire tokens, then netlify deploy --prod --build ``` ## Credits diff --git a/package.json b/package.json index 82e51bc..ed1855f 100644 --- a/package.json +++ b/package.json @@ -7,7 +7,9 @@ "dev": "vite", "build": "tsc -b && vite build", "lint": "eslint .", - "preview": "vite preview" + "preview": "vite preview", + "predeploy": "scripts/check-tinywire-drift.sh", + "deploy": "netlify deploy --prod --build" }, "dependencies": { "framer-motion": "^12.38.0",