Skip to content

Commit 58c216b

Browse files
committed
fix(release): validate cli prerelease artifacts and scripts
1 parent 139a778 commit 58c216b

19 files changed

Lines changed: 362 additions & 217 deletions

‎package.json‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -225,9 +225,9 @@
225225
"build:sea": "node scripts/repo/cli-build/sea/build.mts",
226226
"check:sea-package": "node scripts/repo/cli-build/sea/check.mts",
227227
"prepack": "pnpm run check:sea-package",
228-
"test:sea": "node scripts/fleet/test.mts test/repo/unit/sea-package.test.mts",
228+
"test:sea": "node scripts/fleet/test.mts test/repo/unit/sea test/repo/unit/rolldown.cli.test.mts",
229229
"bump": "node scripts/repo/bump.mts",
230-
"prepublish:check": "node scripts/repo/check/publish-contract.mts",
230+
"prepublish:check": "node scripts/repo/check/publish-contract-is-valid.mts",
231231
"build:publish": "pnpm run prepublish:check --reserved && pnpm run build:sea"
232232
},
233233
"devDependencies": {

‎scripts/repo/bump.mts‎

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -119,9 +119,12 @@ export async function main(): Promise<void> {
119119
writeFileSync(PACKAGE_JSON, replaceVersion(original, source.version))
120120
}
121121

122+
const SCRIPT_META = {
123+
describe: 'generates a source-bound Socket CLI prerelease',
124+
help: 'Usage: pnpm run bump --dry-run | --write-only',
125+
json: 'result' as const,
126+
}
127+
122128
if (isMainModule(import.meta.url)) {
123-
runMain(main, {
124-
describe: 'generates a source-bound Socket CLI prerelease',
125-
help: 'Usage: pnpm run bump --dry-run | --write-only',
126-
})
129+
runMain(main, SCRIPT_META)
127130
}

scripts/repo/check/publish-contract.mts renamed to scripts/repo/check/publish-contract-is-valid.mts

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -34,9 +34,12 @@ export async function main(): Promise<void> {
3434
}
3535
}
3636

37+
const SCRIPT_META = {
38+
describe: 'validates the Socket CLI npm release contract',
39+
help: 'Usage: pnpm run prepublish:check [--reserved]',
40+
json: 'result' as const,
41+
}
42+
3743
if (isMainModule(import.meta.url)) {
38-
runMain(main, {
39-
describe: 'validates the Socket CLI npm release contract',
40-
help: 'Usage: pnpm run prepublish:check [--reserved]',
41-
})
44+
runMain(main, SCRIPT_META)
4245
}

‎scripts/repo/cli-build/build.mts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ import { getDefaultLogger } from '@socketsecurity/lib-stable/logger/default'
1111
import { spawn } from '@socketsecurity/lib-stable/process/spawn/child'
1212
import { getEnvValue } from '@socketsecurity/lib-stable/env/rewire'
1313
import { buildSdxgenBundle } from './sdxgen.mts'
14-
import { safeDelete } from '../../fleet/fs/safe.mts'
14+
import { safeDelete } from '@socketsecurity/lib-stable/fs/safe'
1515
import { isMainModule } from '../../fleet/process/is-main-module.mts'
1616
import { runMain } from '../../fleet/process/run-main.mts'
1717

‎scripts/repo/cli-build/sea/assets.mts‎

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,11 @@ import crypto from 'node:crypto'
22
import { chmod, readFile, writeFile } from 'node:fs/promises'
33
import path from 'node:path'
44
import { httpRequest } from '@socketsecurity/lib-stable/http-request'
5-
import { BASE_ASSET_SHA256 } from '../constants/sea-assets.mts'
5+
import {
6+
BASE_ASSET_SHA256,
7+
BASE_ASSETS_MIRROR_OWNER,
8+
BASE_ASSETS_MIRROR_REPO,
9+
} from '../constants/sea-assets.mts'
610
import { SEA_BUILD_DIR } from './paths.mts'
711

812
export function verifySeaAsset(bytes: Uint8Array, expected: string): boolean {
@@ -32,7 +36,7 @@ export async function fetchSeaAsset(
3236
}
3337
if (!bytes || !verifySeaAsset(bytes, expected)) {
3438
const response = await httpRequest(
35-
`https://github.com/SocketDev/socket-cli/releases/download/base-assets-${tag}/${name}`,
39+
`https://github.com/${BASE_ASSETS_MIRROR_OWNER}/${BASE_ASSETS_MIRROR_REPO}/releases/download/base-assets-${tag}/${name}`,
3640
)
3741
if (!response.ok) {
3842
throw new Error(

‎scripts/repo/cli-build/sea/build.mts‎

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -39,15 +39,13 @@ export async function main(): Promise<void> {
3939
await mkdir(SEA_OUTPUT_DIR, { recursive: true })
4040
const payload = await readFile(SEA_PAYLOAD_PATH, 'utf8')
4141
await writeFile(SEA_ENTRY_PATH, createSeaEntry(payload))
42-
const host = resolveSeaTarget(
43-
process.platform,
44-
process.arch,
45-
(
42+
const host = resolveSeaTarget(process.platform, process.arch, {
43+
glibc: (
4644
process.report.getReport() as {
4745
header: { glibcVersionRuntime?: string | undefined }
4846
}
4947
).header.glibcVersionRuntime,
50-
)
48+
})
5149
const arg = process.argv
5250
.find(value => value.startsWith('--target='))
5351
?.slice(9)
@@ -183,11 +181,13 @@ async function buildSeaTarget(
183181
.digest('hex')
184182
}
185183

184+
const SCRIPT_META = {
185+
describe: 'build the socket package SEA platform matrix',
186+
heavyJob: 'build' as const,
187+
help: 'Usage: pnpm run build:sea [--target=host|TARGET]',
188+
json: 'native' as const,
189+
}
190+
186191
if (isMainModule(import.meta.url)) {
187-
runMain(main, {
188-
describe: 'build the socket package SEA platform matrix',
189-
help: 'Usage: pnpm run build:sea [--target=host|TARGET]',
190-
json: 'native',
191-
heavyJob: 'build',
192-
})
192+
runMain(main, SCRIPT_META)
193193
}

‎scripts/repo/cli-build/sea/check.mts‎

Lines changed: 14 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -42,15 +42,13 @@ export async function main(): Promise<void> {
4242
}
4343
const targets = process.argv.includes('--host')
4444
? [
45-
resolveSeaTarget(
46-
process.platform,
47-
process.arch,
48-
(
45+
resolveSeaTarget(process.platform, process.arch, {
46+
glibc: (
4947
process.report.getReport() as {
5048
header: { glibcVersionRuntime?: string | undefined }
5149
}
5250
).header.glibcVersionRuntime,
53-
),
51+
}),
5452
]
5553
: SEA_TARGETS
5654
for (const target of targets) {
@@ -62,15 +60,13 @@ export async function main(): Promise<void> {
6260
)
6361
}
6462
}
65-
const host = resolveSeaTarget(
66-
process.platform,
67-
process.arch,
68-
(
63+
const host = resolveSeaTarget(process.platform, process.arch, {
64+
glibc: (
6965
process.report.getReport() as {
7066
header: { glibcVersionRuntime?: string | undefined }
7167
}
7268
).header.glibcVersionRuntime,
73-
)
69+
})
7470
for (const args of [['--version'], ['--help'], ['npm', '--version']]) {
7571
const result = await spawn(seaBinaryPath(host), args, {
7672
stdio: 'pipe',
@@ -89,11 +85,13 @@ export async function main(): Promise<void> {
8985
}
9086
}
9187

88+
const SCRIPT_META = {
89+
describe: 'verify socket SEA artifact integrity and execution',
90+
heavyJob: 'test' as const,
91+
help: 'Usage: pnpm run check:sea-package [--host]',
92+
json: 'native' as const,
93+
}
94+
9295
if (isMainModule(import.meta.url)) {
93-
runMain(main, {
94-
describe: 'verify socket SEA artifact integrity and execution',
95-
help: 'Usage: pnpm run check:sea-package [--host]',
96-
json: 'native',
97-
heavyJob: 'test',
98-
})
96+
runMain(main, SCRIPT_META)
9997
}

‎scripts/repo/cli-build/sea/paths.mts‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,8 @@
11
import path from 'node:path'
22
import { PACKAGE_ROOT } from '../paths.mts'
33

4+
export * from '../paths.mts'
5+
46
export const SEA_OUTPUT_DIR = path.join(PACKAGE_ROOT, 'dist', 'sea')
57
export const SEA_BUILD_DIR = path.join(PACKAGE_ROOT, 'build', 'sea')
68
export const SEA_ENTRY_PATH = path.join(SEA_BUILD_DIR, 'entry.generated.cjs')

‎scripts/repo/cli-build/sea/targets.mts‎

Lines changed: 5 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,19 +1,13 @@
1-
export const SEA_TARGETS = [
2-
'darwin-arm64',
3-
'darwin-x64',
4-
'linux-arm64',
5-
'linux-arm64-musl',
6-
'linux-x64',
7-
'linux-x64-musl',
8-
'win32-arm64',
9-
'win32-x64',
10-
] as const
1+
import { PACK_APP_TRIPLETS } from '../../../fleet/util/pack-app-triplets.mts'
2+
3+
export const SEA_TARGETS = PACK_APP_TRIPLETS
114

125
export function resolveSeaTarget(
136
platform: string,
147
arch: string,
15-
glibc?: string | undefined,
8+
options?: { glibc?: string | undefined } | undefined,
169
): string {
10+
const { glibc } = { __proto__: null, ...options }
1711
const target = `${platform}-${arch}${platform === 'linux' && !glibc ? '-musl' : ''}`
1812
if (!(SEA_TARGETS as readonly string[]).includes(target)) {
1913
throw new Error(

0 commit comments

Comments
 (0)