From 6a8ecde9a51132c75080155e7eb0caefa59e3e82 Mon Sep 17 00:00:00 2001 From: NahumDev <60716442+NahumOchoa@users.noreply.github.com> Date: Fri, 9 Oct 2026 01:17:20 -0600 Subject: [PATCH 1/2] Prepare 0.1.3 native renders and public lock --- .github/workflows/release.yml | 17 +- .github/workflows/tag.yml | 17 ++ .github/workflows/test.yml | 22 ++ README.md | 27 +- TARGET.bound | 515 ++++++++++++++++++--------------- capsule.bound | 27 -- package-lock.json | 47 ++- package.json | 14 +- receipts.bound | 189 +++++++++++- src/helpers/pipeline.ts | 2 +- src/helpers/place.ts | 47 ++- src/helpers/world.ts | 34 --- src/index.ts | 20 +- src/regions/github-actions.ts | 8 +- test/workflow-contract.test.ts | 113 ++++++++ 15 files changed, 737 insertions(+), 362 deletions(-) create mode 100644 .github/workflows/tag.yml create mode 100644 .github/workflows/test.yml delete mode 100644 capsule.bound delete mode 100644 src/helpers/world.ts create mode 100644 test/workflow-contract.test.ts diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index c57eb3e..8d403b7 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -19,9 +19,20 @@ jobs: - uses: actions/setup-node@v4 with: node-version: 24 - - env: + - run: npm ci + - run: npm run build + - run: npm test + - id: artifact + env: GH_TOKEN: ${{ github.token }} run: | version="v$(node -p "require('./package.json').version")" - gh release view "$version" >/dev/null 2>&1 && exit 0 - gh release create "$version" "$(npm pack --silent)" --title "$version" --notes "$version" + asset="$(npm pack --silent)" + test -f "$asset" + expected="$(sha256sum "$asset")" + if ! gh release view "$version" >/dev/null 2>&1; then + gh release create "$version" "$asset" --title "$version" --notes "$version" + fi + gh release download "$version" --pattern "$(basename "$asset")" --dir "$RUNNER_TEMP/release-back" + actual="$(sha256sum "$RUNNER_TEMP/release-back/$(basename "$asset")")" + test "${expected%% *}" = "${actual%% *}" diff --git a/.github/workflows/tag.yml b/.github/workflows/tag.yml new file mode 100644 index 0000000..9de0465 --- /dev/null +++ b/.github/workflows/tag.yml @@ -0,0 +1,17 @@ +name: tag +on: + push: + branches: [main] +jobs: + tag: + runs-on: ubuntu-latest + permissions: + contents: write + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + - run: | + version="v$(node -p "require('./package.json').version")" + git tag --list "$version" | grep -q . && exit 0 + git tag "$version" && git push origin "$version" diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml new file mode 100644 index 0000000..61b3d22 --- /dev/null +++ b/.github/workflows/test.yml @@ -0,0 +1,22 @@ +name: test +on: + push: + branches: [main] + pull_request: +jobs: + test: + strategy: + matrix: + node: [22, 24] + runs-on: ubuntu-latest + permissions: + contents: read + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-node@v4 + with: + node-version: ${{ matrix.node }} + - run: npm ci + - run: npm run build + - run: npm test + - run: npm pack --silent diff --git a/README.md b/README.md index 3a94502..e1919fd 100644 --- a/README.md +++ b/README.md @@ -1,34 +1,9 @@ # @lapxo/topos-github -![version 0.1.2](https://img.shields.io/badge/version-0.1.2-8c959f) ![license MIT](https://img.shields.io/badge/license-MIT-8c959f) ![node >=22.12](https://img.shields.io/badge/node-%3E%3D22.12-8c959f) ![dependencies 1](https://img.shields.io/badge/dependencies-1-8c959f) ![cases 0 hold](https://img.shields.io/badge/cases-0_hold-8c959f) ![verify none](https://img.shields.io/badge/verify-none-8c959f) +![license MIT](https://img.shields.io/badge/license-MIT-8c959f) The forge a place asks for, rendered from its lines: the workflows that test, tag and release it, and what its repository never holds. ## Why a line A workflow is a line of the place. A release is the tag that workflow cuts. A repository holds only what its ignore line allows. - -## One repository - -

declares , runs on , reaches, 3 regions, the longest of them 0 lines, 0 vector files, each held from the blob, pinned by topos-github and run by the host

- -## Line - -Add to your lock: -sources/topos-github value=github:Lapxo/topos-github -uses/topos-github sha256: -https://github.com/Lapxo/topos-github/releases -Fetch the release asset, verify its sha256 equals the uses/ line, place it in bound/cas/blobs/. Fold: its pages appear. -open: line/install needs=host/resolve — when bound resolves sources/ itself, the fetch line leaves the page by fold. - -It rests on topos. - -## Check - -● 0 cases hold - -● `npm ci && npm run build` - -## Pointers - -- [Reference](docs/reference.md) diff --git a/TARGET.bound b/TARGET.bound index f6b5323..7da4935 100644 --- a/TARGET.bound +++ b/TARGET.bound @@ -1,36 +1,159 @@ -bound-lock/1 at=place:topos-github by=target form=alphabet measure=status role=writes scope=publish/bootstrap value=topos-github -bound-lock/1 at=policy:keys by=owner epoch=9 form=alphabet measure=class role=reads scope=keys/owner sig="sha256:58f1f0983fe65f062bebefd0a6ffc901049c67525ef12dd86ed4dbb7a184b834:z1+6gtFVPc3MfHCK2FUOfqyuPjZDSefYTfkQkcILMfMlRRnmne1mY9BpiO4QqoH0q9gNt2wCLlpQ+sldM+4tCg==" value=authorize -bound-lock/1 at=policy:keys by=owner epoch=9 form=alphabet measure=coverage role=reads scope=keys/owner sig="sha256:58f1f0983fe65f062bebefd0a6ffc901049c67525ef12dd86ed4dbb7a184b834:gdr4oPiX4pWLNOzhwWcALHKr2zGHo906NoHpymaXTLq1f6Z7icy0gmEn2/smtcjlfAqv/Tr3jbb1nWM23L8QDQ==" value=* -bound-lock/1 at=policy:keys by=owner epoch=9 form=alphabet measure=public-key role=reads scope=keys/owner sig="sha256:58f1f0983fe65f062bebefd0a6ffc901049c67525ef12dd86ed4dbb7a184b834:vAdWbDyY9geq4MaZj39T9A2o+00zb1Mnr2wLzW7w2ZMrgMJjM0abvmVtsRwTaFwfkkJEGDBb0QuNaKmEE5sIDQ==" value="MCowBQYDK2VwAyEAIYI0be8OWhf3HcVceKpibjgZ+hbYJKYO5ayX8Kk16LE=" -bound-lock/1 at=policy:keys by=owner epoch=9 form=interval measure=resolution role=reads scope=keys/owner sig="sha256:58f1f0983fe65f062bebefd0a6ffc901049c67525ef12dd86ed4dbb7a184b834:m/Pm3pk3THBm5Wah79TmXgxq9qpnwWZ6R4a2UvJdTJnJthquUsLMXgcUBagynG/h/WgakNTL6vB+pbL8WnogAQ==" value=1..16 -bound-lock/1 about="the key this lock admits to write what the tree is read as: a reader speaks only what it observed, and the lock says which key that is" at=policy:keys by=owner epoch=22 form=alphabet measure=class role=reads scope=keys/reader sig="sha256:58f1f0983fe65f062bebefd0a6ffc901049c67525ef12dd86ed4dbb7a184b834:+GFCyG3ntO7YFHrDvyii+/Lu3voIpq4HbByzO/LgLUXfXKV5lvp62DDC0+DXalYDw0Cc15mkkculj1UPeQJSDw==" value=read -bound-lock/1 at=policy:keys by=owner epoch=22 form=alphabet measure=coverage role=reads scope=keys/reader sig="sha256:58f1f0983fe65f062bebefd0a6ffc901049c67525ef12dd86ed4dbb7a184b834:bd3JgJ3/P/6zqLo19xwgq+ZrAklwuT7mHMI6yuqU8ayfAZid0gSyVV7xWKuAzwsfgtTuKWuUadfNK5FmnqyUAA==" value=* -bound-lock/1 at=policy:keys by=owner epoch=10 form=alphabet measure=class role=reads scope=keys/verify sig="sha256:58f1f0983fe65f062bebefd0a6ffc901049c67525ef12dd86ed4dbb7a184b834:Q6liul128VZBmQNTlcIx8QK/k8oJsD3JMwaxZ1FinaIkj8ZZA4pcOm1cZbp/yuxgNymJrBR8IQ0ZpahV0ACZCQ==" value=attest -bound-lock/1 at=policy:keys by=owner epoch=10 form=alphabet measure=coverage role=reads scope=keys/verify sig="sha256:58f1f0983fe65f062bebefd0a6ffc901049c67525ef12dd86ed4dbb7a184b834:jxZ1478dEngHANVcHA15tSE+fBlgUeqQnmRLmg/vK7Mk94njKFBZnh+ccye/dpY01zwc5XmDbi2p6Q8+45uvCQ==" value=verify -bound-lock/1 at=policy:keys by=owner epoch=10 form=alphabet measure=public-key role=reads scope=keys/verify sig="sha256:58f1f0983fe65f062bebefd0a6ffc901049c67525ef12dd86ed4dbb7a184b834:YXaWrvwPsC/XULzvHV3r/2oS9cFytiEEcdjhJi3+omwNmdVykyVPUnqltKKMv65YbjJ+BCxrVKRmI/MY8fG0DQ==" value="MCowBQYDK2VwAyEACLnnkNAHf4V7vXG4cCZv6rM7suRwGTe0MJoqqCUxnvw=" -bound-lock/1 at=policy:keys by=owner epoch=10 form=interval measure=resolution role=reads scope=keys/verify sig="sha256:58f1f0983fe65f062bebefd0a6ffc901049c67525ef12dd86ed4dbb7a184b834:Do/XC5Jz7KbVhPNGZkUID1c7w8L0CEMzblgBpU3UEBjfkIs/X6I9ScrAeL3lGYXBY8hYUDohw5kWO85bSlQuDQ==" value=1..16 -bound-lock/1 at=policy:hazard/zero by=target form=interval measure=count role=reads scope=hazard/**/src/** value=0..0 -bound-lock/1 at=policy:tree/comments-few by=target form=interval measure=per-file role=reads scope=comments/*/src/** value=0..3 -bound-lock/1 at=policy:place/removal by=target form=interval measure=removed-by-hand role=reads scope=audit/nothing-is-removed-by-hand value=0..0 -bound-lock/1 at=policy:place/orphans by=target form=interval measure=orphan-samples role=reads scope=audit/orphans value=0..0 -bound-lock/1 at=policy:place/dist by=target form=interval measure=shipped-beside-code role=reads scope=audit/dist-holds-js-and-dts value=0..0 -bound-lock/1 at=policy:pages/mode by=target form=interval measure=prose-marks role=reads scope=audit/docs-have-a-mode value=0..0 -bound-lock/1 at=policy:pages/same by=target form=interval measure=rendered-leaves-differ role=reads scope=audit/rendered-docs-match value=0..0 -bound-lock/1 at=policy:security/acts by=target form=interval measure=acts-on-unnamed-hosts role=reads scope=audit/agent-acts-are-effects value=0..0 -bound-lock/1 at=policy:view by=target form=alphabet measure=id role=demands scope=view/manifest shape=package.json value=published-manifest -bound-lock/1 at=place:topos-github by=target form=alphabet measure=id needs=README.md role=demands scope=view/readme-capsule shape=README.md value=hero|door|idea|figure-world|claims|install|reading|how-they-rest|check|pointers -bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=reads scope=region/source value=src/**/*.ts -bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=reads scope=region/vocabulary value=src/**/*.ts -bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=reads scope=region/said value=src/**/*.ts -bound-lock/1 at=policy:reader by=target form=alphabet kind=js measure=reader needs=src/ role=reads scope=reader/said/source shape=*.ts value=topos-typescript-tree/src/regions/said.ts -bound-lock/1 at=policy:view by=target form=alphabet measure=id needs=src/index.ts role=demands scope=view/index shape=src/index.ts value=index -bound-lock/1 at=policy:view by=target form=alphabet measure=id needs=docs/img/world.svg role=demands scope=view/figure-world shape=docs/img/world.svg value=figure-world@1 -bound-lock/1 at=policy:view by=target form=alphabet measure=id role=demands scope=view/receipts shape=receipts.bound value=receipts@0|receipts@1 -bound-lock/1 at=policy:release by=target form=alphabet measure=id role=demands scope=release/rebirth value=rebirth -bound-lock/1 at=place:topos-github by=target form=alphabet measure=id role=writes scope=uses/topos-node value=sha256:16a90bc2af57ea8bad6525588a0748c7dc1aaae276bc9680761f9186a10ad8b2 -bound-lock/1 at=place:topos-github by=target form=alphabet measure=id role=writes scope=uses/topos-typescript-tree value=sha256:33ddd7774c8fb05403b95eeb342744b60b9a6e6aabbee3ed9db380656cc6b751 +bound-lock/1 about="**{name}** · {answer}" at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/reading/view value=lock +bound-lock/1 about="A workflow is a line of the place. A release is the tag that workflow cuts. A repository holds only what its ignore line allows." at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/idea value=lock +bound-lock/1 about="A world for a repository's workflows and its releases." at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/door/what value=lock +bound-lock/1 about="Cite it as {name}." at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/cff/name value=lock +bound-lock/1 about="Clone, `{check}`. A leaf that differs from what its lines render is the contribution: send it with the lines it was handed.\nNothing else is asked. Lines land through the fold, never by hand; a page and the lock disagree, the lock is right." at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/contributing value=lock +bound-lock/1 about="Each region answers one question." at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/reading/lead value=lock +bound-lock/1 about="How to read it" at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/reading/heading value=lock +bound-lock/1 about="It costs {dependencies} dependencies." at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/claims/1-costs value=lock +bound-lock/1 about="It rests on {names}." at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/rests/on value=lock +bound-lock/1 about="MIT License\n\nCopyright (c) 2026 Lapxo\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE." at=policy:license by=target form=alphabet measure=id role=demands scope=license value=MIT +bound-lock/1 about="One repository" at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/heading value=lock +bound-lock/1 about="Restore the illustration only with a formed example and native evidence delivered to its view." at=witness:verified-render-contract by=target form=alphabet measure=id role=demands scope=plan/render/figure-world value=unpaid +bound-lock/1 about="The historical index view has no provider; source entry points are not generated by a file-fold renderer." at=witness:verified-render-contract by=target form=alphabet measure=id role=demands scope=plan/render/index value=unpaid +bound-lock/1 about="What it claims" at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/claims/heading value=lock +bound-lock/1 about="Why a line" at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/idea/heading value=lock +bound-lock/1 about="Workflows, releases, and what a repository never holds." at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/what value=lock +bound-lock/1 about="[The whole example]({at})" at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/learn/source value=lock +bound-lock/1 about="a page to learn from one example: the cell it draws, what it calls and prints, the law it shows, its form, and where it lives; the example is the one the page is named after" at=policy:region by=target form=alphabet measure=text role=writes scope=region/learn value=lock +bound-lock/1 about="a page to learn from the in-phase example: the cell it draws, what it calls and prints, the law it shows, its form, and where it lives" at=policy:region by=target form=alphabet measure=text role=writes scope=region/learn-in-phase value=lock +bound-lock/1 about="a page to learn from the price example: the cell it draws, what it calls and prints, the law it shows, its form, and where it lives" at=policy:region by=target form=alphabet measure=text role=writes scope=region/learn-price value=lock +bound-lock/1 about="a page to learn from the signature example: the cell it draws, what it calls and prints, the law it shows, its form, and where it lives" at=policy:region by=target form=alphabet measure=text role=writes scope=region/learn-signature value=lock +bound-lock/1 about="a page to learn from the thermometer example: the cell it draws, what it calls and prints, the law it shows, its form, and where it lives" at=policy:region by=target form=alphabet measure=text role=writes scope=region/learn-thermometer value=lock +bound-lock/1 about="a page to learn from the withdrawal example: the cell it draws, what it calls and prints, the law it shows, its form, and where it lives" at=policy:region by=target form=alphabet measure=text role=writes scope=region/learn-withdrawal value=lock +bound-lock/1 about="a place adopts it with {scope}" at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/adopted value=lock +bound-lock/1 about="against topos {digest}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/topos value=lock +bound-lock/1 about="declares {domain}, runs on {runtime}, reaches {effects}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/declares value=lock +bound-lock/1 about="each key, what it has signed and what it may sign" at=policy:region/signers by=target form=alphabet measure=text role=writes scope=region/signers value=lock +bound-lock/1 about="each place the owner has said what it is, in the order they rest on each other, with its state as a colour and what the fold counts of it: paid, hazards open, and what the second head says" at=policy:region by=target form=alphabet measure=text role=writes scope=region/places value=lock +bound-lock/1 about="each signer as a life: what it signed, what it left free and where it forked" at=policy:region/biography by=target form=alphabet measure=text role=writes scope=region/biography value=lock +bound-lock/1 about="every ceiling a reading is over, and every demand nothing paid" at=policy:region/red by=target form=alphabet measure=text role=writes scope=region/red value=lock +bound-lock/1 about="every conjecture of a place as the thing it is: who met it, with what, how together their claims arrived, and whether anything has closed it" at=policy:region/census by=target form=alphabet measure=text role=writes scope=region/census value=readings +bound-lock/1 about="every conjecture of the place, marked as such, with what would falsify it" at=policy:region by=target form=alphabet measure=text role=writes scope=region/open-conjectures value=lock +bound-lock/1 about="every conjecture with the falsifier its own line names" at=policy:region/conjectures by=target form=alphabet measure=text role=writes scope=region/conjectures value=leaves +bound-lock/1 about="every operation offered, with how many vectors reached it" at=policy:region/offers by=target form=alphabet measure=text role=writes scope=region/offers value=readings +bound-lock/1 about="every operation with its signature, its derived refusals, what it reaches and the laws it rests on; every law with its kind, view, premises, sentence and whether it reproduces; every form" at=policy:region by=target form=alphabet measure=text role=writes scope=region/reference value=lock +bound-lock/1 about="four real calls and what each of them answers" at=policy:region/thirty-seconds by=target form=alphabet measure=text role=writes scope=region/thirty-seconds value=prose +bound-lock/1 about="how many epochs a region spans, from its first line to its last" at=policy:region/width by=target form=alphabet measure=text role=writes scope=region/width value=lock-and-readings +bound-lock/1 about="how many of those epochs it was actually spoken in" at=policy:region/rhythm by=target form=alphabet measure=text role=writes scope=region/rhythm value=lock-and-readings +bound-lock/1 about="how not to believe any of it: the command a clone runs today, and the one that runs the cases with bound once it ships, with how many there are; the repository only once it resolves" at=policy:region by=target form=alphabet measure=text role=writes scope=region/check value=lock +bound-lock/1 about="how often each region of the tree was read" at=policy:region/region-frequency by=target form=alphabet measure=text role=writes scope=region/region-frequency value=readings +bound-lock/1 about="how the places rest on each other, drawn from the lock's dependency lines and folded until asked for" at=policy:region by=target form=alphabet measure=text role=writes scope=region/how-they-rest value=lock +bound-lock/1 about="how together a region arrived, one when every line landed at the same turn of the period" at=policy:region/coherence by=target form=alphabet measure=text role=writes scope=region/coherence value=lock-and-readings +bound-lock/1 about="its leaf" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/regions/leaf value=lock +bound-lock/1 about="its regions, read off its own descriptor" at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/door/words value=lock +bound-lock/1 about="lines that stand on one origin and are therefore not yet information" at=policy:region/grey by=target form=alphabet measure=text role=writes scope=region/grey value=lock +bound-lock/1 about="packed as {digest}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/blob value=lock +bound-lock/1 about="pinned by {place}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/pinned value=lock +bound-lock/1 about="publish the version once, by the trusted publisher" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pipeline/publish value=lock +bound-lock/1 about="publish the version once, by the trusted publisher" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/pipeline/publish value=lock +bound-lock/1 about="release the version with its tarball, once" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pipeline/release value=lock +bound-lock/1 about="release the version with its tarball, once" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/pipeline/release value=lock +bound-lock/1 about="run by the {runtime} host" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/host value=lock +bound-lock/1 about="tag the version the manifest names, once" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pipeline/tag value=lock +bound-lock/1 about="tag the version the manifest names, once" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/pipeline/tag value=lock +bound-lock/1 about="the axioms of a place, the three most rested on spelled out in their own words" at=policy:region/axioms by=target form=alphabet measure=text role=writes scope=region/axioms value=leaves +bound-lock/1 about="the cases a place holds and which of them did not hold, read from what the runner already answered rather than run again" at=policy:region/vectors by=target form=alphabet measure=text role=writes scope=region/vectors value=readings +bound-lock/1 about="the cell of an example drawn at a resolution: at zero three bars, above it each claim a bar, what they hold together a bar in the colour of a meeting, and its floor and its ceiling named" at=policy:region by=target form=alphabet measure=text role=writes scope=region/ranges value=lock +bound-lock/1 about="the cell of the shortest example, drawn, with the legend of its marks as its caption" at=policy:region by=target form=alphabet measure=text role=writes scope=region/figure value=lock +bound-lock/1 about="the check a clone runs alone: the subpaths the manifest offers, imported, and the second head's signed word, verified against the key the lock admits and the digest of the lock itself" at=policy:region by=target form=alphabet measure=text role=writes scope=region/selfcheck value=lock +bound-lock/1 about="the check command, which is owed" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/guide/owed value=lock +bound-lock/1 about="the check the forge runs on every push and every proposal" at=policy:region by=target form=alphabet measure=text role=writes scope=region/pipeline-test value=lock +bound-lock/1 about="the citation a forge offers with one click, from the lines that already say it: the software by its name, version, author, repository and licence, and the paper it rests on as the citation the forge prefers" at=policy:region by=target form=alphabet measure=text role=writes scope=region/cff value=lock +bound-lock/1 about="the commands the owner gives, and a grey mark while the verb they call is not published" at=policy:region by=target form=alphabet measure=text role=writes scope=region/commands value=lock +bound-lock/1 about="the facts of the lock as badges a reader recognizes: version, licence, engine, dependencies, the cases that hold, what the second head says, grey until the instrument that runs it is published, and the paper's identifier" at=policy:region by=target form=alphabet measure=text role=writes scope=region/badges value=lock +bound-lock/1 about="the figure a region makes: a point, an edge, or a polygon" at=policy:region/shape by=target form=alphabet measure=text role=writes scope=region/shape value=lock-and-readings +bound-lock/1 about="the first screen of the root: its name, the figure one of its places draws, and one sentence of what the places are together" at=policy:region by=target form=alphabet measure=text role=writes scope=region/door value=lock +bound-lock/1 about="the first screen: the mark the place is known by, its name, the badges its lock reads to, and the one line of what it is; what is not signed is not on it" at=policy:region by=target form=alphabet measure=text role=writes scope=region/hero value=lock +bound-lock/1 about="the forge a place asks for, rendered from its lines: the workflows that test, tag and release it, and what its repository never holds" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/what value=lock +bound-lock/1 about="the guide at resolution zero: five lines, the command that checks the place, how many conjectures are open, and that nothing else is asked" at=policy:region by=target form=alphabet measure=text role=writes scope=region/guide-at-zero value=lock +bound-lock/1 about="the key this lock admits to write what the tree is read as: a reader speaks only what it observed, and the lock says which key that is" at=policy:keys by=target form=alphabet measure=class role=reads scope=keys/reader value=read +bound-lock/1 about="the legend of the marks a page is drawn in, in the owner's words" at=policy:region by=target form=alphabet measure=text role=writes scope=region/marks value=lock +bound-lock/1 about="the licence, carried on a line of the lock and rendered into its own leaf" at=policy:region/license by=target form=alphabet measure=text role=writes scope=region/license value=lock +bound-lock/1 about="the lines a later line replaced, with when they were replaced" at=policy:region/history by=target form=alphabet measure=text role=writes scope=region/history value=lock +bound-lock/1 about="the lock a place is published with, seen from inside it: the bootstrap first, the wire and the keys it is read with, the regions it is written in, its own lines and every line a view of it reads, with the place's name gone from every scope, need, policy and cone; nothing of the tree's history and nothing that needs outside the place" at=policy:region by=target form=alphabet measure=text role=writes scope=region/published-lock value=lock +bound-lock/1 about="the lock lines a place holds in its own files, unsigned, as they are written there" at=policy:region/lock-line by=target form=alphabet measure=text role=writes scope=region/lock-line value=leaves +bound-lock/1 about="the manifest the package carries, rendered from the same lines without the three fields only this tree's resolver reads: what npm packs and a consumer installs" at=policy:region/published-manifest by=target form=alphabet measure=text role=writes scope=region/published-manifest value=lock +bound-lock/1 about="the manifest the place holds, rendered from the lines it signs about itself: the fields a consumer reads and the three a resolver older than exports still needs in this tree" at=policy:region/manifest by=target form=alphabet measure=text role=writes scope=region/manifest value=lock +bound-lock/1 about="the notation of the object at a resolution: at zero the tuple a cell is; at one the tuple and the formulas of what it rests on, in the order they rest; at three each formula beside its law's sentence; at eight all of it with the signature of every arrow and the states" at=policy:region by=target form=alphabet measure=text role=writes scope=region/notation value=lock +bound-lock/1 about="the obligatory as its definition says it, with the four states and the parts it is made of" at=policy:region by=target form=alphabet measure=text role=writes scope=region/the-object value=lock +bound-lock/1 about="the one line that installs it: the verb the lock names, then the name its manifest carries" at=policy:region by=target form=alphabet measure=text role=writes scope=region/install value=lock +bound-lock/1 about="the one line that says what this place is: claims, demands paid, ceilings met, what the second head said, and what a fold of it costs" at=policy:region/programs by=target form=alphabet measure=text role=writes scope=region/programs value=lock +bound-lock/1 about="the open questions of a place, as the lock asks them" at=policy:region/question by=target form=alphabet measure=text role=writes scope=region/question value=lock +bound-lock/1 about="the options a place builds with, each from its own line" at=policy:region by=target form=alphabet measure=text role=writes scope=region/build value=lock +bound-lock/1 about="the pages below the door, as links from the views that write them: the reference and the pages to learn from; the forge shows the guide and the licence itself" at=policy:region by=target form=alphabet measure=text role=writes scope=region/pointers value=lock +bound-lock/1 about="the paper: the owner's words on what it proves, then the reference a reader copies, its authors, year, title, version, publisher and address" at=policy:region by=target form=alphabet measure=text role=writes scope=region/the-paper value=lock +bound-lock/1 about="the prose a place keeps beside its source, read as paragraphs and never as headings" at=policy:region/why by=target form=alphabet measure=text role=writes scope=region/why value=leaves +bound-lock/1 about="the question that costs least to close next" at=policy:region/cheapest-closer by=target form=alphabet measure=text role=writes scope=region/cheapest-closer value=lock +bound-lock/1 about="the questions with no answer yet, widest first" at=policy:region/open-questions by=target form=alphabet measure=text role=writes scope=region/open-questions value=lock +bound-lock/1 about="the receipts a place is published with: what it observed, seen from inside it, without the word the tree's second head gave, since the published place asks its own" at=policy:region by=target form=alphabet measure=text role=writes scope=region/published-receipts value=lock +bound-lock/1 about="the regions spoken in at more than two epochs" at=policy:region/resonance by=target form=alphabet measure=text role=writes scope=region/resonance value=lock +bound-lock/1 about="the regions spoken in less this epoch than last" at=policy:region/receding by=target form=alphabet measure=text role=writes scope=region/receding value=lock +bound-lock/1 about="the regions spoken in more this epoch than last" at=policy:region/approaching by=target form=alphabet measure=text role=writes scope=region/approaching value=lock +bound-lock/1 about="the release the forge makes after the tag: the version published once by the trusted publisher, and its tarball attached" at=policy:region by=target form=alphabet measure=text role=writes scope=region/pipeline-release value=lock +bound-lock/1 about="the scale the shortest example draws: each claim as a bar and what they hold together beneath them" at=policy:region by=target form=alphabet measure=text role=writes scope=region/picture value=lock +bound-lock/1 about="the shortest example this package ships and what it prints, with the digest the lock pins for it" at=policy:region by=target form=alphabet measure=text role=writes scope=region/first-use value=lock +bound-lock/1 about="the tag the forge makes for the version the manifest names, once" at=policy:region by=target form=alphabet measure=text role=writes scope=region/pipeline-tag value=lock +bound-lock/1 about="the theory of a place as its lists, each law with what met it and what would break it" at=policy:region/laws by=target form=alphabet measure=text role=writes scope=region/laws value=readings +bound-lock/1 about="the three axioms the rest leans on hardest by their sentence, the others by name, and one theorem meeting its measurement" at=policy:region by=target form=alphabet measure=text role=writes scope=region/what-holds value=lock +bound-lock/1 about="the whole idea in one picture, before any name is introduced" at=policy:region/idea by=target form=alphabet measure=text role=writes scope=region/idea value=prose +bound-lock/1 about="two readings of one cell that do not meet, with both sides named" at=policy:region/forks by=target form=alphabet measure=text role=writes scope=region/forks value=lock +bound-lock/1 about="what a demand costs to pay and what paying it lands" at=policy:region/take by=target form=alphabet measure=text role=writes scope=region/take value=lock +bound-lock/1 about="what a line is worth beyond what it says, in bits still free" at=policy:region/premium by=target form=alphabet measure=text role=writes scope=region/premium value=lock +bound-lock/1 about="what a package carries of its own reading, so a clone folds without running anything" at=policy:region/receipts by=target form=alphabet measure=text role=writes scope=region/receipts value=readings +bound-lock/1 about="what a place holds that nothing reaches: a test or a sample no demand names and no run reads, and a page no view writes and no demand needs" at=policy:region by=target form=alphabet measure=text role=writes scope=region/orphans value=lock +bound-lock/1 about="what a repository of the place never holds, one line each" at=policy:region by=target form=alphabet measure=text role=writes scope=region/ignore value=lock +bound-lock/1 about="what a tree has not answered, one card per cell: its cone by digest, its ceiling, its origins and each state it could take with what that state would be worth" at=policy:region/cells by=target form=alphabet measure=text role=writes scope=region/cells value=lock +bound-lock/1 about="what each leaf of the place is, written or rendered, so a page says which of its own files were never typed" at=policy:region/role by=target form=alphabet measure=text role=writes scope=region/role value=leaves +bound-lock/1 about="what is open in each place, folded until asked for: conjectures, hazards by kind, and demands not yet paid" at=policy:region by=target form=alphabet measure=text role=writes scope=region/what-is-open value=lock +bound-lock/1 about="what is still undecided, in bits, by region and by the epoch it was born in" at=policy:region/freedom by=target form=alphabet measure=text role=writes scope=region/freedom value=lock +bound-lock/1 about="what it takes to sign here, and who may" at=policy:region/sign by=target form=alphabet measure=text role=writes scope=region/sign value=lock +bound-lock/1 about="what lies where in the source, counted from the tree itself" at=policy:region/folders by=target form=alphabet measure=text role=writes scope=region/folders value=leaves +bound-lock/1 about="what rests on each line, so what would move if it moved is known before it moves" at=policy:region/dependents by=target form=alphabet measure=text role=writes scope=region/dependents value=lock +bound-lock/1 about="what runs here and what is read, said apart" at=policy:region/environments by=target form=alphabet measure=text role=writes scope=region/environments value=prose +bound-lock/1 about="what the object rests on, drawn: the definition most offers rest on and the lines it rests on, each by its name" at=policy:region by=target form=alphabet measure=text role=writes scope=region/rests value=lock +bound-lock/1 about="what the package attacks for an engineer, a mathematician and a physicist, in the owner's words" at=policy:region by=target form=alphabet measure=text role=writes scope=region/audiences value=lock +bound-lock/1 about="what the theory proves and which views implement it" at=policy:region/paper by=target form=alphabet measure=text role=writes scope=region/paper value=prose +bound-lock/1 about="what this place takes from another, by name" at=policy:region/consumes by=target form=alphabet measure=text role=writes scope=region/consumes value=readings +bound-lock/1 about="what this work cites and by what identifier" at=policy:region/cite by=target form=alphabet measure=text role=writes scope=region/cite value=readings +bound-lock/1 about="where looking is worth most, in bits per place" at=policy:region/gaze by=target form=alphabet measure=text role=writes scope=region/gaze value=lock +bound-lock/1 about="where the package goes next, in the owner's words, in four lines at most" at=policy:region by=target form=alphabet measure=text role=writes scope=region/where-next value=lock +bound-lock/1 about="where this place stands in the tree it belongs to" at=policy:region/scene by=target form=alphabet measure=text role=writes scope=region/scene value=lock +bound-lock/1 about="whether a region holds without any one of its origins" at=policy:region/robustness by=target form=alphabet measure=text role=writes scope=region/robustness value=lock-and-readings +bound-lock/1 about="which view answers which question, in the words each view says of itself" at=policy:region by=target form=alphabet measure=text role=writes scope=region/reading value=lock +bound-lock/1 about="who spoke in each region of the tree, head and reader alike" at=policy:region/origins by=target form=alphabet measure=text role=writes scope=region/origins value=lock-and-readings +bound-lock/1 about="{count} hold" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/badge/held value=lock +bound-lock/1 about="{count} meet at {lo}..{hi}: {state}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/cell/together value=lock +bound-lock/1 about="{count} meet at {lo}..{hi}; {who} is apart: {state}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/cell/outlier value=lock +bound-lock/1 about="{count} regions, each read off the lines its descriptor declares and nothing else; it reaches {effects} beyond them." at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/regions/lead value=lock +bound-lock/1 about="{count} regions, the longest of them {longest} lines" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/regions value=lock +bound-lock/1 about="{count} vector files, each held from the blob" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/vectors value=lock +bound-lock/1 about="{glyph} `{check}`" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/check/command value=lock +bound-lock/1 about="{glyph} {count} cases hold" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/check/held value=lock +bound-lock/1 about="{name} reads {reads}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/region value=lock +bound-lock/1 about="{name}@{version} is published" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pipeline/published value=lock +bound-lock/1 about="{name}@{version} is published" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/pipeline/published value=lock +bound-lock/1 about="{version} is released" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pipeline/released value=lock +bound-lock/1 about="{version} is released" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/pipeline/released value=lock +bound-lock/1 about="{version} is tagged" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pipeline/tagged value=lock +bound-lock/1 about="{version} is tagged" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/pipeline/tagged value=lock +bound-lock/1 about="{version}, as its lock holds it" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pipeline/notes value=lock +bound-lock/1 about="{version}, as its lock holds it" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/pipeline/notes value=lock +bound-lock/1 about="| region | reads | writes |" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/regions/table value=lock +bound-lock/1 about=Check at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/check/heading value=lock +bound-lock/1 about=Contributing at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/guide/heading value=lock +bound-lock/1 about=Pointers at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pointers/heading value=lock +bound-lock/1 about=Reference at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/regions/heading value=lock +bound-lock/1 about=cases at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/badge/cases value=lock +bound-lock/1 about=dependencies at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/badge/dependencies value=lock +bound-lock/1 about=license at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/badge/license value=lock +bound-lock/1 about=node at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/badge/engines value=lock +bound-lock/1 about=receipt at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/claims/receipt value=lock +bound-lock/1 about=verify at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/badge/verify value=lock +bound-lock/1 about=version at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/badge/version value=lock bound-lock/1 at=place:topos-github by=target form=alphabet measure=id role=writes scope=sources/topos-github value=github:Lapxo/topos-github -bound-lock/1 at=policy:version by=target form=alphabet measure=id needs=package.json role=writes scope=version shape=package.json value=0.1.2 +bound-lock/1 at=place:topos-github by=target form=alphabet measure=status role=writes scope=publish/bootstrap value=topos-github +bound-lock/1 at=place:topos-measure/release by=target form=alphabet measure=id role=demands scope=view/pipeline-release shape=.github/workflows/release.yml value=github-actions bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/acts value="observe:role=writes|withdraw:value=withdraw|sign:reads,interval,hi|require:reads,interval,lo|join:widening,at=witness|refine:@res" bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/at-classes value=origin|place|receipt|witness|policy bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/badges/world value=version|license|engines|dependencies|cases|verify|doi @@ -52,27 +175,53 @@ bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/offers/world value="artifacts=src/**/*.js\\|src/**/*.ts|capsules=./|concepts=src/**/*.ts|hazards=**|laws=**/*.bound|packages=package.json\\|tsconfig.json|said=src/**/*.ts|source=src/**/*.ts|vocabulary=src/**/*.ts" bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/pipeline/world value="branch=main|runtime=22|version=node -p \"require('./package.json').version\"" bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/questions value=source/answers|source/arrow|source/calls|source/carries|source/declared|source/lang|source/literal|source/returns|source/signature|source/union -bound-lock/1 at=policy:audit by=target form=alphabet measure=resolution role=reads scope=audit/wire/receipts value=0|1|8 -bound-lock/1 at=policy:wire/region-measures by=target form=alphabet measure=id role=reads scope=audit/wire/region-measures value=coordinates|leaves bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/required value=scope|role|form|measure|value|by|at bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/roles value=reads|writes|demands|source|render|receipt bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/rows value=claim|held -bound-lock/1 at=policy:wire/shapes by=target form=alphabet measure=id role=reads scope=audit/wire/shapes value=decision|lock|package|reader|render|run|vector|view -bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/ships value=dist|README.md|LICENSE|TARGET.bound bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/signature-algorithms value=ed25519|sha256:58f1f0983fe65f062bebefd0a6ffc901049c67525ef12dd86ed4dbb7a184b834|ed25519:era1 -bound-lock/1 at=policy:wire/states by=target form=alphabet measure=id role=reads scope=audit/wire/states value=absent|present|unread|withdraw -bound-lock/1 at=policy:wire/templates by=target form=alphabet measure=id role=reads scope=audit/wire/templates value={cone}|{roots} bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/verdicts value=agrees|forks|stale|grey|none bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/views value=field|spectrum|ideal|chain|complement|dual|product|quotient|valuation|galois bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/views/world value=citation-file|gitignore|guide|manifest|pipeline-release|readme-capsule|reference-capsule|tsconfig bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/worlds/documents value=readme|markdown|svg|mermaid|cff|doi|badge bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/worlds/forge value=github|workflow bound-lock/1 at=policy:audit by=target form=alphabet measure=id role=reads scope=audit/wire/worlds/packages value=npm|tsconfig +bound-lock/1 at=policy:audit by=target form=alphabet measure=resolution role=reads scope=audit/wire/receipts value=0|1|8 +bound-lock/1 at=policy:author by=target form=alphabet measure=id needs=package.json role=writes scope=author shape=package.json value=Lapxo +bound-lock/1 at=policy:bound/011-port-release by=target form=alphabet measure=signer role=writes scope=keys/owner value=file +bound-lock/1 at=policy:bound/011-port-release by=target form=interval measure=bytes role=writes scope=signer/response-bytes value=1048576..1048576 +bound-lock/1 at=policy:bound/011-port-release by=target form=interval measure=milliseconds role=writes scope=signer/timeout value=30000..30000 +bound-lock/1 at=policy:bound/leaf-roles by=target form=alphabet measure=role role=reads scope=leaf-role/receipts.bound value=derived +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/allowImportingTsExtensions shape=tsconfig.json value=true +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/declaration shape=tsconfig.json value=true +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/esModuleInterop shape=tsconfig.json value=true +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/forceConsistentCasingInFileNames shape=tsconfig.json value=true +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/include shape=tsconfig.json value=src +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/incremental shape=tsconfig.json value=true +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/module shape=tsconfig.json value=NodeNext +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/moduleResolution shape=tsconfig.json value=NodeNext +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/noFallthroughCasesInSwitch shape=tsconfig.json value=true +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/noImplicitOverride shape=tsconfig.json value=true +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/noImplicitReturns shape=tsconfig.json value=true +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/outDir shape=tsconfig.json value=dist +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/rewriteRelativeImportExtensions shape=tsconfig.json value=true +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/rootDir shape=tsconfig.json value=src +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/skipLibCheck shape=tsconfig.json value=true +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/strict shape=tsconfig.json value=true +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/target shape=tsconfig.json value=ES2020 +bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/tsBuildInfoFile shape=tsconfig.json value=.cache/tsbuildinfo +bound-lock/1 at=policy:capsule/at-most-four-hundred by=target form=interval measure=count role=reads scope=lines/src/**/* value=0..400 +bound-lock/1 at=policy:capsule/customisation-is-the-places-lines by=target form=interval measure=count role=reads scope=source/customised/src/** value=0..0 +bound-lock/1 at=policy:capsule/language-facts-come-from-the-language-capsule by=target form=interval measure=count role=reads scope=source/lexed/src/** value=0..0 +bound-lock/1 at=policy:capsule/one-world by=target form=alphabet measure=id role=reads scope=literal/src/** value=not:readme|markdown|npm|tsconfig|cff|doi|badge +bound-lock/1 at=policy:capsule/reads-lines-and-receipts-only by=target form=interval measure=count role=reads scope=source/unread/src/** value=0..0 +bound-lock/1 at=policy:check by=target form=alphabet measure=id needs=package.json role=writes scope=check value="npm ci && npm run build" bound-lock/1 at=policy:cites by=target form=alphabet measure=author role=writes scope=cites/two-sided-constraints value="Ochoa, N." bound-lock/1 at=policy:cites by=target form=alphabet measure=doi role=writes scope=cites/two-sided-constraints value=10.5281/zenodo.21858428 bound-lock/1 at=policy:cites by=target form=alphabet measure=publisher role=writes scope=cites/two-sided-constraints value=Zenodo bound-lock/1 at=policy:cites by=target form=alphabet measure=version role=writes scope=cites/two-sided-constraints value=1.0.0 bound-lock/1 at=policy:cites by=target form=alphabet measure=year role=writes scope=cites/two-sided-constraints value=2026 +bound-lock/1 at=policy:engines by=target form=alphabet measure=id needs=package.json role=writes scope=engines shape=package.json value=">=22.12" +bound-lock/1 at=policy:exports by=target form=alphabet measure=id needs=package.json role=writes scope=exports shape=package.json value=dist/index bound-lock/1 at=policy:form by=target form=alphabet measure=id role=writes scope=form/figure/fold value=REQUIRED|FREE|CONFLICT bound-lock/1 at=policy:form by=target form=alphabet measure=id role=writes scope=form/figure/line value=scope|role|measure|form|value|at bound-lock/1 at=policy:form by=target form=alphabet measure=id role=writes scope=form/formula value=text|latex|mathml @@ -83,32 +232,6 @@ bound-lock/1 at=policy:form by=target form=alphabet measure=id role=writes scope bound-lock/1 at=policy:form by=target form=alphabet measure=id role=writes scope=form/prose/en/heading value=capital bound-lock/1 at=policy:form by=target form=alphabet measure=id role=writes scope=form/prose/en/list value=", | and " bound-lock/1 at=policy:form by=target form=alphabet measure=id role=writes scope=form/prose/en/numbers value=no|one|two|three|four|five|six|seven|eight|nine|ten|eleven|twelve -bound-lock/1 about=cases at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/badge/cases value=lock -bound-lock/1 about=dependencies at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/badge/dependencies value=lock -bound-lock/1 about=node at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/badge/engines value=lock -bound-lock/1 about="{count} hold" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/badge/held value=lock -bound-lock/1 about=license at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/badge/license value=lock -bound-lock/1 about=verify at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/badge/verify value=lock -bound-lock/1 about=version at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/badge/version value=lock -bound-lock/1 about="Cite it as {name}." at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/cff/name value=lock -bound-lock/1 about="{glyph} `{check}`" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/check/command value=lock -bound-lock/1 about=Check at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/check/heading value=lock -bound-lock/1 about="{glyph} {count} cases hold" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/check/held value=lock -bound-lock/1 about="Clone, `{check}`. A leaf that differs from what its lines render is the contribution: send it with the lines it was handed.\nNothing else is asked. Lines land through the fold, never by hand; a page and the lock disagree, the lock is right." at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/contributing value=lock -bound-lock/1 about=Contributing at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/guide/heading value=lock -bound-lock/1 about="the check command, which is owed" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/guide/owed value=lock -bound-lock/1 about="{version}, as its lock holds it" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pipeline/notes value=lock -bound-lock/1 about="publish the version once, by the trusted publisher" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pipeline/publish value=lock -bound-lock/1 about="{name}@{version} is published" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pipeline/published value=lock -bound-lock/1 about="release the version with its tarball, once" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pipeline/release value=lock -bound-lock/1 about="{version} is released" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pipeline/released value=lock -bound-lock/1 about="tag the version the manifest names, once" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pipeline/tag value=lock -bound-lock/1 about="{version} is tagged" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pipeline/tagged value=lock -bound-lock/1 about=Pointers at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pointers/heading value=lock -bound-lock/1 about=Reference at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/regions/heading value=lock -bound-lock/1 about="{count} regions, each read off the lines its descriptor declares and nothing else; it reaches {effects} beyond them." at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/regions/lead value=lock -bound-lock/1 about="its leaf" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/regions/leaf value=lock -bound-lock/1 about="| region | reads | writes |" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/regions/table value=lock bound-lock/1 at=policy:form by=target form=alphabet measure=id role=writes scope=form/prose/en/sentence value=capital|period bound-lock/1 at=policy:form by=target form=alphabet measure=id role=writes scope=form/prose/en/separator value=" · " bound-lock/1 at=policy:form by=target form=alphabet measure=id role=writes scope=form/prose/en/state/CONFLICT value="its origins are apart" @@ -264,170 +387,45 @@ bound-lock/1 at=policy:form by=target form=alphabet measure=id role=writes scope bound-lock/1 at=policy:form by=target form=alphabet measure=id role=writes scope=form/template/what-holds/other value=name|about bound-lock/1 at=policy:form by=target form=alphabet measure=id role=writes scope=form/template/what-holds/others value=count bound-lock/1 at=policy:form by=target form=alphabet measure=id role=writes scope=form/template/wire/blob value=hash -bound-lock/1 at=policy:topos/wire-page by=target form=alphabet measure=id role=writes scope=form/template/wire/canonical value=hash -bound-lock/1 at=policy:topos/wire-page by=target form=alphabet measure=id role=writes scope=form/template/wire/encoding value=encoding -bound-lock/1 at=policy:topos/wire-page by=target form=alphabet measure=id role=writes scope=form/template/wire/header value=header -bound-lock/1 at=policy:topos/wire-page by=target form=alphabet measure=id role=writes scope=form/template/wire/lead value=header|encoding -bound-lock/1 at=policy:topos/wire-page by=target form=alphabet measure=id role=writes scope=form/template/wire/order value=encoding +bound-lock/1 at=policy:hazard/zero by=target form=interval measure=count role=reads scope=hazard/**/src/** value=0..0 +bound-lock/1 at=policy:ignore by=target form=alphabet measure=id role=writes scope=ignore value=.bound/|dist/|node_modules/|.cache/ +bound-lock/1 at=policy:install by=target form=alphabet measure=id needs=package.json role=writes scope=install value="npm install" +bound-lock/1 at=policy:keys by=owner epoch=1 form=alphabet measure=public-key role=reads scope=keys/owner sig="ed25519:era1:f9v/MckzhV22QrzF/liHT/vPfN+mrn9PFChpcQQBRYw2y5tMlv+JcNo8XYthh8Seaia3N+CcbRW3mJaxafqSCw==" value="MCowBQYDK2VwAyEAIYI0be8OWhf3HcVceKpibjgZ+hbYJKYO5ayX8Kk16LE=" +bound-lock/1 at=policy:keys by=owner epoch=1 form=alphabet measure=public-key role=reads scope=keys/verify sig="ed25519:era1:vH9Edf77HqyUvWK9O/1s6E02C+AkMqUV9slcjUztxQ2P1N5knpLis+g9sVDuZ/zUwFdUsqtS0luRgis7rdXvCg==" value="MCowBQYDK2VwAyEACLnnkNAHf4V7vXG4cCZv6rM7suRwGTe0MJoqqCUxnvw=" +bound-lock/1 at=policy:keys by=target form=alphabet measure=class role=reads scope=keys/owner value=authorize +bound-lock/1 at=policy:keys by=target form=alphabet measure=class role=reads scope=keys/verify value=attest +bound-lock/1 at=policy:keys by=target form=alphabet measure=coverage role=reads scope=keys/owner value=* +bound-lock/1 at=policy:keys by=target form=alphabet measure=coverage role=reads scope=keys/reader value=* +bound-lock/1 at=policy:keys by=target form=alphabet measure=coverage role=reads scope=keys/verify value=verify +bound-lock/1 at=policy:keys by=target form=interval measure=resolution role=reads scope=keys/owner value=1..16 +bound-lock/1 at=policy:keys by=target form=interval measure=resolution role=reads scope=keys/verify value=1..16 +bound-lock/1 at=policy:keywords by=target form=alphabet measure=id needs=package.json role=writes scope=keywords shape=package.json value=topos|capsule|forge|render +bound-lock/1 at=policy:lang by=target form=alphabet measure=id role=writes scope=lang value=en bound-lock/1 at=policy:leaf-role by=target form=alphabet measure=role role=reads scope=leaf-role/.cache value=derived bound-lock/1 at=policy:leaf-role by=target form=alphabet measure=role role=reads scope=leaf-role/.github value=derived bound-lock/1 at=policy:leaf-role by=target form=alphabet measure=role role=reads scope=leaf-role/.gitignore value=derived bound-lock/1 at=policy:leaf-role by=target form=alphabet measure=role role=reads scope=leaf-role/CITATION.cff value=derived bound-lock/1 at=policy:leaf-role by=target form=alphabet measure=role role=reads scope=leaf-role/CONTRIBUTING.md value=derived bound-lock/1 at=policy:leaf-role by=target form=alphabet measure=role role=reads scope=leaf-role/package-lock.json value=derived -bound-lock/1 at=policy:bound/leaf-roles by=target form=alphabet measure=role role=reads scope=leaf-role/receipts.bound value=derived bound-lock/1 at=policy:leaf-role by=target form=alphabet measure=role role=reads scope=leaf-role/reference.md value=derived -bound-lock/1 about="MIT License\n\nCopyright (c) 2026 Lapxo\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE." at=policy:license by=target form=alphabet measure=id role=demands scope=license value=MIT -bound-lock/1 at=policy:capsule/at-most-four-hundred by=target form=interval measure=count role=reads scope=lines/src/**/* value=0..400 -bound-lock/1 at=policy:capsule/one-world by=target form=alphabet measure=id role=reads scope=literal/src/** value=not:readme|markdown|npm|tsconfig|cff|doi|badge -bound-lock/1 at=policy:open by=target form=alphabet measure=id role=writes scope=open/who value="for a ledger=H1-uncertainty|for a ledger=H2-density-attracts|for a mathematician=H4-enriched-semilattice|for a mathematician=H9-the-obligatory-is-maximal|readings=H3-a-distant-signature-moves-a-cell-that-did-not-move|readings=H5-hilbert-is-the-obligatory-without-four-fields|readings=H6-structure-of-measurement|readings=H7-the-medium-of-encounters|readings=H8-refereed-game" -bound-lock/1 about="{count} meet at {lo}..{hi}; {who} is apart: {state}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/cell/outlier value=lock -bound-lock/1 about="{count} meet at {lo}..{hi}: {state}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/cell/together value=lock -bound-lock/1 about="packed as {digest}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/blob value=lock -bound-lock/1 about="declares {domain}, runs on {runtime}, reaches {effects}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/declares value=lock -bound-lock/1 about="run by the {runtime} host" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/host value=lock -bound-lock/1 about="pinned by {place}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/pinned value=lock -bound-lock/1 about="{name} reads {reads}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/region value=lock -bound-lock/1 about="{count} regions, the longest of them {longest} lines" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/regions value=lock -bound-lock/1 about="against topos {digest}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/topos value=lock -bound-lock/1 about="{count} vector files, each held from the blob" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/vectors value=lock -bound-lock/1 about="{version}, as its lock holds it" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/pipeline/notes value=lock -bound-lock/1 about="publish the version once, by the trusted publisher" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/pipeline/publish value=lock -bound-lock/1 about="{name}@{version} is published" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/pipeline/published value=lock -bound-lock/1 about="release the version with its tarball, once" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/pipeline/release value=lock -bound-lock/1 about="{version} is released" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/pipeline/released value=lock -bound-lock/1 about="tag the version the manifest names, once" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/pipeline/tag value=lock -bound-lock/1 about="{version} is tagged" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/pipeline/tagged value=lock -bound-lock/1 about="the forge a place asks for, rendered from its lines: the workflows that test, tag and release it, and what its repository never holds" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/what value=lock -bound-lock/1 about="the regions spoken in more this epoch than last" at=policy:region/approaching by=target form=alphabet measure=text role=writes scope=region/approaching value=lock -bound-lock/1 about="what the package attacks for an engineer, a mathematician and a physicist, in the owner's words" at=policy:region by=target form=alphabet measure=text role=writes scope=region/audiences value=lock -bound-lock/1 about="the axioms of a place, the three most rested on spelled out in their own words" at=policy:region/axioms by=target form=alphabet measure=text role=writes scope=region/axioms value=leaves -bound-lock/1 about="the facts of the lock as badges a reader recognizes: version, licence, engine, dependencies, the cases that hold, what the second head says, grey until the instrument that runs it is published, and the paper's identifier" at=policy:region by=target form=alphabet measure=text role=writes scope=region/badges value=lock -bound-lock/1 about="each signer as a life: what it signed, what it left free and where it forked" at=policy:region/biography by=target form=alphabet measure=text role=writes scope=region/biography value=lock -bound-lock/1 about="the options a place builds with, each from its own line" at=policy:region by=target form=alphabet measure=text role=writes scope=region/build value=lock -bound-lock/1 about="what a tree has not answered, one card per cell: its cone by digest, its ceiling, its origins and each state it could take with what that state would be worth" at=policy:region/cells by=target form=alphabet measure=text role=writes scope=region/cells value=lock -bound-lock/1 about="every conjecture of a place as the thing it is: who met it, with what, how together their claims arrived, and whether anything has closed it" at=policy:region/census by=target form=alphabet measure=text role=writes scope=region/census value=readings -bound-lock/1 about="the citation a forge offers with one click, from the lines that already say it: the software by its name, version, author, repository and licence, and the paper it rests on as the citation the forge prefers" at=policy:region by=target form=alphabet measure=text role=writes scope=region/cff value=lock -bound-lock/1 about="the question that costs least to close next" at=policy:region/cheapest-closer by=target form=alphabet measure=text role=writes scope=region/cheapest-closer value=lock -bound-lock/1 about="how not to believe any of it: the command a clone runs today, and the one that runs the cases with bound once it ships, with how many there are; the repository only once it resolves" at=policy:region by=target form=alphabet measure=text role=writes scope=region/check value=lock -bound-lock/1 about="what this work cites and by what identifier" at=policy:region/cite by=target form=alphabet measure=text role=writes scope=region/cite value=readings -bound-lock/1 about="how together a region arrived, one when every line landed at the same turn of the period" at=policy:region/coherence by=target form=alphabet measure=text role=writes scope=region/coherence value=lock-and-readings -bound-lock/1 about="the commands the owner gives, and a grey mark while the verb they call is not published" at=policy:region by=target form=alphabet measure=text role=writes scope=region/commands value=lock -bound-lock/1 about="every conjecture with the falsifier its own line names" at=policy:region/conjectures by=target form=alphabet measure=text role=writes scope=region/conjectures value=leaves -bound-lock/1 about="what this place takes from another, by name" at=policy:region/consumes by=target form=alphabet measure=text role=writes scope=region/consumes value=readings -bound-lock/1 about="what rests on each line, so what would move if it moved is known before it moves" at=policy:region/dependents by=target form=alphabet measure=text role=writes scope=region/dependents value=lock -bound-lock/1 about="the first screen of the root: its name, the figure one of its places draws, and one sentence of what the places are together" at=policy:region by=target form=alphabet measure=text role=writes scope=region/door value=lock -bound-lock/1 about="what runs here and what is read, said apart" at=policy:region/environments by=target form=alphabet measure=text role=writes scope=region/environments value=prose -bound-lock/1 about="the cell of the shortest example, drawn, with the legend of its marks as its caption" at=policy:region by=target form=alphabet measure=text role=writes scope=region/figure value=lock -bound-lock/1 about="the shortest example this package ships and what it prints, with the digest the lock pins for it" at=policy:region by=target form=alphabet measure=text role=writes scope=region/first-use value=lock -bound-lock/1 about="what lies where in the source, counted from the tree itself" at=policy:region/folders by=target form=alphabet measure=text role=writes scope=region/folders value=leaves -bound-lock/1 about="two readings of one cell that do not meet, with both sides named" at=policy:region/forks by=target form=alphabet measure=text role=writes scope=region/forks value=lock -bound-lock/1 about="what is still undecided, in bits, by region and by the epoch it was born in" at=policy:region/freedom by=target form=alphabet measure=text role=writes scope=region/freedom value=lock -bound-lock/1 about="where looking is worth most, in bits per place" at=policy:region/gaze by=target form=alphabet measure=text role=writes scope=region/gaze value=lock -bound-lock/1 about="lines that stand on one origin and are therefore not yet information" at=policy:region/grey by=target form=alphabet measure=text role=writes scope=region/grey value=lock -bound-lock/1 about="the guide at resolution zero: five lines, the command that checks the place, how many conjectures are open, and that nothing else is asked" at=policy:region by=target form=alphabet measure=text role=writes scope=region/guide-at-zero value=lock -bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=writes scope=region/harness value=harness/** -bound-lock/1 about="the first screen: the mark the place is known by, its name, the badges its lock reads to, and the one line of what it is; what is not signed is not on it" at=policy:region by=target form=alphabet measure=text role=writes scope=region/hero value=lock -bound-lock/1 about="the lines a later line replaced, with when they were replaced" at=policy:region/history by=target form=alphabet measure=text role=writes scope=region/history value=lock -bound-lock/1 about="how the places rest on each other, drawn from the lock's dependency lines and folded until asked for" at=policy:region by=target form=alphabet measure=text role=writes scope=region/how-they-rest value=lock -bound-lock/1 about="the whole idea in one picture, before any name is introduced" at=policy:region/idea by=target form=alphabet measure=text role=writes scope=region/idea value=prose -bound-lock/1 about="what a repository of the place never holds, one line each" at=policy:region by=target form=alphabet measure=text role=writes scope=region/ignore value=lock -bound-lock/1 about="the one line that installs it: the verb the lock names, then the name its manifest carries" at=policy:region by=target form=alphabet measure=text role=writes scope=region/install value=lock -bound-lock/1 about="the theory of a place as its lists, each law with what met it and what would break it" at=policy:region/laws by=target form=alphabet measure=text role=writes scope=region/laws value=readings -bound-lock/1 about="a page to learn from one example: the cell it draws, what it calls and prints, the law it shows, its form, and where it lives; the example is the one the page is named after" at=policy:region by=target form=alphabet measure=text role=writes scope=region/learn value=lock -bound-lock/1 about="a page to learn from the in-phase example: the cell it draws, what it calls and prints, the law it shows, its form, and where it lives" at=policy:region by=target form=alphabet measure=text role=writes scope=region/learn-in-phase value=lock -bound-lock/1 about="a page to learn from the price example: the cell it draws, what it calls and prints, the law it shows, its form, and where it lives" at=policy:region by=target form=alphabet measure=text role=writes scope=region/learn-price value=lock -bound-lock/1 about="a page to learn from the signature example: the cell it draws, what it calls and prints, the law it shows, its form, and where it lives" at=policy:region by=target form=alphabet measure=text role=writes scope=region/learn-signature value=lock -bound-lock/1 about="a page to learn from the thermometer example: the cell it draws, what it calls and prints, the law it shows, its form, and where it lives" at=policy:region by=target form=alphabet measure=text role=writes scope=region/learn-thermometer value=lock -bound-lock/1 about="a page to learn from the withdrawal example: the cell it draws, what it calls and prints, the law it shows, its form, and where it lives" at=policy:region by=target form=alphabet measure=text role=writes scope=region/learn-withdrawal value=lock -bound-lock/1 about="the licence, carried on a line of the lock and rendered into its own leaf" at=policy:region/license by=target form=alphabet measure=text role=writes scope=region/license value=lock -bound-lock/1 about="the lock lines a place holds in its own files, unsigned, as they are written there" at=policy:region/lock-line by=target form=alphabet measure=text role=writes scope=region/lock-line value=leaves -bound-lock/1 about="the manifest the place holds, rendered from the lines it signs about itself: the fields a consumer reads and the three a resolver older than exports still needs in this tree" at=policy:region/manifest by=target form=alphabet measure=text role=writes scope=region/manifest value=lock -bound-lock/1 about="the legend of the marks a page is drawn in, in the owner's words" at=policy:region by=target form=alphabet measure=text role=writes scope=region/marks value=lock -bound-lock/1 about="the notation of the object at a resolution: at zero the tuple a cell is; at one the tuple and the formulas of what it rests on, in the order they rest; at three each formula beside its law's sentence; at eight all of it with the signature of every arrow and the states" at=policy:region by=target form=alphabet measure=text role=writes scope=region/notation value=lock -bound-lock/1 about="every operation offered, with how many vectors reached it" at=policy:region/offers by=target form=alphabet measure=text role=writes scope=region/offers value=readings -bound-lock/1 about="every conjecture of the place, marked as such, with what would falsify it" at=policy:region by=target form=alphabet measure=text role=writes scope=region/open-conjectures value=lock -bound-lock/1 about="the questions with no answer yet, widest first" at=policy:region/open-questions by=target form=alphabet measure=text role=writes scope=region/open-questions value=lock -bound-lock/1 about="who spoke in each region of the tree, head and reader alike" at=policy:region/origins by=target form=alphabet measure=text role=writes scope=region/origins value=lock-and-readings -bound-lock/1 about="what a place holds that nothing reaches: a test or a sample no demand names and no run reads, and a page no view writes and no demand needs" at=policy:region by=target form=alphabet measure=text role=writes scope=region/orphans value=lock -bound-lock/1 about="what the theory proves and which views implement it" at=policy:region/paper by=target form=alphabet measure=text role=writes scope=region/paper value=prose -bound-lock/1 about="the scale the shortest example draws: each claim as a bar and what they hold together beneath them" at=policy:region by=target form=alphabet measure=text role=writes scope=region/picture value=lock -bound-lock/1 about="the release the forge makes after the tag: the version published once by the trusted publisher, and its tarball attached" at=policy:region by=target form=alphabet measure=text role=writes scope=region/pipeline-release value=lock -bound-lock/1 about="the tag the forge makes for the version the manifest names, once" at=policy:region by=target form=alphabet measure=text role=writes scope=region/pipeline-tag value=lock -bound-lock/1 about="the check the forge runs on every push and every proposal" at=policy:region by=target form=alphabet measure=text role=writes scope=region/pipeline-test value=lock -bound-lock/1 about="each place the owner has said what it is, in the order they rest on each other, with its state as a colour and what the fold counts of it: paid, hazards open, and what the second head says" at=policy:region by=target form=alphabet measure=text role=writes scope=region/places value=lock -bound-lock/1 about="the pages below the door, as links from the views that write them: the reference and the pages to learn from; the forge shows the guide and the licence itself" at=policy:region by=target form=alphabet measure=text role=writes scope=region/pointers value=lock -bound-lock/1 about="what a line is worth beyond what it says, in bits still free" at=policy:region/premium by=target form=alphabet measure=text role=writes scope=region/premium value=lock -bound-lock/1 about="the one line that says what this place is: claims, demands paid, ceilings met, what the second head said, and what a fold of it costs" at=policy:region/programs by=target form=alphabet measure=text role=writes scope=region/programs value=lock -bound-lock/1 about="the lock a place is published with, seen from inside it: the bootstrap first, the wire and the keys it is read with, the regions it is written in, its own lines and every line a view of it reads, with the place's name gone from every scope, need, policy and cone; nothing of the tree's history and nothing that needs outside the place" at=policy:region by=target form=alphabet measure=text role=writes scope=region/published-lock value=lock -bound-lock/1 about="the manifest the package carries, rendered from the same lines without the three fields only this tree's resolver reads: what npm packs and a consumer installs" at=policy:region/published-manifest by=target form=alphabet measure=text role=writes scope=region/published-manifest value=lock -bound-lock/1 about="the receipts a place is published with: what it observed, seen from inside it, without the word the tree's second head gave, since the published place asks its own" at=policy:region by=target form=alphabet measure=text role=writes scope=region/published-receipts value=lock -bound-lock/1 about="the open questions of a place, as the lock asks them" at=policy:region/question by=target form=alphabet measure=text role=writes scope=region/question value=lock -bound-lock/1 about="the cell of an example drawn at a resolution: at zero three bars, above it each claim a bar, what they hold together a bar in the colour of a meeting, and its floor and its ceiling named" at=policy:region by=target form=alphabet measure=text role=writes scope=region/ranges value=lock -bound-lock/1 about="which view answers which question, in the words each view says of itself" at=policy:region by=target form=alphabet measure=text role=writes scope=region/reading value=lock -bound-lock/1 about="the regions spoken in less this epoch than last" at=policy:region/receding by=target form=alphabet measure=text role=writes scope=region/receding value=lock -bound-lock/1 about="what a package carries of its own reading, so a clone folds without running anything" at=policy:region/receipts by=target form=alphabet measure=text role=writes scope=region/receipts value=readings -bound-lock/1 about="every ceiling a reading is over, and every demand nothing paid" at=policy:region/red by=target form=alphabet measure=text role=writes scope=region/red value=lock -bound-lock/1 about="every operation with its signature, its derived refusals, what it reaches and the laws it rests on; every law with its kind, view, premises, sentence and whether it reproduces; every form" at=policy:region by=target form=alphabet measure=text role=writes scope=region/reference value=lock -bound-lock/1 about="how often each region of the tree was read" at=policy:region/region-frequency by=target form=alphabet measure=text role=writes scope=region/region-frequency value=readings -bound-lock/1 about="the regions spoken in at more than two epochs" at=policy:region/resonance by=target form=alphabet measure=text role=writes scope=region/resonance value=lock -bound-lock/1 about="what the object rests on, drawn: the definition most offers rest on and the lines it rests on, each by its name" at=policy:region by=target form=alphabet measure=text role=writes scope=region/rests value=lock -bound-lock/1 about="how many of those epochs it was actually spoken in" at=policy:region/rhythm by=target form=alphabet measure=text role=writes scope=region/rhythm value=lock-and-readings -bound-lock/1 about="whether a region holds without any one of its origins" at=policy:region/robustness by=target form=alphabet measure=text role=writes scope=region/robustness value=lock-and-readings -bound-lock/1 about="what each leaf of the place is, written or rendered, so a page says which of its own files were never typed" at=policy:region/role by=target form=alphabet measure=text role=writes scope=region/role value=leaves -bound-lock/1 about="where this place stands in the tree it belongs to" at=policy:region/scene by=target form=alphabet measure=text role=writes scope=region/scene value=lock -bound-lock/1 about="the check a clone runs alone: the subpaths the manifest offers, imported, and the second head's signed word, verified against the key the lock admits and the digest of the lock itself" at=policy:region by=target form=alphabet measure=text role=writes scope=region/selfcheck value=lock -bound-lock/1 about="the figure a region makes: a point, an edge, or a polygon" at=policy:region/shape by=target form=alphabet measure=text role=writes scope=region/shape value=lock-and-readings -bound-lock/1 about="what it takes to sign here, and who may" at=policy:region/sign by=target form=alphabet measure=text role=writes scope=region/sign value=lock -bound-lock/1 about="each key, what it has signed and what it may sign" at=policy:region/signers by=target form=alphabet measure=text role=writes scope=region/signers value=lock -bound-lock/1 about="what a demand costs to pay and what paying it lands" at=policy:region/take by=target form=alphabet measure=text role=writes scope=region/take value=lock -bound-lock/1 about="the obligatory as its definition says it, with the four states and the parts it is made of" at=policy:region by=target form=alphabet measure=text role=writes scope=region/the-object value=lock -bound-lock/1 about="the paper: the owner's words on what it proves, then the reference a reader copies, its authors, year, title, version, publisher and address" at=policy:region by=target form=alphabet measure=text role=writes scope=region/the-paper value=lock -bound-lock/1 about="four real calls and what each of them answers" at=policy:region/thirty-seconds by=target form=alphabet measure=text role=writes scope=region/thirty-seconds value=prose -bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=writes scope=region/topos-measure value=topos-measure/** -bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=writes scope=region/topos-typescript-artifacts value=topos-typescript-artifacts/** -bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=writes scope=region/topos-typescript-concepts value=topos-typescript-concepts/** -bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=writes scope=region/topos-typescript-packages value=topos-typescript-packages/** -bound-lock/1 about="the cases a place holds and which of them did not hold, read from what the runner already answered rather than run again" at=policy:region/vectors by=target form=alphabet measure=text role=writes scope=region/vectors value=readings -bound-lock/1 about="the three axioms the rest leans on hardest by their sentence, the others by name, and one theorem meeting its measurement" at=policy:region by=target form=alphabet measure=text role=writes scope=region/what-holds value=lock -bound-lock/1 about="what is open in each place, folded until asked for: conjectures, hazards by kind, and demands not yet paid" at=policy:region by=target form=alphabet measure=text role=writes scope=region/what-is-open value=lock -bound-lock/1 about="where the package goes next, in the owner's words, in four lines at most" at=policy:region by=target form=alphabet measure=text role=writes scope=region/where-next value=lock -bound-lock/1 about="the prose a place keeps beside its source, read as paragraphs and never as headings" at=policy:region/why by=target form=alphabet measure=text role=writes scope=region/why value=leaves -bound-lock/1 about="how many epochs a region spans, from its first line to its last" at=policy:region/width by=target form=alphabet measure=text role=writes scope=region/width value=lock-and-readings -bound-lock/1 at=policy:capsule/customisation-is-the-places-lines by=target form=interval measure=count role=reads scope=source/customised/src/** value=0..0 -bound-lock/1 at=policy:capsule/language-facts-come-from-the-language-capsule by=target form=interval measure=count role=reads scope=source/lexed/src/** value=0..0 -bound-lock/1 at=policy:source by=target form=interval measure=longest role=reads scope=source/longest/src/** value=0..40 -bound-lock/1 at=policy:capsule/reads-lines-and-receipts-only by=target form=interval measure=count role=reads scope=source/unread/src/** value=0..0 -bound-lock/1 at=policy:theme by=target form=alphabet measure=id role=writes scope=theme value=green:2da44e:●|grey:8c959f:○|red:cf222e:✕|fork:8250df:⋔|text:59636e|text-dark:9198a1|text-on:ffffff -bound-lock/1 at=policy:author by=target form=alphabet measure=id needs=package.json role=writes scope=author shape=package.json value=Lapxo -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/allowImportingTsExtensions shape=tsconfig.json value=true -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/declaration shape=tsconfig.json value=true -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/esModuleInterop shape=tsconfig.json value=true -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/forceConsistentCasingInFileNames shape=tsconfig.json value=true -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/include shape=tsconfig.json value=src -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/incremental shape=tsconfig.json value=true -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/module shape=tsconfig.json value=NodeNext -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/moduleResolution shape=tsconfig.json value=NodeNext -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/noFallthroughCasesInSwitch shape=tsconfig.json value=true -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/noImplicitOverride shape=tsconfig.json value=true -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/noImplicitReturns shape=tsconfig.json value=true -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/outDir shape=tsconfig.json value=dist -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/rewriteRelativeImportExtensions shape=tsconfig.json value=true -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/rootDir shape=tsconfig.json value=src -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/skipLibCheck shape=tsconfig.json value=true -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/strict shape=tsconfig.json value=true -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/target shape=tsconfig.json value=ES2020 -bound-lock/1 at=policy:build by=target form=alphabet measure=id needs=tsconfig.json role=writes scope=build/tsBuildInfoFile shape=tsconfig.json value=.cache/tsbuildinfo -bound-lock/1 at=policy:check by=target form=alphabet measure=id needs=package.json role=writes scope=check value="npm ci && npm run build" -bound-lock/1 at=policy:dependencies by=target form=alphabet measure=id needs=package.json role=writes scope=dependencies shape=package.json value=@lapxo/topos@^0.1.0 -bound-lock/1 at=policy:engines by=target form=alphabet measure=id needs=package.json role=writes scope=engines shape=package.json value=">=22.12" -bound-lock/1 at=policy:exports by=target form=alphabet measure=id needs=package.json role=writes scope=exports shape=package.json value=dist/index -bound-lock/1 at=policy:ignore by=target form=alphabet measure=id role=writes scope=ignore value=.bound/|dist/|node_modules/|.cache/ -bound-lock/1 at=policy:install by=target form=alphabet measure=id needs=package.json role=writes scope=install value="npm install" -bound-lock/1 at=policy:keywords by=target form=alphabet measure=id needs=package.json role=writes scope=keywords shape=package.json value=topos|capsule|forge|render -bound-lock/1 at=policy:lang by=target form=alphabet measure=id role=writes scope=lang value=en bound-lock/1 at=policy:license by=target form=alphabet measure=id needs=package.json role=writes scope=license shape=package.json value=MIT +bound-lock/1 at=policy:local-fold-journal by=target form=alphabet measure=class role=reads scope=keys/fold value=fold bound-lock/1 at=policy:name by=target form=alphabet measure=id needs=package.json role=writes scope=name shape=package.json value=@lapxo/topos-github +bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/cell value="floor=⊥|ceiling=⊤|origins=O|rest=⊑" +bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/claim value="who=origin|lo=span.lo|hi=span.hi|without=takes" +bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/formulas value=law/D11-the-obligatory|law/A1-encounter|law/A7-freedom-conserved|law/T49-amplitude-has-sign-and-phase|law/T95-signatures-live-where-they-are-signed|law/T87-the-quarter-turn|law/D3-state +bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/gloss value="over L at r" +bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/glue value="open=⟨|close=⟩|member=∈|product=×|maps=→|iff=⟺" +bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/moves value=vectors/moves.json +bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/named value=string|number|boolean +bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/object value=law/D11-the-obligatory +bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/renders value="FREE=green|REQUIRED=grey|FORBIDDEN=red|CONFLICT=fork" +bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/states value="bounds that cross=CONFLICT|one origin=REQUIRED|claims that do not meet=CONFLICT|claims that meet and fit the bounds=FREE|claims that meet outside the bounds=FORBIDDEN" +bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/symbols value="object=c|state=state" +bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/types value="Origin=(o, φ)|Act=s|State=state" +bound-lock/1 at=policy:open by=target form=alphabet measure=id role=writes scope=open/who value="for a ledger=H1-uncertainty|for a ledger=H2-density-attracts|for a mathematician=H4-enriched-semilattice|for a mathematician=H9-the-obligatory-is-maximal|readings=H3-a-distant-signature-moves-a-cell-that-did-not-move|readings=H5-hilbert-is-the-obligatory-without-four-fields|readings=H6-structure-of-measurement|readings=H7-the-medium-of-encounters|readings=H8-refereed-game" +bound-lock/1 at=policy:pages/mode by=target form=interval measure=prose-marks role=reads scope=audit/docs-have-a-mode value=0..0 +bound-lock/1 at=policy:pages/same by=target form=interval measure=rendered-leaves-differ role=reads scope=audit/rendered-docs-match value=0..0 bound-lock/1 at=policy:pipeline by=target form=alphabet measure=id role=writes scope=pipeline/branch value=main bound-lock/1 at=policy:pipeline by=target form=alphabet measure=id role=writes scope=pipeline/environment value=release bound-lock/1 at=policy:pipeline by=target form=alphabet measure=id role=writes scope=pipeline/node value=22|24 @@ -436,31 +434,70 @@ bound-lock/1 at=policy:pipeline by=target form=alphabet measure=id role=writes s bound-lock/1 at=policy:pipeline by=target form=alphabet measure=id role=writes scope=pipeline/published value="npm view" bound-lock/1 at=policy:pipeline by=target form=alphabet measure=id role=writes scope=pipeline/registry value=https://registry.npmjs.org bound-lock/1 at=policy:pipeline by=target form=alphabet measure=id role=writes scope=pipeline/trusted-publisher value=pending +bound-lock/1 at=policy:place/dist by=target form=interval measure=shipped-beside-code role=reads scope=audit/dist-holds-js-and-dts value=0..0 +bound-lock/1 at=policy:place/orphans by=target form=interval measure=orphan-samples role=reads scope=audit/orphans value=0..0 +bound-lock/1 at=policy:place/removal by=target form=interval measure=removed-by-hand role=reads scope=audit/nothing-is-removed-by-hand value=0..0 +bound-lock/1 at=policy:reader by=target form=alphabet kind=js measure=reader needs=src/ role=reads scope=reader/said/source shape=*.ts value=topos-typescript-tree/src/regions/said.ts +bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=reads scope=region/said value=src/**/*.ts +bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=reads scope=region/source value=src/**/*.ts +bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=reads scope=region/vocabulary value=src/**/*.ts +bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=writes scope=region/harness value=harness/** +bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=writes scope=region/topos-measure value=topos-measure/** +bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=writes scope=region/topos-typescript-artifacts value=topos-typescript-artifacts/** +bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=writes scope=region/topos-typescript-concepts value=topos-typescript-concepts/** +bound-lock/1 at=policy:region by=target form=alphabet measure=coordinates role=writes scope=region/topos-typescript-packages value=topos-typescript-packages/** +bound-lock/1 at=policy:release by=target form=alphabet measure=id role=demands scope=release/rebirth value=rebirth bound-lock/1 at=policy:repository by=target form=alphabet measure=id needs=package.json role=writes scope=repository shape=package.json value=https://github.com/lapxo/topos-github bound-lock/1 at=policy:scripts by=target form=alphabet measure=id needs=package.json role=writes scope=scripts/build shape=package.json value="tsc --build" +bound-lock/1 at=policy:security/acts by=target form=interval measure=acts-on-unnamed-hosts role=reads scope=audit/agent-acts-are-effects value=0..0 bound-lock/1 at=policy:sideEffects by=target form=alphabet measure=id needs=package.json role=writes scope=sideEffects shape=package.json value=false +bound-lock/1 at=policy:source by=target form=interval measure=longest role=reads scope=source/longest/src/** value=0..40 bound-lock/1 at=policy:sources by=target form=alphabet measure=id role=writes scope=sources/badges value=https://img.shields.io/badge +bound-lock/1 at=policy:theme by=target form=alphabet measure=id role=writes scope=theme value=green:2da44e:●|grey:8c959f:○|red:cf222e:✕|fork:8250df:⋔|text:59636e|text-dark:9198a1|text-on:ffffff +bound-lock/1 at=policy:topos/bounded-readers by=target form=alphabet measure=id role=writes scope=reader/empty value=required +bound-lock/1 at=policy:topos/bounded-readers by=target form=alphabet measure=id role=writes scope=reader/inputs value=required +bound-lock/1 at=policy:topos/bounded-readers by=target form=interval measure=bytes role=writes scope=reader/response-bytes value=0..67108864 +bound-lock/1 at=policy:topos/bounded-readers by=target form=interval measure=milliseconds role=writes scope=reader/timeout value=0..30000 bound-lock/1 at=policy:topos/capsule-length by=target form=interval measure=count role=reads scope=src/lines value=0..400 bound-lock/1 at=policy:topos/region-length by=target form=interval measure=per-file role=reads scope=src/regions/**/lines value=0..40 +bound-lock/1 at=policy:topos/wire-page by=target form=alphabet measure=id role=writes scope=form/template/wire/canonical value=hash +bound-lock/1 at=policy:topos/wire-page by=target form=alphabet measure=id role=writes scope=form/template/wire/encoding value=encoding +bound-lock/1 at=policy:topos/wire-page by=target form=alphabet measure=id role=writes scope=form/template/wire/header value=header +bound-lock/1 at=policy:topos/wire-page by=target form=alphabet measure=id role=writes scope=form/template/wire/lead value=header|encoding +bound-lock/1 at=policy:topos/wire-page by=target form=alphabet measure=id role=writes scope=form/template/wire/order value=encoding +bound-lock/1 at=policy:tree/comments-few by=target form=interval measure=per-file role=reads scope=comments/*/src/** value=0..3 bound-lock/1 at=policy:type by=target form=alphabet measure=id needs=package.json role=writes scope=type shape=package.json value=module -bound-lock/1 at=policy:uses by=target form=alphabet measure=id role=writes scope=uses/topos value=sha256:9bd23c16b52258e2a2f56f516887aef384b799bd8b54d133e9f82c4aa99c9e2f -bound-lock/1 at=policy:uses by=target form=alphabet measure=id role=writes scope=uses/topos-bound value=sha256:8742250a27d7848a731c72f2f6296a3527ff68e0b5232c6afd44e0d2b666ee92 -bound-lock/1 at=policy:uses by=target form=alphabet measure=id role=writes scope=uses/topos-doc value=sha256:713f7604d1feef271d0f4f81495422b35c81f0d757e06866d088728715d60112 -bound-lock/1 at=policy:uses by=target form=alphabet measure=id role=writes scope=uses/topos-frame value=sha256:51af4be51da524873b2d4debdf5c0026182e005076a39965f2b42223bb5a818e -bound-lock/1 at=policy:uses by=target form=alphabet measure=id role=writes scope=uses/topos-github value=sha256:f58cd403038adc9e552fe8452ffeba8e182ebc5b46a9fb2af66e1391363566a3 -bound-lock/1 at=policy:view/license by=target form=alphabet measure=id role=demands scope=view/license shape=LICENSE value=license -bound-lock/1 at=place:topos-measure/release by=target form=alphabet measure=id role=demands scope=view/pipeline-release shape=.github/workflows/release.yml value=github-actions -bound-lock/1 at=policy:view by=target form=alphabet measure=id needs=docs/reference.md role=demands scope=view/reference-capsule shape=docs/reference.md value=regions bound-lock/1 at=policy:view by=target form=alphabet measure=id role=demands scope=view/reference-capsule shape=docs/reference.md value=regions -bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/formulas value=law/D11-the-obligatory|law/A1-encounter|law/A7-freedom-conserved|law/T49-amplitude-has-sign-and-phase|law/T95-signatures-live-where-they-are-signed|law/T87-the-quarter-turn|law/D3-state -bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/states value="bounds that cross=CONFLICT|one origin=REQUIRED|claims that do not meet=CONFLICT|claims that meet and fit the bounds=FREE|claims that meet outside the bounds=FORBIDDEN" -bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/glue value="open=⟨|close=⟩|member=∈|product=×|maps=→|iff=⟺" -bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/cell value="floor=⊥|ceiling=⊤|origins=O|rest=⊑" -bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/types value="Origin=(o, φ)|Act=s|State=state" -bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/gloss value="over L at r" -bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/claim value="who=origin|lo=span.lo|hi=span.hi|without=takes" -bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/moves value=vectors/moves.json -bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/named value=string|number|boolean -bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/object value=law/D11-the-obligatory -bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/renders value="FREE=green|REQUIRED=grey|FORBIDDEN=red|CONFLICT=fork" -bound-lock/1 at=policy:notation by=target form=alphabet measure=id role=writes scope=notation/symbols value="object=c|state=state" +bound-lock/1 at=policy:view/license by=target form=alphabet measure=id role=demands scope=view/license shape=LICENSE value=license +bound-lock/1 at=policy:wire/region-measures by=target form=alphabet measure=id role=reads scope=audit/wire/region-measures value=coordinates|leaves +bound-lock/1 at=policy:wire/shapes by=target form=alphabet measure=id role=reads scope=audit/wire/shapes value=decision|lock|package|reader|render|run|vector|view +bound-lock/1 at=policy:wire/states by=target form=alphabet measure=id role=reads scope=audit/wire/states value=absent|present|unread|withdraw +bound-lock/1 at=policy:wire/templates by=target form=alphabet measure=id role=reads scope=audit/wire/templates value={cone}|{roots} +bound-lock/1 at=witness:native-receipts-ship-with-the-place by=target form=alphabet measure=id role=reads scope=audit/wire/ships value=dist|README.md|LICENSE|TARGET.bound|receipts.bound +bound-lock/1 at=witness:native-render-release by=target form=alphabet measure=id needs=package.json role=writes scope=version shape=package.json value=0.1.3 +bound-lock/1 at=witness:own-page-from-own-prose by=target form=alphabet measure=id needs=README.md role=demands scope=view/readme-capsule shape=README.md value=hero|idea +bound-lock/1 at=witness:own-store-never-ships by=target form=alphabet measure=id role=demands scope=view/gitignore shape=.gitignore value=ignore +bound-lock/1 at=witness:portable-native-receipts by=target form=alphabet measure=id role=demands scope=view/receipts shape=receipts.bound value=receipts@8|receipts@0|receipts@1 +bound-lock/1 at=witness:published-render-contract by=target form=alphabet measure=id needs=package.json role=writes scope=dependencies shape=package.json value=@lapxo/topos@0.1.12 +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest needs=topos-typescript-tree role=reads scope=dep/typescript-reader value=sha256:ecf86c50adacb3e199e7363fb355ad66d7c76a76ab1e007836d9e9fbc74ad434 +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest needs=topos-typescript-tree/node_modules/@lapxo/obligations role=reads scope=dep/typescript-reader-algebra shape=package value=sha256:e4b48f480e86c2e1b9518b7a5dbe18e4b4dfa449961c781a291295fa85a3ec72 +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest needs=topos-typescript-tree/node_modules/@lapxo/topos role=reads scope=dep/typescript-reader-sdk shape=package value=sha256:21e030acdc0d825e183b30f94d400daf351b02f782d474635f246de9e6e12b83 +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest needs=topos-typescript-tree/node_modules/typescript role=reads scope=dep/typescript-reader-compiler value=sha256:9dc6ee1f8dec9598cbecff5e2fcf2b916d04294c0615588dd424448a5a3afce5 +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest role=writes scope=dep/topos-doc shape=dist/index.js value=sha256:1b9fa141c118669a69ffee76d049b23c6bf68eb07f524aa7b89dd873bcde68eb +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest role=writes scope=dep/topos-github shape=dist/index.js value=sha256:0a0ce9bac2dd52a5620691a26960f69ac013642bfd9a51a374ab998f7d780a7a +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest role=writes scope=dep/topos-node shape=dist/index.js value=sha256:859ee30f9eaed96edfdfd8d72834a18ebb82022d9c7ceea52e66409241f2cfb6 +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest role=writes scope=uses/topos-doc value=sha256:65bfa43e2d5122db2d516afe516921d52fc22647fb092d55e313c25c5a2d9b52 +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest role=writes scope=uses/topos-github value=sha256:af59e6e41b8da160bf746ba4319a6bf138491c7f409c7f187f747ae7c247b7f1 +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest role=writes scope=uses/topos-node value=sha256:c7cfad66c15e3fb1d2cd71de9eabf70898723ea45f402987c7b8136729bfabd4 +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=id needs=.github/workflows/tag.yml role=demands scope=view/pipeline-tag shape=.github/workflows/tag.yml value=github-actions@1 +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=id needs=.github/workflows/test.yml role=demands scope=view/pipeline-test shape=.github/workflows/test.yml value=github-actions@1 +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=id needs=package.json role=demands scope=view/manifest shape=package.json value=manifest +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=id needs=package.json role=writes scope=devDependencies shape=package.json value=@types/node@^22|typescript@5.9.3 +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=id needs=package.json role=writes scope=scripts/test shape=package.json value="node --test test/*.test.ts" +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=id needs=tsconfig.json role=demands scope=view/tsconfig shape=tsconfig.json value=build +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=id role=demands scope=view/closure value=red|programs +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=id role=writes scope=docs/badges value=license +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=id role=writes scope=pipeline/check value="npm run build && npm test" +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=id role=writes scope=pipeline/install value="npm ci" +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=id role=writes scope=pipeline/release/digest-command value=sha256sum +bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=id role=writes scope=wire/receipt-fields value=scope|role|measure|form|value|at diff --git a/capsule.bound b/capsule.bound deleted file mode 100644 index ce47614..0000000 --- a/capsule.bound +++ /dev/null @@ -1,27 +0,0 @@ -bound-lock/1 about="the domain this capsule serves: the workflows, releases and repositories a place asks for" at=policy:topos/capsule by=target form=alphabet measure=id role=writes scope=capsule/domain value=github -bound-lock/1 about="the runtime a host starts this capsule with, whose entry, regions and effects are the runtime's own lines" at=policy:topos/capsule by=target form=alphabet measure=id role=writes scope=capsule/runtime value=node -bound-lock/1 about="where this capsule's world keeps its values: the place's own files" at=policy:topos/capsule by=target form=alphabet measure=id role=writes scope=capsule/holds value=./ -bound-lock/1 about="the workflows of a place as github-actions runs them, read only from its pipeline lines" at=policy:topos/capsule by=target form=alphabet measure=reads role=render shape=.github/workflows/*.yml scope=region/github-actions value=pipeline/**|audit/wire/pipeline/world -bound-lock/1 about="what a repository of the place never holds" at=policy:topos/capsule by=target form=alphabet measure=reads role=render shape=.gitignore scope=region/ignore value=ignore -bound-lock/1 about="a published place publishes by its trusted publisher: a place whose auth still names a secret, a token handed to its publish, reads 1" at=policy:topos/capsule by=target form=alphabet measure=reads role=receipt shape=pipeline/publish/auth scope=region/publish-auth-is-trusted value=pipeline/publish/auth -bound-lock/1 about="the key this world's own prose is written under, which its host drops as it hands the prose to the place's pages and to its own regions" at=policy:topos/capsule by=target form=alphabet measure=id role=writes scope=capsule/key value=github -bound-lock/1 about="what this capsule reaches beyond the lines it is handed" at=policy:topos/capsule by=target form=alphabet measure=effects role=writes scope=capsule/effects value=none -bound-lock/1 about="the topos release this capsule is packed against, named by its digest" at=policy:topos/capsule by=target form=alphabet measure=digest role=writes scope=capsule/topos value=sha256:680af2143a339689f58b8f672da4c637b76e22f3b3812d2dfb95b2f0723d5541 -bound-lock/1 about="Workflows, releases, and what a repository never holds." at=witness:a-repository-with-no-page by=target form=alphabet measure=text role=writes scope=prose/en/github/what value=lock -bound-lock/1 about="A world for a repository's workflows and its releases." at=witness:a-repository-with-no-page by=target form=alphabet measure=text role=writes scope=prose/en/github/door/what value=lock -bound-lock/1 about="its regions, read off its own descriptor" at=witness:a-repository-with-no-page by=target form=alphabet measure=text role=writes scope=prose/en/github/door/words value=lock -bound-lock/1 about="Why a line" at=witness:a-repository-with-no-page by=target form=alphabet measure=text role=writes scope=prose/en/github/idea/heading value=lock -bound-lock/1 about="A workflow is a line of the place. A release is the tag that workflow cuts. A repository holds only what its ignore line allows." at=witness:a-repository-with-no-page by=target form=alphabet measure=text role=writes scope=prose/en/github/idea value=lock -bound-lock/1 about="One repository" at=witness:a-repository-with-no-page by=target form=alphabet measure=text role=writes scope=prose/en/github/figure/world/heading value=lock -bound-lock/1 about="a place adopts it with {scope}" at=witness:a-repository-with-no-page by=target form=alphabet measure=text role=writes scope=prose/en/github/figure/world/adopted value=lock -bound-lock/1 about="[The whole example]({at})" at=witness:a-repository-with-no-page by=target form=alphabet measure=text role=writes scope=prose/en/github/figure/learn/source value=lock -bound-lock/1 about="What it claims" at=witness:a-repository-with-no-page by=target form=alphabet measure=text role=writes scope=prose/en/github/claims/heading value=lock -bound-lock/1 about="It costs {dependencies} dependencies." at=witness:a-repository-with-no-page by=target form=alphabet measure=text role=writes scope=prose/en/github/claims/1-costs value=lock -bound-lock/1 about=receipt at=witness:a-repository-with-no-page by=target form=alphabet measure=text role=writes scope=prose/en/github/claims/receipt value=lock -bound-lock/1 about="How to read it" at=witness:a-repository-with-no-page by=target form=alphabet measure=text role=writes scope=prose/en/github/reading/heading value=lock -bound-lock/1 about="Each region answers one question." at=witness:a-repository-with-no-page by=target form=alphabet measure=text role=writes scope=prose/en/github/reading/lead value=lock -bound-lock/1 about="**{name}** · {answer}" at=witness:a-repository-with-no-page by=target form=alphabet measure=text role=writes scope=prose/en/github/reading/view value=lock -bound-lock/1 about="It rests on {names}." at=witness:a-repository-with-no-page by=target form=alphabet measure=text role=writes scope=prose/en/github/rests/on value=lock -bound-lock/1 about="the vector this region holds its cases in, named by the digest of its bytes" at=policy:topos/capsule by=target form=alphabet measure=digest role=writes scope=vector/github-actions value=sha256:63f7c9bc71e14693d438c543b1c65759927c3c2a69362dcde40f136a06670680 -bound-lock/1 about="the vector this region holds its cases in, named by the digest of its bytes" at=policy:topos/capsule by=target form=alphabet measure=digest role=writes scope=vector/ignore value=sha256:bc37ac05fd8f7876dcbb3a49f43de2de7809453864821590aecc27f9da3494b5 -bound-lock/1 about="the vector this region holds its cases in, named by the digest of its bytes" at=policy:topos/capsule by=target form=alphabet measure=digest role=writes scope=vector/publish-auth-is-trusted value=sha256:59a18f7dca3099e8d9ef85c59c36d9d0e93ff942594a791bb37aa6c069bd75b2 diff --git a/package-lock.json b/package-lock.json index d2bc744..80b3319 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,15 +1,19 @@ { "name": "@lapxo/topos-github", - "version": "0.1.2", + "version": "0.1.3", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@lapxo/topos-github", - "version": "0.1.2", + "version": "0.1.3", "license": "MIT", "dependencies": { - "@lapxo/topos": "^0.1.0" + "@lapxo/topos": "0.1.12" + }, + "devDependencies": { + "@types/node": "^22", + "typescript": "5.9.3" }, "engines": { "node": ">=22.12" @@ -25,9 +29,9 @@ } }, "node_modules/@lapxo/topos": { - "version": "0.1.3", - "resolved": "https://registry.npmjs.org/@lapxo/topos/-/topos-0.1.3.tgz", - "integrity": "sha512-OlN2FQ7W+w5WjDPNFqG+iZ9ThQ180gr2D42PfIvX3sFxOGEIdwmKA0K73WIrq6j0NiCTRYYnHf4xZeEO0ug3IQ==", + "version": "0.1.12", + "resolved": "https://registry.npmjs.org/@lapxo/topos/-/topos-0.1.12.tgz", + "integrity": "sha512-bD4mZrzGP/D6YOOKm3rxNL79jfXa/4kT/9dAUHo458c3O8NufY85bZ5FE3bzwYWIvd5BX42sJg18/jc6/HzKvQ==", "license": "MIT", "dependencies": { "@lapxo/obligations": "^0.3.5" @@ -35,6 +39,37 @@ "engines": { "node": ">=22.12" } + }, + "node_modules/@types/node": { + "version": "22.20.5", + "resolved": "https://registry.npmjs.org/@types/node/-/node-22.20.5.tgz", + "integrity": "sha512-U2+DNr+wSjpsTS/wZGYHq7GcwfuSmKiKvoPvK22zwTlRhU91yOniN4qRR5KhIjvif7ysw/dz/hKmfDH0Ris4aA==", + "dev": true, + "license": "MIT", + "dependencies": { + "undici-types": "~6.21.0" + } + }, + "node_modules/typescript": { + "version": "5.9.3", + "resolved": "https://registry.npmjs.org/typescript/-/typescript-5.9.3.tgz", + "integrity": "sha512-jl1vZzPDinLr9eUt3J/t7V6FgNEw9QjvBPdysz9KfQDD41fQrC2Y4vKQdiaUpFT4bXlb1RHhLpp8wtm6M5TgSw==", + "dev": true, + "license": "Apache-2.0", + "bin": { + "tsc": "bin/tsc", + "tsserver": "bin/tsserver" + }, + "engines": { + "node": ">=14.17" + } + }, + "node_modules/undici-types": { + "version": "6.21.0", + "resolved": "https://registry.npmjs.org/undici-types/-/undici-types-6.21.0.tgz", + "integrity": "sha512-iwDZqg0QAGrg9Rav5H4n0M64c3mkR59cJ6wQp+7C4nI0gsmExaedaYLNO44eT4AtBBwjbTiGPMlt2Md0T9H9JQ==", + "dev": true, + "license": "MIT" } } } diff --git a/package.json b/package.json index 80e20cc..44751a9 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@lapxo/topos-github", - "version": "0.1.2", + "version": "0.1.3", "description": "The forge a place asks for, rendered from its lines: the workflows that test, tag and release it, and what its repository never holds.", "type": "module", "license": "MIT", @@ -30,12 +30,18 @@ "dist", "README.md", "LICENSE", - "TARGET.bound" + "TARGET.bound", + "receipts.bound" ], "scripts": { - "build": "tsc --build" + "build": "tsc --build", + "test": "node --test test/*.test.ts" }, "dependencies": { - "@lapxo/topos": "^0.1.0" + "@lapxo/topos": "0.1.12" + }, + "devDependencies": { + "@types/node": "^22", + "typescript": "5.9.3" } } diff --git a/receipts.bound b/receipts.bound index 3da22f3..a74e15a 100644 --- a/receipts.bound +++ b/receipts.bound @@ -1,6 +1,185 @@ -bound-lock/1 at=place:sha256:df778902c0ce904b2abd549c0794f41c1542d876e1ce1a416b4ba49fe9689cba by=bound form=alphabet measure=digest role=writes scope=receipts value=sha256:14637bf7b736cf997c2f0a4d94332bab7eb81bcacce4eee59a3bf111646a1162 +bound-lock/1 at=place:sha256:6b3554be1ed484638426ba79e7c8b29fcdad187387a60fd945a0f5b98f3facb6 by=fold form=alphabet measure=digest role=writes scope=write/topos-typescript-tree/receipts.bound value=sha256:6b3554be1ed484638426ba79e7c8b29fcdad187387a60fd945a0f5b98f3facb6 +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=observed role=writes scope=src/regions/ignore.ts value=00246d80dca2046e +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=observed role=writes scope=src/regions/publish-auth-is-trusted.ts value=02128973d344f065 +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=observed role=writes scope=src/index.ts value=5021befb9f5f522c +bound-lock/1 at=place:sha256:6ad7ac4bc48040733a0993ba1f1c3bc1f586c5d3a99fcb63886952b40442415f by=reader:1b9fa141c118 form=alphabet measure=observed role=writes scope=./ value=6ad7ac4bc4804073 +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=observed role=writes scope=src/helpers/pipeline.ts value=757f8311759ec9f0 +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=observed role=writes scope=src/helpers/place.ts value=94dfc7ee99fe983f +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=observed role=writes scope=src/regions/github-actions.ts value=c13bb734622636fb +bound-lock/1 at=place:sha256:ea0f87db80e5848db75282af9c1543dcb2ccfc8dc0ce2ab47af2027875f63972 by=reader:0a0ce9bac2dd form=alphabet measure=observed role=writes scope=./ value=ea0f87db80e5848d +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/calls value=listed +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/carries value=Asked +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/declares value=render +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/heads value=ignore +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/capsule value=listed +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/lang value=ts +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/specifiers value=@lapxo/topos/capsule +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/words value=ignore +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=named role=reads scope=source/range/render value=182..244 +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/answers value="what a repository never holds, one line each" +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/head value=" The ignore region. It answers what a repository never holds, one line each. " +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/signature/render value="render(asked: Asked): readonly string[]" +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/listed value='ignore' +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/customised value=0..0 +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/dynamic value=0..0 +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/form-splits value=0..0 +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lexed value=0..0 +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lines value=5..5 +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/numbers value=0..0 +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/parsed value=0..0 +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/spans value=0..0 +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/text value=0..0 +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/unread value=0..0 +bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=interval measure=longest role=reads scope=source/longest value=1..1 +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/calls value=counted|said|value +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/declares value=receipt +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/heads value=count|pipeline|publish|tokens +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/../helpers/pipeline.ts value=said +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/capsule value=counted|value +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/lang value=ts +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/specifiers value=@lapxo/topos/capsule|../helpers/pipeline.ts +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/words value=count|tokens +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=named role=reads scope=source/range/receipt value=209..272 +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/answers value="whether a publish still names a secret" +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/head value=" The publish-auth-is-trusted region. It answers whether a publish still names a secret. " +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/signature/receipt value="receipt(asked: Asked)" +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/counted value='tokens' +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/said value='publish/auth' +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/value value='pipeline/publish/auth' +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/customised value=0..0 +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/dynamic value=0..0 +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/form-splits value=0..0 +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lexed value=0..0 +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lines value=5..5 +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/numbers value=0..0 +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/parsed value=0..0 +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/spans value=0..0 +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/text value=0..0 +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/unread value=0..0 +bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=interval measure=longest role=reads scope=source/longest value=1..1 +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/calls value=Error|alphabet|lines|own|provided|r0|r1|r2|readsOf|receiptShell|shell +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/carries value=Asked +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/compared value=reads +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/declares value=own|provided|readsOf|receipt|render +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/heads value=form|github-actions|ignore|notation|prose|publish-auth-is-trusted|reads|receipt|region|render|wire +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/capsule value=shell|receiptShell +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/wire value=alphabet +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/lang value=ts +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/shape value="a non-null assertion" +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/specifiers value=@lapxo/topos/capsule|@lapxo/topos/wire|./regions/github-actions.ts|./regions/ignore.ts|./regions/publish-auth-is-trusted.ts +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/words value=form|ignore|notation|prose|reads|receipt|render|wire +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=named role=reads scope=source/range/receipt value=1272..1333 +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=named role=reads scope=source/range/render value=920..980 +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/signature/receipt value=receipt(asked:Asked) +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/signature/render value=render(asked:Asked) +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/readsOf value="\"github-actions\"|\"ignore\"|\"publish-auth-is-trusted\"" +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/customised value=0..0 +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/dynamic value=0..0 +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/form-splits value=0..0 +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lexed value=0..0 +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lines value=17..17 +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/numbers value=0..0 +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/parsed value=1..1 +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/spans value=0..0 +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/text value=0..0 +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/unread value=0..0 +bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=interval measure=longest role=reads scope=source/longest value=4..4 +bound-lock/1 at=place:sha256:6ad7ac4bc48040733a0993ba1f1c3bc1f586c5d3a99fcb63886952b40442415f by=reader:1b9fa141c118 form=interval measure=unreceipted role=reads scope=door/unreceipted value=0..0 +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/calls value=fields|file|steps|value +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/declares value=said|workflow +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/heads value=audit|pipeline|wire +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/capsule value=value +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/wire value=fields|steps +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/lang value=ts +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/specifiers value=@lapxo/topos/capsule|@lapxo/topos/wire +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=named role=reads scope=source/range/said value=207..267 +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=named role=reads scope=source/range/workflow value=422..486 +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/head value=" A key of the place's pipeline: its own line, else the default the wire gives every world. " +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/signature/said value="said(asked: Asked, key: string): string" +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/signature/workflow value="workflow(shape: string): string" +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/value value='wire/pipeline/world'|'audit/wire/pipeline/world' +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/customised value=0..0 +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/dynamic value=0..0 +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/form-splits value=0..0 +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lexed value=0..0 +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lines value=11..11 +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/numbers value=0..0 +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/parsed value=0..0 +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/spans value=0..0 +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/text value=0..0 +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/unread value=0..0 +bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=longest role=reads scope=source/longest value=5..5 +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/calls value=Error|allow|alphabet|asked|asset|assets|auth|check|checkout|job|missing|nodes|of|one|quote|requireInputs|required|run|said|secretly|setup|value|withs +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/compared value=present +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/declares value=render|requireInputs +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/heads value=audit|branch|check|environment|fold|install|name|node|pack|pipeline|present|publish|published|release|scope|tag|test|two-heads|value|verify|version|wire +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/./pipeline.ts value=said +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/capsule value=of +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/wire value=alphabet +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/lang value=ts +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/specifiers value=@lapxo/topos/capsule|@lapxo/topos/wire|./pipeline.ts +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/words value=branch|check|environment|install|name|node|pack|present|publish|published|release|scope|tag|test|value|version +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=named role=reads scope=source/range/render value=1090..1152 +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/head value=" The handed workflow profile names its inputs before anything is rendered. " +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/signature/render value="render(asked: Asked, named: string): readonly string[]" +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/checkout value="'fetch-depth: 2'" +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/job value="['contents: read']|['contents: read']|['contents: write']|['contents: write']|['contents: read', ...(secret ? [] : ['id-token: write'])]" +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/of value='scope'|'value' +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/replace value="\"'\\\"'\\\"'\"" +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/said value='node'|'publish/auth'|'check'|'install'|'publish/command'|'fold/command'|'verify/command'|'fold/command'|'verify/key'|'verify/command'|'release/assets'|'release/digest-command'|'release/digest-command'|'branch'|'pack'|'pack'|'branch'|'version'|'version'|'pack'|'release/digest-command'|'release/notes'|'release/digest-command'|'version'|'release/digest-command'|'publish/once'|'published'|'name'|'version'|'publish/command'|'environment' +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/secretly value="[`version=\"v$(${said(asked, 'version')})\"`, 'git tag --list \"$version\" / grep -q . && exit 0', 'git tag \"$version\" && git push origin \"$version\"']" +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/customised value=0..0 +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/dynamic value=0..0 +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/form-splits value=0..0 +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lexed value=0..0 +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lines value=67..67 +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/numbers value=0..0 +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/parsed value=2..2 +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/spans value=0..0 +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/text value=0..0 +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/unread value=1..1 +bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=longest role=reads scope=source/longest value=50..50 +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/calls value=Error|asked|place|workflow +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/carries value=Asked +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/compared value=audit/wire/pipeline/world|capsule/key|wire/pipeline/world +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/declares value=render +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/heads value=audit|capsule|pipeline|scope|wire +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/../helpers/pipeline.ts value=workflow +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/../helpers/place.ts value=render +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/lang value=ts +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/specifiers value=@lapxo/topos/capsule|../helpers/pipeline.ts|../helpers/place.ts +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/words value=scope +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=named role=reads scope=source/range/render value=268..330 +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/answers value="which workflow the shape names, from the place's pipeline lines" +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/head value=" The github-actions region. It answers which workflow the shape names, from the place's pipeline lines. " +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/signature/render value="render(asked: Asked): readonly string[]" +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/customised value=0..0 +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/dynamic value=0..0 +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/form-splits value=0..0 +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lexed value=0..0 +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lines value=12..12 +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/numbers value=0..0 +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/parsed value=0..0 +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/spans value=0..0 +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/text value=0..0 +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/unread value=0..0 +bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=interval measure=longest role=reads scope=source/longest value=7..7 +bound-lock/1 at=place:sha256:ea0f87db80e5848db75282af9c1543dcb2ccfc8dc0ce2ab47af2027875f63972 by=reader:0a0ce9bac2dd form=interval measure=count role=reads scope=publish-auth-is-trusted/tokens value=0..0 +bound-lock/1 at=place:sha256:6133be7754b662e0979dd77c56f0e9e5784346388e9a442ee2cfb5bfc43e470b by=bound form=alphabet measure=digest role=writes scope=instrument/implementation value=sha256:6133be7754b662e0979dd77c56f0e9e5784346388e9a442ee2cfb5bfc43e470b -bound-lock/1 at=place:sha256:1662ef3b89c66de34660ae911aa5ea1a620d1da3e4f13ffd9eb29dfea2030c75 by=bound form=interval measure=count role=writes scope=receipts/source value=158..158 -bound-lock/1 at=place:sha256:c309594d23f8c70d916b50666031a3f213610c7e655c83b89b43e0f6c56b9da3 by=bound form=alphabet measure=bytes role=writes scope=receipts/source value=sha256:c309594d23f8c70d916b50666031a3f213610c7e655c83b89b43e0f6c56b9da3 -bound-lock/1 at=place:sha256:6ac00b6949306a47b9f8c1a3ee01a8b87e05da1ef1306ddc040e0c21a0c2743e by=bound form=interval measure=count role=writes scope=receipts/src value=7..7 -bound-lock/1 at=place:sha256:312127ae448c0e1bbba54a243e2d1bb9669c43c96f6ea3df613f661d909af91d by=bound form=alphabet measure=bytes role=writes scope=receipts/src value=sha256:312127ae448c0e1bbba54a243e2d1bb9669c43c96f6ea3df613f661d909af91d +bound-lock/1 at=place:sha256:53648217483215503da753bd952dc913d3ad5f26c381b2422b4eb8e4d61b1072 by=bound form=alphabet measure=digest role=writes scope=receipts value=sha256:4c2a7f824191b26563770df50df2048488118a65022d83a9ee0581f0ad2e7a12 + +bound-lock/1 at=place:sha256:5c082fef1ce762fa94247263374999862cb5dbacb123320ac771ce079ef38a1d by=bound form=interval measure=count role=writes scope=receipts/. value=2..2 +bound-lock/1 at=place:sha256:85f68938e18e3edb16187df5fa513c14d068d0e0cd1c8351a82ae3816e37a7f4 by=bound form=alphabet measure=bytes role=writes scope=receipts/. value=sha256:85f68938e18e3edb16187df5fa513c14d068d0e0cd1c8351a82ae3816e37a7f4 +bound-lock/1 at=place:sha256:45577827f043137dfe5cddff39aa4cf6bb61cc4361b6593e58fd119e92de7bfb by=bound form=interval measure=count role=writes scope=receipts/door value=1..1 +bound-lock/1 at=place:sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 by=bound form=alphabet measure=bytes role=writes scope=receipts/door value=sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 +bound-lock/1 at=place:sha256:496d2b3650b6dc875b9d8b36aadc110348d644b227f18e1a7fcb12c1df1c6267 by=bound form=interval measure=count role=writes scope=receipts/instrument value=1..1 +bound-lock/1 at=place:sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 by=bound form=alphabet measure=bytes role=writes scope=receipts/instrument value=sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 +bound-lock/1 at=place:sha256:d89c6fb88ef9356228dfe25d617aff88d5068e1af355034fae6baaae339e7a43 by=bound form=interval measure=count role=writes scope=receipts/publish-auth-is-trusted value=1..1 +bound-lock/1 at=place:sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 by=bound form=alphabet measure=bytes role=writes scope=receipts/publish-auth-is-trusted value=sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 +bound-lock/1 at=place:sha256:bfec36684511f3f5d6b0f961b9f146ecb57001dcd59b54c2efe3563e38030fef by=bound form=interval measure=count role=writes scope=receipts/source value=156..156 +bound-lock/1 at=place:sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 by=bound form=alphabet measure=bytes role=writes scope=receipts/source value=sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 +bound-lock/1 at=place:sha256:c95fe937618b93959f722f625d115af7a216ef24249126389a772f339e79748c by=bound form=interval measure=count role=writes scope=receipts/src value=6..6 +bound-lock/1 at=place:sha256:03afa13b3b3eac6d79d7907eb97a382bce4013a29055a0ad03d4634e03b5fd0b by=bound form=alphabet measure=bytes role=writes scope=receipts/src value=sha256:03afa13b3b3eac6d79d7907eb97a382bce4013a29055a0ad03d4634e03b5fd0b +bound-lock/1 at=place:sha256:1f8e612d12ae11253468b76be25ce5e71c43ab7c4e4811cef55c8cff57fcae2f by=bound form=interval measure=count role=writes scope=receipts/write value=1..1 +bound-lock/1 at=place:sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 by=bound form=alphabet measure=bytes role=writes scope=receipts/write value=sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 diff --git a/src/helpers/pipeline.ts b/src/helpers/pipeline.ts index 37c247d..3c051d9 100644 --- a/src/helpers/pipeline.ts +++ b/src/helpers/pipeline.ts @@ -2,7 +2,7 @@ import { value, type Asked } from '@lapxo/topos/capsule'; import { fields, steps } from '@lapxo/topos/wire'; /** A key of the place's pipeline: its own line, else the default the wire gives every world. */ -export const said = (asked: Asked, key: string): string => value(asked, `pipeline/${key}`) ?? new Map(fields(value(asked, 'audit/wire/pipeline/world') ?? '')).get(key) ?? ''; +export const said = (asked: Asked, key: string): string => value(asked, `pipeline/${key}`) ?? new Map(fields(value(asked, 'wire/pipeline/world') ?? value(asked, 'audit/wire/pipeline/world') ?? '')).get(key) ?? ''; export const workflow = (shape: string): string => { const file = steps(shape).at(-1) ?? ''; diff --git a/src/helpers/place.ts b/src/helpers/place.ts index e9dfc8f..404c913 100644 --- a/src/helpers/place.ts +++ b/src/helpers/place.ts @@ -1,17 +1,33 @@ -import type { Asked } from '@lapxo/topos/capsule'; +import { of, type Asked } from '@lapxo/topos/capsule'; import { alphabet } from '@lapxo/topos/wire'; import { said } from './pipeline.ts'; +/** The handed workflow profile names its inputs before anything is rendered. */ +const requireInputs = (asked: Asked, named: string): void => { + const contract = `wire/pipeline/required/${named}`; + const declarations = [...new Set(asked.lines.filter(line => [contract, `audit/${contract}`].includes(of(line, 'scope'))).map(line => of(line, 'value')))]; + if (declarations.length > 1) throw Error(`REFUSE·github-actions ${asked.shape} conflicting ${contract}`); + const declaration = declarations[0]; + if (declaration === undefined) throw Error(`REFUSE·github-actions ${asked.shape} missing ${contract}`); + const required = alphabet(declaration).members; + const missing = required.filter(key => !said(asked, key)); + if (missing.length) throw Error(`REFUSE·github-actions ${asked.shape} missing ${missing.map(key => 'pipeline/' + key).join(' · ')}`); +}; + /** The workflows a place that runs renders: test, tag, and a release that may publish. */ export const render = (asked: Asked, named: string): readonly string[] => { + requireInputs(asked, named); const nodes = alphabet(said(asked, 'node')).members; const [last, auth] = [nodes[nodes.length - 1] ?? '', said(asked, 'publish/auth')]; - const secret = auth.includes(':') ? auth.replace(/^[^:]*:/, '') : ''; + const colon = auth.indexOf(':'); + const secret = colon < 0 ? '' : auth.slice(colon + 1); const checkout = (...withs: readonly string[]): readonly string[] => [' - uses: actions/checkout@v4', ...(withs.length ? [' with:', ...withs.map((one) => ` ${one}`)] : [])]; const setup = (node: string): readonly string[] => [' - uses: actions/setup-node@v4', ' with:', ` node-version: ${node}`]; const secretly = (key: string, run: readonly string[]): readonly string[] => (key ? [' - env:', ` ${key}: \${{ secrets.${key} }}`, ' run: |', ' umask 077', ` printf '%s\\n' "$${key}" > "$RUNNER_TEMP/${key}"`, ` export ${key}="$RUNNER_TEMP/${key}"`, ...run.map((one) => ` ${one}`)] : [' - run: |', ...run.map((one) => ` ${one}`)]); - const runs = said(asked, 'check').split('&&').map((one) => one.trim()).filter(Boolean).map((run) => ` - run: ${run}`); + const check = said(asked, 'check'); + const runs = check.split('&&').map((one) => one.trim()).filter(Boolean).map((run) => ` - run: ${run}`); + const install = said(asked, 'install').split('&&').map(one => one.trim()).filter(Boolean).map(run => ` - run: ${run}`); const job = (name: string, allow: readonly string[], body: readonly string[], head: readonly string[] = []): readonly string[] => [` ${name}:`, ...head, ' runs-on: ubuntu-latest', ' permissions:', ...allow.map((one) => ` ${one}`), ' steps:', ...body]; const at = 'ref: ${{ github.event.workflow_run.head_sha || github.sha }}'; @@ -19,17 +35,30 @@ export const render = (asked: Asked, named: string): readonly string[] => { const tools = tool && said(asked, `publish/${tool}`) ? [` - run: ${tool} install --global ${tool}@'${said(asked, `publish/${tool}`)}'`] : []; const heads = said(asked, 'fold/command') && said(asked, 'verify/command') ? job('two-heads', ['contents: read'], [...checkout(), ...setup(last), ` - run: ${said(asked, 'fold/command')}`, ...secretly(said(asked, 'verify/key'), [said(asked, 'verify/command')])]) : []; + const assets = alphabet(said(asked, 'release/assets')).members; + const names = assets.map(asset => asset.split('/').at(-1)); + if (new Set(names).size !== names.length) throw Error(`REFUSE·github-actions ${asked.shape} release assets share a filename`); + const quote = (value: string): string => "'" + value.replace(/'/g, "'\"'\"'") + "'"; + const extraChecks = assets.flatMap(asset => [ + ` extra=${quote(asset)}`, + ' test -f "$extra"', + ' test "$(basename "$extra")" != "$(basename "$asset")"', + ` extra_expected="$(${said(asked, 'release/digest-command')} "$extra")"`, + ' gh release download "$version" --pattern "$(basename "$extra")" --dir "$RUNNER_TEMP/release-back"', + ` extra_actual="$(${said(asked, 'release/digest-command')} "$RUNNER_TEMP/release-back/$(basename "$extra")")"`, + ' test "${extra_expected%% *}" = "${extra_actual%% *}"', + ]); const workflows: Readonly> = { test: ['name: test', 'on:', ' push:', ` branches: [${said(asked, 'branch')}]`, ' pull_request:', 'jobs:', ...job('test', ['contents: read'], - [...checkout(), ...setup('${{ matrix.node }}'), ...runs, ...(said(asked, 'pack') ? [` - run: ${said(asked, 'pack')}`] : [])], [' strategy:', ' matrix:', ` node: [${nodes.join(', ')}]`]), ...heads], + [...checkout(), ...setup('${{ matrix.node }}'), ...install, ...runs, ...(said(asked, 'pack') ? [` - run: ${said(asked, 'pack')}`] : [])], [' strategy:', ' matrix:', ` node: [${nodes.join(', ')}]`]), ...heads], tag: ['name: tag', 'on:', ' push:', ` branches: [${said(asked, 'branch')}]`, 'jobs:', ...job('tag', ['contents: write'], [...checkout('fetch-depth: 0'), ...secretly('', [`version="v$(${said(asked, 'version')})"`, 'git tag --list "$version" | grep -q . && exit 0', 'git tag "$version" && git push origin "$version"'])])], release: ['name: release', 'on:', ' workflow_run:', ' workflows: [tag]', ' types: [completed]', ' push:', " tags: ['v*']", 'jobs:', - ...job('release', ['contents: write'], [...checkout(at, 'fetch-depth: 2'), ...setup(last), ...runs, ' - env:', ' GH_TOKEN: ${{ github.token }}', ' run: |', - ` version="v$(${said(asked, 'version')})"`, ' gh release view "$version" >/dev/null 2>&1 && exit 0', ` gh release create "$version"${said(asked, 'pack') ? ` "$(${said(asked, 'pack')})"` : ''}${alphabet(said(asked, 'release/assets')).members.map((one) => ` "${one}"`).join('')} --title "$version" --notes "${said(asked, 'release/notes') || '$version'}"`], - [" if: github.event_name == 'push' || github.event.workflow_run.conclusion == 'success'"]), - ...(auth ? job('publish', ['contents: read', ...(secret ? [] : ['id-token: write'])], [...checkout(at), ...setup(last), ...runs, ...tools, ...secretly(secret, [ - ...(said(asked, 'publish/once') === 'present' ? [`${said(asked, 'published')} "$(${said(asked, 'name')})@$(${said(asked, 'version')})" version >/dev/null 2>&1 && exit 0`] : []), said(asked, 'publish/command')])], + ...job('release', ['contents: write'], [...checkout(at, 'fetch-depth: 2'), ...setup(last), ...install, ...runs, ' - id: artifact', ' env:', ' GH_TOKEN: ${{ github.token }}', ' run: |', + ` version="v$(${said(asked, 'version')})"`, ` asset="$(${said(asked, 'pack')})"`, ' test -f "$asset"', ` expected="$(${said(asked, 'release/digest-command')} "$asset")"`, ' if ! gh release view "$version" >/dev/null 2>&1; then', ` gh release create "$version" "$asset"${assets.map(one => ` ${quote(one)}`).join('')} --title "$version" --notes "${said(asked, 'release/notes') || '$version'}"`, ' fi', ' gh release download "$version" --pattern "$(basename "$asset")" --dir "$RUNNER_TEMP/release-back"', ` actual="$(${said(asked, 'release/digest-command')} "$RUNNER_TEMP/release-back/$(basename "$asset")")"`, ' test "${expected%% *}" = "${actual%% *}"', ...extraChecks, ...(auth ? [" printf 'artifact=%s\\n' \"$(basename \"$asset\")\" >> \"$GITHUB_OUTPUT\"", " printf 'digest=%s\\n' \"${expected%% *}\" >> \"$GITHUB_OUTPUT\""] : [])], + [" if: github.event_name == 'push' || github.event.workflow_run.conclusion == 'success'", ...(auth ? [' outputs:', ' artifact: ${{ steps.artifact.outputs.artifact }}', ' digest: ${{ steps.artifact.outputs.digest }}'] : [])]), + ...(auth ? job('publish', ['contents: read', ...(secret ? [] : ['id-token: write'])], [...checkout(at), ...setup(last), ...tools, ' - env:', ' GH_TOKEN: ${{ github.token }}', ' RELEASE_ARTIFACT: ${{ needs.release.outputs.artifact }}', ' RELEASE_DIGEST: ${{ needs.release.outputs.digest }}', ' run: |', ` version="v$(${said(asked, 'version')})"`, ' test -n "$RELEASE_ARTIFACT"', ' test -n "$RELEASE_DIGEST"', ' gh release download "$version" --pattern "$RELEASE_ARTIFACT" --dir "$RUNNER_TEMP/publish"', ' asset="$RUNNER_TEMP/publish/$RELEASE_ARTIFACT"', ` actual="$(${said(asked, 'release/digest-command')} "$asset")"`, ' test "${actual%% *}" = "$RELEASE_DIGEST"', " printf 'RELEASE_ASSET=%s\\n' \"$asset\" >> \"$GITHUB_ENV\"", ...secretly(secret, [ + ...(said(asked, 'publish/once') === 'present' ? [`${said(asked, 'published')} "$(${said(asked, 'name')})@$(${said(asked, 'version')})" version >/dev/null 2>&1 && exit 0`] : []), `asset="$RELEASE_ASSET"`, said(asked, 'publish/command')])], [' needs: release', ` environment: ${said(asked, 'environment')}`]) : [])], }; const held = workflows[named]; diff --git a/src/helpers/world.ts b/src/helpers/world.ts deleted file mode 100644 index 7911124..0000000 --- a/src/helpers/world.ts +++ /dev/null @@ -1,34 +0,0 @@ -/** The release a world renders: tag folded into the one job, the blob checked, contents write only. */ -export const release = (branch: string, runtime: string, version: string): readonly string[] => { - const run = [ - `version="v$(${version})"`, - 'git diff HEAD^ HEAD -- package.json | grep -q \'"version"\' || exit 0', - 'git tag --list "$version" | grep -q . && exit 0', - 'git tag "$version" && git push origin "$version"', - 'git checkout "$version"', - 'npm ci', - 'one="$(bound fold --as release)"', - 'two="$(bound fold --as release)"', - 'test "$one" = "$two"', - 'printf \'%s\' "$one" > release.blob', - 'digest="sha256:$(sha256sum release.blob | awk \'{print $1}\')"', - 'export digest', - 'asset="${digest#sha256:}.tar.gz"', - 'mv release.blob "$asset"', - 'printf \'%s\\n\' "$(bound fold --as release --check)" | grep -q \'^SAME\'', - 'secrets="$(grep -RIlE \'BEGIN (RSA|EC|OPENSSH|PRIVATE)|sk_live_|ghp_|AKIA\' --exclude-dir=node_modules --exclude-dir=.git . | wc -l | tr -d \' \')"', - 'stray=0', - 'nonjs="$(find dist -type f ! -name \'*.js\' ! -name \'*.d.ts\' 2>/dev/null | wc -l | tr -d \' \')"', - 'words="$(grep -RIlE \'registry\\.npmjs\\.org\' --exclude-dir=node_modules --exclude-dir=.git . | wc -l | tr -d \' \')"', - 'test "$secrets" = 0 && test "$stray" = 0 && test "$nonjs" = 0 && test "$words" = 0', - 'node --input-type=module -e \'import { readFileSync, writeFileSync } from "node:fs"; const lines = readFileSync("TARGET.bound","utf8").split("\\n").filter((line) => line.startsWith("bound-lock/1 ") && !line.includes(" value=withdraw")); const take = (head) => lines.filter((line) => line.includes(` scope=${head}`)); writeFileSync("release.json", JSON.stringify({ digest: process.env.digest, sources: take("sources/"), uses: take("uses/"), needs: take("needs/") }, null, 2) + "\\n");\'', - 'gh release create "$version" "$asset" release.json --title "$version" --notes "$version"', - 'gh release download "$version" --pattern "$asset" --dir "$RUNNER_TEMP/back" --clobber', - 'got="$(sha256sum "$RUNNER_TEMP/back/$asset" | awk \'{print $1}\')"', - 'case "$digest" in *"$got"*) ;; *) gh release delete "$version" --yes --cleanup-tag; exit 1 ;; esac', - '{ echo \'```\'; node -e \'const j=JSON.parse(require("fs").readFileSync("release.json","utf8")); for (const k of ["sources","uses","needs"]) for (const line of j[k]) console.log(line)\'; echo \'```\'; } >> "$GITHUB_STEP_SUMMARY"', - ]; - return ['name: release', 'on:', ' push:', ` branches: [${branch}]`, 'jobs:', ' release:', ' runs-on: ubuntu-latest', ' permissions:', ' contents: write', ' steps:', - ' - uses: actions/checkout@v4', ' with:', ' fetch-depth: 0', ' - uses: actions/setup-node@v4', ' with:', ` node-version: ${runtime}`, - ' - env:', ' GH_TOKEN: ${{ github.token }}', ' run: |', ...run.map((line) => ` ${line}`)]; -}; diff --git a/src/index.ts b/src/index.ts index b4aafde..0a3f781 100644 --- a/src/index.ts +++ b/src/index.ts @@ -1,3 +1,17 @@ -import { receiptShell, shell } from '@lapxo/topos/capsule'; -export const render = shell(import.meta.url); -export const receipt = receiptShell(import.meta.url); +import{shell,receiptShell}from'@lapxo/topos/capsule'; +import type{Asked}from'@lapxo/topos/capsule'; +import{alphabet}from'@lapxo/topos/wire'; +import * as r0 from './regions/github-actions.ts'; +import * as r1 from './regions/ignore.ts'; +import * as r2 from './regions/publish-auth-is-trusted.ts'; +type Fields=Readonly>; +const provided=(asked:Asked):readonly Fields[]=>{const lines=(asked as Asked & {provider?:{lines?:readonly Fields[]}}).provider?.lines;if(lines===undefined)throw Error('REFUSE·world provider standing not handed');return lines;}; +const own=(lines:readonly Fields[]):readonly Fields[]=>lines.filter(f=>['form','prose','notation','wire'].includes((f.scope??'').split('/')[0]!)); +const readsOf=(lines:readonly Fields[],name:string,role:string):readonly string[]=>lines.filter(f=>f.scope==='region/'+name&&f.role===role&&f.measure==='reads').flatMap(f=>alphabet(f.value??'').members); +export const render=(asked:Asked)=>{const lines=provided(asked);return shell({ + "github-actions":{reads:readsOf(lines,"github-actions","render"),region:(a:Asked)=>r0.render({...a,lines:[...a.lines,...own(lines)]})}, + "ignore":{reads:readsOf(lines,"ignore","render"),region:(a:Asked)=>r1.render({...a,lines:[...a.lines,...own(lines)]})}, +})(asked);}; +export const receipt=(asked:Asked)=>{const lines=provided(asked);return receiptShell({ + "publish-auth-is-trusted":{reads:readsOf(lines,"publish-auth-is-trusted","receipt"),region:(a:Asked)=>r2.receipt({...a,lines:[...a.lines,...own(lines)]})}, +})(asked);}; diff --git a/src/regions/github-actions.ts b/src/regions/github-actions.ts index 8d87a61..b90291b 100644 --- a/src/regions/github-actions.ts +++ b/src/regions/github-actions.ts @@ -1,14 +1,12 @@ import type { Asked } from '@lapxo/topos/capsule'; -import { said, workflow } from '../helpers/pipeline.ts'; +import { workflow } from '../helpers/pipeline.ts'; import { render as place } from '../helpers/place.ts'; -import { release as worldRelease } from '../helpers/world.ts'; /** The github-actions region. It answers which workflow the shape names, from the place's pipeline lines. */ export const render = (asked: Asked): readonly string[] => { const named = workflow(asked.shape); - const world = asked.lines.some((line) => line['scope'] === 'capsule/key'); + const world = asked.lines.some((line) => line['scope'] === 'capsule/key' || line['scope'] === 'wire/pipeline/world' || line['scope'] === 'audit/wire/pipeline/world'); const runs = !world || asked.lines.some((line) => (line['scope'] ?? '').startsWith('pipeline/')); if (runs) return place(asked, named); - if (named === 'release') return worldRelease(said(asked, 'branch'), said(asked, 'runtime'), said(asked, 'version')); - return [`REFUSE·github-actions: no workflow of the forge is named by ${asked.shape}`]; + throw Error(`REFUSE·github-actions ${asked.shape} requires declared pipeline lines`); }; diff --git a/test/workflow-contract.test.ts b/test/workflow-contract.test.ts new file mode 100644 index 0000000..7888044 --- /dev/null +++ b/test/workflow-contract.test.ts @@ -0,0 +1,113 @@ +import test from 'node:test'; +import assert from 'node:assert/strict'; +import { render } from '../src/helpers/place.ts'; +import { mkdtempSync, writeFileSync, rmSync } from 'node:fs'; +import { tmpdir } from 'node:os'; +import { join } from 'node:path'; +import { spawnSync } from 'node:child_process'; +import type { Asked } from '@lapxo/topos/capsule'; + +const asked = (pipeline: Record): Asked => ({ + name: 'independent-place', shape: '.github/workflows/test.yml', + lines: [...Object.entries({test:'branch|node|check',tag:'branch|version',release:'branch|node|version|check|pack|release/digest-command'}).map(([name,value])=>({scope:`wire/pipeline/required/${name}`,value,role:'writes',form:'alphabet',measure:'id'})),...Object.entries(pipeline).map(([key, value]) => ({ + scope: `pipeline/${key}`, value, role: 'writes', form: 'alphabet', measure: 'id', + }))], +} as Asked); +const base = { branch: 'main', node: '22|24', version: 'read-version', check: 'judge-place', pack: 'pack-place', 'release/digest-command': 'hash-asset' }; + +test('an absent install declaration contributes no command to test or release', () => { + for (const workflow of ['test', 'release']) { + const lines = render(asked(base), workflow); + assert.ok(lines.some(line => line.includes('judge-place'))); + assert.equal(lines.some(line => line.includes('npm ci')), false); + } +}); + +test('the place chooses its install commands, in declared order', () => { + for (const workflow of ['test', 'release']) { + const lines = render(asked({ ...base, install: 'fetch-inputs && prepare-place' }), workflow); + const fetch = lines.indexOf(' - run: fetch-inputs'); + const prepare = lines.indexOf(' - run: prepare-place'); + const check = lines.indexOf(' - run: judge-place'); + assert.ok(fetch >= 0 && prepare > fetch && check > prepare); + assert.equal(lines.some(line => line.includes('npm ci')), false); + } +}); + +test('an absent required check refuses by coordinate', () => { + const { check, ...missing } = base; + assert.throws(() => render(asked(missing), 'test'), /REFUSE·github-actions.*pipeline\/check/); +}); + +test('required fields come from the handed contract, not a hidden checklist', () => { + const input=asked({...base,approval:'confirmed'}); + const profile=input.lines.find(line=>line.scope==='wire/pipeline/required/test')!; + const lines=input.lines.filter(line=>line!==profile); + assert.throws(()=>render({...input,lines},'test'),/missing wire\/pipeline\/required\/test/); + const custom={...profile,value:'branch|node|check|approval'}; + assert.ok(render({...input,lines:[...lines,custom]},'test').length); + assert.throws(()=>render({...input,lines:[...lines.filter(line=>line.scope!=='pipeline/approval'),custom]},'test'),/missing pipeline\/approval/); +}); + +test('incompatible required-field profiles refuse in either order; duplicates are idempotent', () => { + const input=asked(base),profile=input.lines.find(line=>line.scope==='wire/pipeline/required/test')!; + assert.deepEqual(render({...input,lines:[...input.lines,{...profile}]},'test'),render(input,'test')); + for(const lines of [[...input.lines,{...profile,value:'branch|approval'}],[{...profile,value:'branch|approval'},...input.lines]]) { + assert.throws(()=>render({...input,lines},'test'),/conflicting wire\/pipeline\/required\/test/); + } +}); + +for (const place of ['library', 'service']) test(`staging uses the verified release archive without rebuilding: ${place}`, () => { + const lines = render(asked({ ...base, branch: place, install: 'fetch-inputs', 'publish/auth': 'trusted', 'publish/command': 'stage-artifact "$asset"', environment: 'release' }), 'release'); + const text = lines.join('\n'), publishing = text.slice(text.indexOf(' publish:')); + assert.equal(lines.filter(line => line.includes('asset="$(pack-place)"')).length, 1); + assert.ok(publishing.includes('needs.release.outputs.artifact')); + assert.ok(publishing.includes('needs.release.outputs.digest')); + assert.ok(publishing.includes('gh release download')); + assert.ok(publishing.indexOf('test "${actual%% *}" = "$RELEASE_DIGEST"') < publishing.indexOf('stage-artifact "$asset"')); + assert.ok(!publishing.includes('fetch-inputs')); + assert.ok(!publishing.includes('judge-place')); + assert.ok(!publishing.includes('pack-place')); + assert.ok(!text.includes('gh release view "$version" >/dev/null 2>&1 && exit 0')); +}); + +test('workflow metadata uses shell newlines rather than literal backslash-n', () => { + const text = render(asked({ ...base, 'publish/auth': 'trusted', 'publish/command': 'stage-artifact "$asset"', environment: 'release' }), 'release').join('\n'); + assert.ok(text.includes("printf 'artifact=%s\\n'")); + assert.ok(text.includes("printf 'digest=%s\\n'")); + assert.ok(!text.includes("printf 'artifact=%s\\\\n'")); +}); + +for (const place of ['library', 'service']) test(`every declared release asset is downloaded and verified: ${place}`, () => { + const root = mkdtempSync(join(tmpdir(), 'forge-assets-')); + try { + writeFileSync(join(root, 'primary.tgz'), 'archive'); + writeFileSync(join(root, 'standing'), 'canonical standing'); + const lines = render(asked({ ...base, branch: place, version: "printf 1", pack: 'printf primary.tgz', 'release/digest-command': 'shasum -a 256', 'release/assets': 'standing' }), 'release'); + const start = lines.findIndex(line => line.startsWith(' version=')); + const end = lines.findIndex((line, index) => index > start && !line.startsWith(' ')); + const script = lines.slice(start, end < 0 ? undefined : end).map(line => line.slice(10)).join('\n'); + const fake = `gh() { + if [ "$1 $2" = "release view" ]; then return 0; fi + if [ "$1 $2" = "release download" ]; then + mkdir -p "$7" + case "$5" in + standing) [ "$MODE" != missing ] || return 1; + if [ "$MODE" = corrupt ]; then printf corrupt > "$7/$5"; else cp "$5" "$7/$5"; fi ;; + *) cp "$5" "$7/$5" ;; + esac + return 0 + fi + return 1 + } + `; + for (const mode of ['same', 'corrupt', 'missing']) { + const result = spawnSync('bash', ['-e', '-c', fake + script], { cwd: root, encoding: 'utf8', env: { ...process.env, MODE: mode, RUNNER_TEMP: join(root, mode) }, timeout: 5000 }); + assert.equal(result.status === 0, mode === 'same', result.stderr); + } + } finally { rmSync(root, { recursive: true, force: true }); } +}); + +test('release assets with identical filenames refuse before rendering', () => { + assert.throws(() => render(asked({ ...base, 'release/assets': 'first/standing|second/standing' }), 'release'), /REFUSE.*share a filename/); +}); From 5d3049d4d11ee72c629f55cc759d7bf85344df10 Mon Sep 17 00:00:00 2001 From: NahumDev <60716442+NahumOchoa@users.noreply.github.com> Date: Fri, 9 Oct 2026 01:58:59 -0600 Subject: [PATCH 2/2] Close native receipts and verify release asset delivery --- .github/workflows/release.yml | 58 +++++++++++++- TARGET.bound | 9 ++- receipts.bound | 139 +++++++++++++++++---------------- src/helpers/pipeline.ts | 8 +- src/helpers/place.ts | 2 +- test/workflow-contract.test.ts | 10 +++ 6 files changed, 152 insertions(+), 74 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 8d403b7..568de8a 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -27,12 +27,68 @@ jobs: GH_TOKEN: ${{ github.token }} run: | version="v$(node -p "require('./package.json').version")" + mkdir -p release-assets + gh release download "$version" --repo Lapxo/topos-github --pattern '0f5b05b2bd1b1f5e3641e6539e61fae87d791c4d51aa5d3d304ffdc064e7fe4d' --dir release-assets || gh release download "${version}-inputs" --repo Lapxo/topos-github --pattern '0f5b05b2bd1b1f5e3641e6539e61fae87d791c4d51aa5d3d304ffdc064e7fe4d' --dir release-assets + printf '%s %s\n' '0f5b05b2bd1b1f5e3641e6539e61fae87d791c4d51aa5d3d304ffdc064e7fe4d' 'release-assets/0f5b05b2bd1b1f5e3641e6539e61fae87d791c4d51aa5d3d304ffdc064e7fe4d' | sha256sum -c - + gh release download "$version" --repo Lapxo/topos-github --pattern '97190fb5e62ffd89940dc08bbbfc7ff865bd4f2096c1805e172297a4a441cb01' --dir release-assets || gh release download "${version}-inputs" --repo Lapxo/topos-github --pattern '97190fb5e62ffd89940dc08bbbfc7ff865bd4f2096c1805e172297a4a441cb01' --dir release-assets + printf '%s %s\n' '97190fb5e62ffd89940dc08bbbfc7ff865bd4f2096c1805e172297a4a441cb01' 'release-assets/97190fb5e62ffd89940dc08bbbfc7ff865bd4f2096c1805e172297a4a441cb01' | sha256sum -c - + gh release download "$version" --repo Lapxo/topos-github --pattern 'archive-profile.mjs' --dir release-assets || gh release download "${version}-inputs" --repo Lapxo/topos-github --pattern 'archive-profile.mjs' --dir release-assets + printf '%s %s\n' 'b29b48db2b4d9633a095765ae65e99ca8c14aae10a76735f006fb728a23e5aaa' 'release-assets/archive-profile.mjs' | sha256sum -c - + npx --yes --package esbuild@0.28.2 esbuild src/index.ts --bundle --platform=node --format=esm --outfile="$RUNNER_TEMP/runtime-index.js" + printf '%s %s\n' 'c99a99e45f88b31979e57281cdf74ee695092724abb65553d95b51f4ed5fb890' "$RUNNER_TEMP/runtime-index.js" | sha256sum -c - + node release-assets/archive-profile.mjs 'release-assets/36e1f6822242625e745e5fb1611d8c74c2b769e39b902d1eff56e384bb3ae29e' 'sha256:36e1f6822242625e745e5fb1611d8c74c2b769e39b902d1eff56e384bb3ae29e' capsule.bound 'release-assets/97190fb5e62ffd89940dc08bbbfc7ff865bd4f2096c1805e172297a4a441cb01' dist/index.js "$RUNNER_TEMP/runtime-index.js" >&2 + gh release download "$version" --repo Lapxo/topos-github --pattern 'ce09169123e270319fcd9cfb46c414d8693d6e28800e1cf58cc4716e531915cb' --dir release-assets || gh release download "${version}-inputs" --repo Lapxo/topos-github --pattern 'ce09169123e270319fcd9cfb46c414d8693d6e28800e1cf58cc4716e531915cb' --dir release-assets + printf '%s %s\n' 'ce09169123e270319fcd9cfb46c414d8693d6e28800e1cf58cc4716e531915cb' 'release-assets/ce09169123e270319fcd9cfb46c414d8693d6e28800e1cf58cc4716e531915cb' | sha256sum -c - + gh release download "$version" --repo Lapxo/topos-github --pattern '1b6385f068b4d35d6688150e964694353c96c8ed027bac95cc5ef5d90e6035c0' --dir release-assets || gh release download "${version}-inputs" --repo Lapxo/topos-github --pattern '1b6385f068b4d35d6688150e964694353c96c8ed027bac95cc5ef5d90e6035c0' --dir release-assets + printf '%s %s\n' '1b6385f068b4d35d6688150e964694353c96c8ed027bac95cc5ef5d90e6035c0' 'release-assets/1b6385f068b4d35d6688150e964694353c96c8ed027bac95cc5ef5d90e6035c0' | sha256sum -c - asset="$(npm pack --silent)" test -f "$asset" expected="$(sha256sum "$asset")" if ! gh release view "$version" >/dev/null 2>&1; then - gh release create "$version" "$asset" --title "$version" --notes "$version" + gh release create "$version" "$asset" 'release-assets/0f5b05b2bd1b1f5e3641e6539e61fae87d791c4d51aa5d3d304ffdc064e7fe4d' 'release-assets/36e1f6822242625e745e5fb1611d8c74c2b769e39b902d1eff56e384bb3ae29e' 'release-assets/97190fb5e62ffd89940dc08bbbfc7ff865bd4f2096c1805e172297a4a441cb01' 'release-assets/archive-profile.mjs' 'release-assets/ce09169123e270319fcd9cfb46c414d8693d6e28800e1cf58cc4716e531915cb' 'release-assets/1b6385f068b4d35d6688150e964694353c96c8ed027bac95cc5ef5d90e6035c0' --title "$version" --notes "$version" fi gh release download "$version" --pattern "$(basename "$asset")" --dir "$RUNNER_TEMP/release-back" actual="$(sha256sum "$RUNNER_TEMP/release-back/$(basename "$asset")")" test "${expected%% *}" = "${actual%% *}" + extra='release-assets/0f5b05b2bd1b1f5e3641e6539e61fae87d791c4d51aa5d3d304ffdc064e7fe4d' + test -f "$extra" + test "$(basename "$extra")" != "$(basename "$asset")" + extra_expected="$(sha256sum "$extra")" + gh release download "$version" --pattern "$(basename "$extra")" --dir "$RUNNER_TEMP/release-back" + extra_actual="$(sha256sum "$RUNNER_TEMP/release-back/$(basename "$extra")")" + test "${extra_expected%% *}" = "${extra_actual%% *}" + extra='release-assets/36e1f6822242625e745e5fb1611d8c74c2b769e39b902d1eff56e384bb3ae29e' + test -f "$extra" + test "$(basename "$extra")" != "$(basename "$asset")" + extra_expected="$(sha256sum "$extra")" + gh release download "$version" --pattern "$(basename "$extra")" --dir "$RUNNER_TEMP/release-back" + extra_actual="$(sha256sum "$RUNNER_TEMP/release-back/$(basename "$extra")")" + test "${extra_expected%% *}" = "${extra_actual%% *}" + extra='release-assets/97190fb5e62ffd89940dc08bbbfc7ff865bd4f2096c1805e172297a4a441cb01' + test -f "$extra" + test "$(basename "$extra")" != "$(basename "$asset")" + extra_expected="$(sha256sum "$extra")" + gh release download "$version" --pattern "$(basename "$extra")" --dir "$RUNNER_TEMP/release-back" + extra_actual="$(sha256sum "$RUNNER_TEMP/release-back/$(basename "$extra")")" + test "${extra_expected%% *}" = "${extra_actual%% *}" + extra='release-assets/archive-profile.mjs' + test -f "$extra" + test "$(basename "$extra")" != "$(basename "$asset")" + extra_expected="$(sha256sum "$extra")" + gh release download "$version" --pattern "$(basename "$extra")" --dir "$RUNNER_TEMP/release-back" + extra_actual="$(sha256sum "$RUNNER_TEMP/release-back/$(basename "$extra")")" + test "${extra_expected%% *}" = "${extra_actual%% *}" + extra='release-assets/ce09169123e270319fcd9cfb46c414d8693d6e28800e1cf58cc4716e531915cb' + test -f "$extra" + test "$(basename "$extra")" != "$(basename "$asset")" + extra_expected="$(sha256sum "$extra")" + gh release download "$version" --pattern "$(basename "$extra")" --dir "$RUNNER_TEMP/release-back" + extra_actual="$(sha256sum "$RUNNER_TEMP/release-back/$(basename "$extra")")" + test "${extra_expected%% *}" = "${extra_actual%% *}" + extra='release-assets/1b6385f068b4d35d6688150e964694353c96c8ed027bac95cc5ef5d90e6035c0' + test -f "$extra" + test "$(basename "$extra")" != "$(basename "$asset")" + extra_expected="$(sha256sum "$extra")" + gh release download "$version" --pattern "$(basename "$extra")" --dir "$RUNNER_TEMP/release-back" + extra_actual="$(sha256sum "$RUNNER_TEMP/release-back/$(basename "$extra")")" + test "${extra_expected%% *}" = "${extra_actual%% *}" diff --git a/TARGET.bound b/TARGET.bound index 7da4935..afd9806 100644 --- a/TARGET.bound +++ b/TARGET.bound @@ -43,6 +43,7 @@ bound-lock/1 about="how together a region arrived, one when every line landed at bound-lock/1 about="its leaf" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/regions/leaf value=lock bound-lock/1 about="its regions, read off its own descriptor" at=witness:own-project-prose by=target form=alphabet measure=text role=writes scope=prose/en/door/words value=lock bound-lock/1 about="lines that stand on one origin and are therefore not yet information" at=policy:region/grey by=target form=alphabet measure=text role=writes scope=region/grey value=lock +bound-lock/1 about="mkdir -p release-assets\ngh release download \"$version\" --repo Lapxo/topos-github --pattern '0f5b05b2bd1b1f5e3641e6539e61fae87d791c4d51aa5d3d304ffdc064e7fe4d' --dir release-assets || gh release download \"${version}-inputs\" --repo Lapxo/topos-github --pattern '0f5b05b2bd1b1f5e3641e6539e61fae87d791c4d51aa5d3d304ffdc064e7fe4d' --dir release-assets\nprintf '%s %s\\n' '0f5b05b2bd1b1f5e3641e6539e61fae87d791c4d51aa5d3d304ffdc064e7fe4d' 'release-assets/0f5b05b2bd1b1f5e3641e6539e61fae87d791c4d51aa5d3d304ffdc064e7fe4d' | sha256sum -c -\ngh release download \"$version\" --repo Lapxo/topos-github --pattern '97190fb5e62ffd89940dc08bbbfc7ff865bd4f2096c1805e172297a4a441cb01' --dir release-assets || gh release download \"${version}-inputs\" --repo Lapxo/topos-github --pattern '97190fb5e62ffd89940dc08bbbfc7ff865bd4f2096c1805e172297a4a441cb01' --dir release-assets\nprintf '%s %s\\n' '97190fb5e62ffd89940dc08bbbfc7ff865bd4f2096c1805e172297a4a441cb01' 'release-assets/97190fb5e62ffd89940dc08bbbfc7ff865bd4f2096c1805e172297a4a441cb01' | sha256sum -c -\ngh release download \"$version\" --repo Lapxo/topos-github --pattern 'archive-profile.mjs' --dir release-assets || gh release download \"${version}-inputs\" --repo Lapxo/topos-github --pattern 'archive-profile.mjs' --dir release-assets\nprintf '%s %s\\n' 'b29b48db2b4d9633a095765ae65e99ca8c14aae10a76735f006fb728a23e5aaa' 'release-assets/archive-profile.mjs' | sha256sum -c -\nnpx --yes --package esbuild@0.28.2 esbuild src/index.ts --bundle --platform=node --format=esm --outfile=\"$RUNNER_TEMP/runtime-index.js\"\nprintf '%s %s\\n' 'c99a99e45f88b31979e57281cdf74ee695092724abb65553d95b51f4ed5fb890' \"$RUNNER_TEMP/runtime-index.js\" | sha256sum -c -\nnode release-assets/archive-profile.mjs 'release-assets/36e1f6822242625e745e5fb1611d8c74c2b769e39b902d1eff56e384bb3ae29e' 'sha256:36e1f6822242625e745e5fb1611d8c74c2b769e39b902d1eff56e384bb3ae29e' capsule.bound 'release-assets/97190fb5e62ffd89940dc08bbbfc7ff865bd4f2096c1805e172297a4a441cb01' dist/index.js \"$RUNNER_TEMP/runtime-index.js\" >&2\ngh release download \"$version\" --repo Lapxo/topos-github --pattern 'ce09169123e270319fcd9cfb46c414d8693d6e28800e1cf58cc4716e531915cb' --dir release-assets || gh release download \"${version}-inputs\" --repo Lapxo/topos-github --pattern 'ce09169123e270319fcd9cfb46c414d8693d6e28800e1cf58cc4716e531915cb' --dir release-assets\nprintf '%s %s\\n' 'ce09169123e270319fcd9cfb46c414d8693d6e28800e1cf58cc4716e531915cb' 'release-assets/ce09169123e270319fcd9cfb46c414d8693d6e28800e1cf58cc4716e531915cb' | sha256sum -c -\ngh release download \"$version\" --repo Lapxo/topos-github --pattern '1b6385f068b4d35d6688150e964694353c96c8ed027bac95cc5ef5d90e6035c0' --dir release-assets || gh release download \"${version}-inputs\" --repo Lapxo/topos-github --pattern '1b6385f068b4d35d6688150e964694353c96c8ed027bac95cc5ef5d90e6035c0' --dir release-assets\nprintf '%s %s\\n' '1b6385f068b4d35d6688150e964694353c96c8ed027bac95cc5ef5d90e6035c0' 'release-assets/1b6385f068b4d35d6688150e964694353c96c8ed027bac95cc5ef5d90e6035c0' | sha256sum -c -" at=witness:retained-provider-delivery by=target form=alphabet measure=text role=writes scope=pipeline/release/prepare value=lock bound-lock/1 about="packed as {digest}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/blob value=lock bound-lock/1 about="pinned by {place}" at=policy:prose by=target form=alphabet measure=text role=writes scope=prose/en/figure/world/pinned value=lock bound-lock/1 about="publish the version once, by the trusted publisher" at=policy:form by=target form=alphabet measure=text role=writes scope=form/prose/en/page/pipeline/publish value=lock @@ -473,21 +474,25 @@ bound-lock/1 at=policy:wire/region-measures by=target form=alphabet measure=id r bound-lock/1 at=policy:wire/shapes by=target form=alphabet measure=id role=reads scope=audit/wire/shapes value=decision|lock|package|reader|render|run|vector|view bound-lock/1 at=policy:wire/states by=target form=alphabet measure=id role=reads scope=audit/wire/states value=absent|present|unread|withdraw bound-lock/1 at=policy:wire/templates by=target form=alphabet measure=id role=reads scope=audit/wire/templates value={cone}|{roots} +bound-lock/1 at=witness:installed-dependencies-are-foreign by=target form=alphabet measure=role role=writes scope=coordinate-role/node_modules value=foreign bound-lock/1 at=witness:native-receipts-ship-with-the-place by=target form=alphabet measure=id role=reads scope=audit/wire/ships value=dist|README.md|LICENSE|TARGET.bound|receipts.bound bound-lock/1 at=witness:native-render-release by=target form=alphabet measure=id needs=package.json role=writes scope=version shape=package.json value=0.1.3 bound-lock/1 at=witness:own-page-from-own-prose by=target form=alphabet measure=id needs=README.md role=demands scope=view/readme-capsule shape=README.md value=hero|idea bound-lock/1 at=witness:own-store-never-ships by=target form=alphabet measure=id role=demands scope=view/gitignore shape=.gitignore value=ignore bound-lock/1 at=witness:portable-native-receipts by=target form=alphabet measure=id role=demands scope=view/receipts shape=receipts.bound value=receipts@8|receipts@0|receipts@1 bound-lock/1 at=witness:published-render-contract by=target form=alphabet measure=id needs=package.json role=writes scope=dependencies shape=package.json value=@lapxo/topos@0.1.12 +bound-lock/1 at=witness:reproducible-release-assets by=target form=alphabet measure=digest role=writes scope=dep/runtime-topos-github shape=dist/index.js value=sha256:36e1f6822242625e745e5fb1611d8c74c2b769e39b902d1eff56e384bb3ae29e +bound-lock/1 at=witness:reproducible-release-assets by=target form=alphabet measure=digest role=writes scope=uses/topos-github value=sha256:0f5b05b2bd1b1f5e3641e6539e61fae87d791c4d51aa5d3d304ffdc064e7fe4d +bound-lock/1 at=witness:reproducible-release-assets by=target form=alphabet measure=id role=writes scope=sources/runtime-topos-github value=https://github.com/Lapxo/topos-github/releases/download/v0.1.3/36e1f6822242625e745e5fb1611d8c74c2b769e39b902d1eff56e384bb3ae29e +bound-lock/1 at=witness:reproducible-release-assets by=target form=alphabet measure=id role=writes scope=sources/topos-github value=https://github.com/Lapxo/topos-github/releases/download/v0.1.3/0f5b05b2bd1b1f5e3641e6539e61fae87d791c4d51aa5d3d304ffdc064e7fe4d +bound-lock/1 at=witness:retained-provider-delivery by=target form=alphabet measure=id role=writes scope=pipeline/release/assets value=release-assets/0f5b05b2bd1b1f5e3641e6539e61fae87d791c4d51aa5d3d304ffdc064e7fe4d|release-assets/36e1f6822242625e745e5fb1611d8c74c2b769e39b902d1eff56e384bb3ae29e|release-assets/97190fb5e62ffd89940dc08bbbfc7ff865bd4f2096c1805e172297a4a441cb01|release-assets/archive-profile.mjs|release-assets/ce09169123e270319fcd9cfb46c414d8693d6e28800e1cf58cc4716e531915cb|release-assets/1b6385f068b4d35d6688150e964694353c96c8ed027bac95cc5ef5d90e6035c0 bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest needs=topos-typescript-tree role=reads scope=dep/typescript-reader value=sha256:ecf86c50adacb3e199e7363fb355ad66d7c76a76ab1e007836d9e9fbc74ad434 bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest needs=topos-typescript-tree/node_modules/@lapxo/obligations role=reads scope=dep/typescript-reader-algebra shape=package value=sha256:e4b48f480e86c2e1b9518b7a5dbe18e4b4dfa449961c781a291295fa85a3ec72 bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest needs=topos-typescript-tree/node_modules/@lapxo/topos role=reads scope=dep/typescript-reader-sdk shape=package value=sha256:21e030acdc0d825e183b30f94d400daf351b02f782d474635f246de9e6e12b83 bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest needs=topos-typescript-tree/node_modules/typescript role=reads scope=dep/typescript-reader-compiler value=sha256:9dc6ee1f8dec9598cbecff5e2fcf2b916d04294c0615588dd424448a5a3afce5 bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest role=writes scope=dep/topos-doc shape=dist/index.js value=sha256:1b9fa141c118669a69ffee76d049b23c6bf68eb07f524aa7b89dd873bcde68eb -bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest role=writes scope=dep/topos-github shape=dist/index.js value=sha256:0a0ce9bac2dd52a5620691a26960f69ac013642bfd9a51a374ab998f7d780a7a bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest role=writes scope=dep/topos-node shape=dist/index.js value=sha256:859ee30f9eaed96edfdfd8d72834a18ebb82022d9c7ceea52e66409241f2cfb6 bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest role=writes scope=uses/topos-doc value=sha256:65bfa43e2d5122db2d516afe516921d52fc22647fb092d55e313c25c5a2d9b52 -bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest role=writes scope=uses/topos-github value=sha256:af59e6e41b8da160bf746ba4319a6bf138491c7f409c7f187f747ae7c247b7f1 bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=digest role=writes scope=uses/topos-node value=sha256:c7cfad66c15e3fb1d2cd71de9eabf70898723ea45f402987c7b8136729bfabd4 bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=id needs=.github/workflows/tag.yml role=demands scope=view/pipeline-tag shape=.github/workflows/tag.yml value=github-actions@1 bound-lock/1 at=witness:verified-render-contract by=target form=alphabet measure=id needs=.github/workflows/test.yml role=demands scope=view/pipeline-test shape=.github/workflows/test.yml value=github-actions@1 diff --git a/receipts.bound b/receipts.bound index a74e15a..a859cc0 100644 --- a/receipts.bound +++ b/receipts.bound @@ -3,10 +3,10 @@ bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68 bound-lock/1 at=place:sha256:02128973d344f0653782ddec43c9e00a31372ad8885571313f0d921886f9c812 by=reader:17a29ca33b8e form=alphabet measure=observed role=writes scope=src/regions/publish-auth-is-trusted.ts value=02128973d344f065 bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=alphabet measure=observed role=writes scope=src/index.ts value=5021befb9f5f522c bound-lock/1 at=place:sha256:6ad7ac4bc48040733a0993ba1f1c3bc1f586c5d3a99fcb63886952b40442415f by=reader:1b9fa141c118 form=alphabet measure=observed role=writes scope=./ value=6ad7ac4bc4804073 -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=observed role=writes scope=src/helpers/pipeline.ts value=757f8311759ec9f0 -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=observed role=writes scope=src/helpers/place.ts value=94dfc7ee99fe983f bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=observed role=writes scope=src/regions/github-actions.ts value=c13bb734622636fb -bound-lock/1 at=place:sha256:ea0f87db80e5848db75282af9c1543dcb2ccfc8dc0ce2ab47af2027875f63972 by=reader:0a0ce9bac2dd form=alphabet measure=observed role=writes scope=./ value=ea0f87db80e5848d +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=observed role=writes scope=src/helpers/place.ts value=d86f337d96182a85 +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=observed role=writes scope=src/helpers/pipeline.ts value=db189fd22e16e7f4 +bound-lock/1 at=place:sha256:ea0f87db80e5848db75282af9c1543dcb2ccfc8dc0ce2ab47af2027875f63972 by=reader:36e1f6822242 form=alphabet measure=observed role=writes scope=./ value=ea0f87db80e5848d bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/calls value=listed bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/carries value=Asked bound-lock/1 at=place:sha256:00246d80dca2046e388d29eed90a71f97e0175f7f8b41fc4a68d2f767151134e by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/declares value=render @@ -85,60 +85,6 @@ bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901a bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/unread value=0..0 bound-lock/1 at=place:sha256:5021befb9f5f522c55c1f3e941d84481416862f9ded965e901aec1f4fbc54460 by=reader:17a29ca33b8e form=interval measure=longest role=reads scope=source/longest value=4..4 bound-lock/1 at=place:sha256:6ad7ac4bc48040733a0993ba1f1c3bc1f586c5d3a99fcb63886952b40442415f by=reader:1b9fa141c118 form=interval measure=unreceipted role=reads scope=door/unreceipted value=0..0 -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/calls value=fields|file|steps|value -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/declares value=said|workflow -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/heads value=audit|pipeline|wire -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/capsule value=value -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/wire value=fields|steps -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/lang value=ts -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/specifiers value=@lapxo/topos/capsule|@lapxo/topos/wire -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=named role=reads scope=source/range/said value=207..267 -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=named role=reads scope=source/range/workflow value=422..486 -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/head value=" A key of the place's pipeline: its own line, else the default the wire gives every world. " -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/signature/said value="said(asked: Asked, key: string): string" -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/signature/workflow value="workflow(shape: string): string" -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/value value='wire/pipeline/world'|'audit/wire/pipeline/world' -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/customised value=0..0 -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/dynamic value=0..0 -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/form-splits value=0..0 -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lexed value=0..0 -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lines value=11..11 -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/numbers value=0..0 -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/parsed value=0..0 -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/spans value=0..0 -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/text value=0..0 -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/unread value=0..0 -bound-lock/1 at=place:sha256:757f8311759ec9f08e6fd3768230b39b103b3a7eb1945e838010c917273d789f by=reader:17a29ca33b8e form=interval measure=longest role=reads scope=source/longest value=5..5 -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/calls value=Error|allow|alphabet|asked|asset|assets|auth|check|checkout|job|missing|nodes|of|one|quote|requireInputs|required|run|said|secretly|setup|value|withs -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/compared value=present -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/declares value=render|requireInputs -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/heads value=audit|branch|check|environment|fold|install|name|node|pack|pipeline|present|publish|published|release|scope|tag|test|two-heads|value|verify|version|wire -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/./pipeline.ts value=said -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/capsule value=of -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/wire value=alphabet -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/lang value=ts -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/specifiers value=@lapxo/topos/capsule|@lapxo/topos/wire|./pipeline.ts -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/words value=branch|check|environment|install|name|node|pack|present|publish|published|release|scope|tag|test|value|version -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=named role=reads scope=source/range/render value=1090..1152 -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/head value=" The handed workflow profile names its inputs before anything is rendered. " -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/signature/render value="render(asked: Asked, named: string): readonly string[]" -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/checkout value="'fetch-depth: 2'" -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/job value="['contents: read']|['contents: read']|['contents: write']|['contents: write']|['contents: read', ...(secret ? [] : ['id-token: write'])]" -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/of value='scope'|'value' -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/replace value="\"'\\\"'\\\"'\"" -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/said value='node'|'publish/auth'|'check'|'install'|'publish/command'|'fold/command'|'verify/command'|'fold/command'|'verify/key'|'verify/command'|'release/assets'|'release/digest-command'|'release/digest-command'|'branch'|'pack'|'pack'|'branch'|'version'|'version'|'pack'|'release/digest-command'|'release/notes'|'release/digest-command'|'version'|'release/digest-command'|'publish/once'|'published'|'name'|'version'|'publish/command'|'environment' -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/secretly value="[`version=\"v$(${said(asked, 'version')})\"`, 'git tag --list \"$version\" / grep -q . && exit 0', 'git tag \"$version\" && git push origin \"$version\"']" -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/customised value=0..0 -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/dynamic value=0..0 -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/form-splits value=0..0 -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lexed value=0..0 -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lines value=67..67 -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/numbers value=0..0 -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/parsed value=2..2 -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/spans value=0..0 -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/text value=0..0 -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/unread value=1..1 -bound-lock/1 at=place:sha256:94dfc7ee99fe983fc7deef4093f33aa56c0d607084f87e11120f1b31bcd4f98c by=reader:17a29ca33b8e form=interval measure=longest role=reads scope=source/longest value=50..50 bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/calls value=Error|asked|place|workflow bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/carries value=Asked bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/compared value=audit/wire/pipeline/world|capsule/key|wire/pipeline/world @@ -164,22 +110,79 @@ bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b98 bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/text value=0..0 bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/unread value=0..0 bound-lock/1 at=place:sha256:c13bb734622636fbef7dfaebd19a07ef7a7866091edf6ca5b9874e41a39ab785 by=reader:17a29ca33b8e form=interval measure=longest role=reads scope=source/longest value=7..7 -bound-lock/1 at=place:sha256:ea0f87db80e5848db75282af9c1543dcb2ccfc8dc0ce2ab47af2027875f63972 by=reader:0a0ce9bac2dd form=interval measure=count role=reads scope=publish-auth-is-trusted/tokens value=0..0 +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/calls value=Error|allow|alphabet|asked|asset|assets|auth|check|checkout|job|missing|nodes|of|one|quote|requireInputs|required|run|said|secretly|setup|value|withs +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/compared value=present +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/declares value=render|requireInputs +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/heads value=audit|branch|check|environment|fold|install|name|node|pack|pipeline|present|publish|published|release|scope|tag|test|two-heads|value|verify|version|wire +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/./pipeline.ts value=said +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/capsule value=of +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/wire value=alphabet +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/lang value=ts +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/specifiers value=@lapxo/topos/capsule|@lapxo/topos/wire|./pipeline.ts +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/words value=branch|check|environment|install|name|node|pack|present|publish|published|release|scope|tag|test|value|version +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=named role=reads scope=source/range/render value=1090..1152 +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/head value=" The handed workflow profile names its inputs before anything is rendered. " +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/signature/render value="render(asked: Asked, named: string): readonly string[]" +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/checkout value="'fetch-depth: 2'" +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/job value="['contents: read']|['contents: read']|['contents: write']|['contents: write']|['contents: read', ...(secret ? [] : ['id-token: write'])]" +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/of value='scope'|'value' +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/replace value="\"'\\\"'\\\"'\"" +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/said value='node'|'publish/auth'|'check'|'install'|'publish/command'|'fold/command'|'verify/command'|'fold/command'|'verify/key'|'verify/command'|'release/assets'|'release/digest-command'|'release/digest-command'|'branch'|'pack'|'pack'|'branch'|'version'|'version'|'release/prepare'|'release/prepare'|'pack'|'release/digest-command'|'release/notes'|'release/digest-command'|'version'|'release/digest-command'|'publish/once'|'published'|'name'|'version'|'publish/command'|'environment' +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/secretly value="[`version=\"v$(${said(asked, 'version')})\"`, 'git tag --list \"$version\" / grep -q . && exit 0', 'git tag \"$version\" && git push origin \"$version\"']" +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/customised value=0..0 +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/dynamic value=0..0 +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/form-splits value=0..0 +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lexed value=0..0 +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lines value=67..67 +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/numbers value=0..0 +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/parsed value=2..2 +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/spans value=0..0 +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/text value=0..0 +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/unread value=1..1 +bound-lock/1 at=place:sha256:d86f337d96182a85b0e1fe0fe55de163c9c70b9254f561397693c1f72c644970 by=reader:17a29ca33b8e form=interval measure=longest role=reads scope=source/longest value=50..50 +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/calls value=asked|fields|file|of|steps|value +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/compared value=text +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/declares value=said|workflow +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/heads value=about|audit|measure|pipeline|scope|text|wire +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/capsule value=of|value +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/imports/@lapxo/topos/wire value=fields|steps +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/lang value=ts +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/specifiers value=@lapxo/topos/capsule|@lapxo/topos/wire +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=id role=reads scope=source/words value=about|measure|scope|text +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=named role=reads scope=source/range/said value=211..271 +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=named role=reads scope=source/range/workflow value=602..666 +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/head value=" A key of the place's pipeline: its own line, else the default the wire gives every world. " +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/signature/said value="said(asked: Asked, key: string): string" +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/signature/workflow value="workflow(shape: string): string" +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/of value='scope'|'measure'|'about' +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=alphabet measure=text role=reads scope=source/typed/value value='wire/pipeline/world'|'audit/wire/pipeline/world' +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/customised value=0..0 +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/dynamic value=0..0 +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/form-splits value=0..0 +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lexed value=0..0 +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/lines value=15..15 +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/numbers value=0..0 +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/parsed value=0..0 +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/spans value=0..0 +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/text value=0..0 +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=interval measure=count role=reads scope=source/unread value=0..0 +bound-lock/1 at=place:sha256:db189fd22e16e7f49d677b758f50b05ec3f09f3cbc5e4eddacaab42aeed90775 by=reader:17a29ca33b8e form=interval measure=longest role=reads scope=source/longest value=5..5 +bound-lock/1 at=place:sha256:ea0f87db80e5848db75282af9c1543dcb2ccfc8dc0ce2ab47af2027875f63972 by=reader:36e1f6822242 form=interval measure=count role=reads scope=publish-auth-is-trusted/tokens value=0..0 bound-lock/1 at=place:sha256:6133be7754b662e0979dd77c56f0e9e5784346388e9a442ee2cfb5bfc43e470b by=bound form=alphabet measure=digest role=writes scope=instrument/implementation value=sha256:6133be7754b662e0979dd77c56f0e9e5784346388e9a442ee2cfb5bfc43e470b -bound-lock/1 at=place:sha256:53648217483215503da753bd952dc913d3ad5f26c381b2422b4eb8e4d61b1072 by=bound form=alphabet measure=digest role=writes scope=receipts value=sha256:4c2a7f824191b26563770df50df2048488118a65022d83a9ee0581f0ad2e7a12 +bound-lock/1 at=place:sha256:50103ef5ee25e89663ecf6511b017dc02199eca16674e93fe4c0ed8df3e9b824 by=bound form=alphabet measure=digest role=writes scope=receipts value=sha256:e36e4d0bb4517d39b42b6896b0d896f378b4ee374e2383535be2af6232ba5197 bound-lock/1 at=place:sha256:5c082fef1ce762fa94247263374999862cb5dbacb123320ac771ce079ef38a1d by=bound form=interval measure=count role=writes scope=receipts/. value=2..2 -bound-lock/1 at=place:sha256:85f68938e18e3edb16187df5fa513c14d068d0e0cd1c8351a82ae3816e37a7f4 by=bound form=alphabet measure=bytes role=writes scope=receipts/. value=sha256:85f68938e18e3edb16187df5fa513c14d068d0e0cd1c8351a82ae3816e37a7f4 +bound-lock/1 at=place:sha256:b4fb7dffa778d1e05dc0eab4849c81c48f50f2c4629a993ba942fd0782f6570a by=bound form=alphabet measure=bytes role=writes scope=receipts/. value=sha256:b4fb7dffa778d1e05dc0eab4849c81c48f50f2c4629a993ba942fd0782f6570a bound-lock/1 at=place:sha256:45577827f043137dfe5cddff39aa4cf6bb61cc4361b6593e58fd119e92de7bfb by=bound form=interval measure=count role=writes scope=receipts/door value=1..1 -bound-lock/1 at=place:sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 by=bound form=alphabet measure=bytes role=writes scope=receipts/door value=sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 +bound-lock/1 at=place:sha256:1c5148ac69f804602c0312f3809755dbad2ad5d77e4c4f5f5faa8910a8b6c077 by=bound form=alphabet measure=bytes role=writes scope=receipts/door value=sha256:1c5148ac69f804602c0312f3809755dbad2ad5d77e4c4f5f5faa8910a8b6c077 bound-lock/1 at=place:sha256:496d2b3650b6dc875b9d8b36aadc110348d644b227f18e1a7fcb12c1df1c6267 by=bound form=interval measure=count role=writes scope=receipts/instrument value=1..1 -bound-lock/1 at=place:sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 by=bound form=alphabet measure=bytes role=writes scope=receipts/instrument value=sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 +bound-lock/1 at=place:sha256:1c5148ac69f804602c0312f3809755dbad2ad5d77e4c4f5f5faa8910a8b6c077 by=bound form=alphabet measure=bytes role=writes scope=receipts/instrument value=sha256:1c5148ac69f804602c0312f3809755dbad2ad5d77e4c4f5f5faa8910a8b6c077 bound-lock/1 at=place:sha256:d89c6fb88ef9356228dfe25d617aff88d5068e1af355034fae6baaae339e7a43 by=bound form=interval measure=count role=writes scope=receipts/publish-auth-is-trusted value=1..1 -bound-lock/1 at=place:sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 by=bound form=alphabet measure=bytes role=writes scope=receipts/publish-auth-is-trusted value=sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 -bound-lock/1 at=place:sha256:bfec36684511f3f5d6b0f961b9f146ecb57001dcd59b54c2efe3563e38030fef by=bound form=interval measure=count role=writes scope=receipts/source value=156..156 -bound-lock/1 at=place:sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 by=bound form=alphabet measure=bytes role=writes scope=receipts/source value=sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 -bound-lock/1 at=place:sha256:c95fe937618b93959f722f625d115af7a216ef24249126389a772f339e79748c by=bound form=interval measure=count role=writes scope=receipts/src value=6..6 -bound-lock/1 at=place:sha256:03afa13b3b3eac6d79d7907eb97a382bce4013a29055a0ad03d4634e03b5fd0b by=bound form=alphabet measure=bytes role=writes scope=receipts/src value=sha256:03afa13b3b3eac6d79d7907eb97a382bce4013a29055a0ad03d4634e03b5fd0b +bound-lock/1 at=place:sha256:1c5148ac69f804602c0312f3809755dbad2ad5d77e4c4f5f5faa8910a8b6c077 by=bound form=alphabet measure=bytes role=writes scope=receipts/publish-auth-is-trusted value=sha256:1c5148ac69f804602c0312f3809755dbad2ad5d77e4c4f5f5faa8910a8b6c077 +bound-lock/1 at=place:sha256:c70b90155fb07805bfd601be08f77660778bc502a47ae6131f4789f492dc01c8 by=bound form=interval measure=count role=writes scope=receipts/source value=159..159 +bound-lock/1 at=place:sha256:1c5148ac69f804602c0312f3809755dbad2ad5d77e4c4f5f5faa8910a8b6c077 by=bound form=alphabet measure=bytes role=writes scope=receipts/source value=sha256:1c5148ac69f804602c0312f3809755dbad2ad5d77e4c4f5f5faa8910a8b6c077 +bound-lock/1 at=place:sha256:e94bdbd6f2774854cf4d1e2f0ef8aec50cc44ded91553114e7d524dd3b9d0c9f by=bound form=interval measure=count role=writes scope=receipts/src value=6..6 +bound-lock/1 at=place:sha256:217423633069bad5ef7905536c1f897ce994f1cfad5b9c3a041b39106592b251 by=bound form=alphabet measure=bytes role=writes scope=receipts/src value=sha256:217423633069bad5ef7905536c1f897ce994f1cfad5b9c3a041b39106592b251 bound-lock/1 at=place:sha256:1f8e612d12ae11253468b76be25ce5e71c43ab7c4e4811cef55c8cff57fcae2f by=bound form=interval measure=count role=writes scope=receipts/write value=1..1 -bound-lock/1 at=place:sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 by=bound form=alphabet measure=bytes role=writes scope=receipts/write value=sha256:bea40e3b4435bfd29e7af62de3e7b6be7de3f95dd074b8469690dc7b9b701af6 +bound-lock/1 at=place:sha256:1c5148ac69f804602c0312f3809755dbad2ad5d77e4c4f5f5faa8910a8b6c077 by=bound form=alphabet measure=bytes role=writes scope=receipts/write value=sha256:1c5148ac69f804602c0312f3809755dbad2ad5d77e4c4f5f5faa8910a8b6c077 diff --git a/src/helpers/pipeline.ts b/src/helpers/pipeline.ts index 3c051d9..b7030e4 100644 --- a/src/helpers/pipeline.ts +++ b/src/helpers/pipeline.ts @@ -1,8 +1,12 @@ -import { value, type Asked } from '@lapxo/topos/capsule'; +import { of, value, type Asked } from '@lapxo/topos/capsule'; import { fields, steps } from '@lapxo/topos/wire'; /** A key of the place's pipeline: its own line, else the default the wire gives every world. */ -export const said = (asked: Asked, key: string): string => value(asked, `pipeline/${key}`) ?? new Map(fields(value(asked, 'wire/pipeline/world') ?? value(asked, 'audit/wire/pipeline/world') ?? '')).get(key) ?? ''; +export const said = (asked: Asked, key: string): string => { + const line = asked.lines.find(line => of(line, 'scope') === `pipeline/${key}`); + const own = line && of(line, 'measure') === 'text' ? of(line, 'about') : value(asked, `pipeline/${key}`); + return own ?? new Map(fields(value(asked, 'wire/pipeline/world') ?? value(asked, 'audit/wire/pipeline/world') ?? '')).get(key) ?? ''; +}; export const workflow = (shape: string): string => { const file = steps(shape).at(-1) ?? ''; diff --git a/src/helpers/place.ts b/src/helpers/place.ts index 404c913..adebc94 100644 --- a/src/helpers/place.ts +++ b/src/helpers/place.ts @@ -55,7 +55,7 @@ export const render = (asked: Asked, named: string): readonly string[] => { [`version="v$(${said(asked, 'version')})"`, 'git tag --list "$version" | grep -q . && exit 0', 'git tag "$version" && git push origin "$version"'])])], release: ['name: release', 'on:', ' workflow_run:', ' workflows: [tag]', ' types: [completed]', ' push:', " tags: ['v*']", 'jobs:', ...job('release', ['contents: write'], [...checkout(at, 'fetch-depth: 2'), ...setup(last), ...install, ...runs, ' - id: artifact', ' env:', ' GH_TOKEN: ${{ github.token }}', ' run: |', - ` version="v$(${said(asked, 'version')})"`, ` asset="$(${said(asked, 'pack')})"`, ' test -f "$asset"', ` expected="$(${said(asked, 'release/digest-command')} "$asset")"`, ' if ! gh release view "$version" >/dev/null 2>&1; then', ` gh release create "$version" "$asset"${assets.map(one => ` ${quote(one)}`).join('')} --title "$version" --notes "${said(asked, 'release/notes') || '$version'}"`, ' fi', ' gh release download "$version" --pattern "$(basename "$asset")" --dir "$RUNNER_TEMP/release-back"', ` actual="$(${said(asked, 'release/digest-command')} "$RUNNER_TEMP/release-back/$(basename "$asset")")"`, ' test "${expected%% *}" = "${actual%% *}"', ...extraChecks, ...(auth ? [" printf 'artifact=%s\\n' \"$(basename \"$asset\")\" >> \"$GITHUB_OUTPUT\"", " printf 'digest=%s\\n' \"${expected%% *}\" >> \"$GITHUB_OUTPUT\""] : [])], + ` version="v$(${said(asked, 'version')})"`, ...(said(asked, 'release/prepare') ? said(asked, 'release/prepare').split('\n').map(line => ` ${line}`) : []), ` asset="$(${said(asked, 'pack')})"`, ' test -f "$asset"', ` expected="$(${said(asked, 'release/digest-command')} "$asset")"`, ' if ! gh release view "$version" >/dev/null 2>&1; then', ` gh release create "$version" "$asset"${assets.map(one => ` ${quote(one)}`).join('')} --title "$version" --notes "${said(asked, 'release/notes') || '$version'}"`, ' fi', ' gh release download "$version" --pattern "$(basename "$asset")" --dir "$RUNNER_TEMP/release-back"', ` actual="$(${said(asked, 'release/digest-command')} "$RUNNER_TEMP/release-back/$(basename "$asset")")"`, ' test "${expected%% *}" = "${actual%% *}"', ...extraChecks, ...(auth ? [" printf 'artifact=%s\\n' \"$(basename \"$asset\")\" >> \"$GITHUB_OUTPUT\"", " printf 'digest=%s\\n' \"${expected%% *}\" >> \"$GITHUB_OUTPUT\""] : [])], [" if: github.event_name == 'push' || github.event.workflow_run.conclusion == 'success'", ...(auth ? [' outputs:', ' artifact: ${{ steps.artifact.outputs.artifact }}', ' digest: ${{ steps.artifact.outputs.digest }}'] : [])]), ...(auth ? job('publish', ['contents: read', ...(secret ? [] : ['id-token: write'])], [...checkout(at), ...setup(last), ...tools, ' - env:', ' GH_TOKEN: ${{ github.token }}', ' RELEASE_ARTIFACT: ${{ needs.release.outputs.artifact }}', ' RELEASE_DIGEST: ${{ needs.release.outputs.digest }}', ' run: |', ` version="v$(${said(asked, 'version')})"`, ' test -n "$RELEASE_ARTIFACT"', ' test -n "$RELEASE_DIGEST"', ' gh release download "$version" --pattern "$RELEASE_ARTIFACT" --dir "$RUNNER_TEMP/publish"', ' asset="$RUNNER_TEMP/publish/$RELEASE_ARTIFACT"', ` actual="$(${said(asked, 'release/digest-command')} "$asset")"`, ' test "${actual%% *}" = "$RELEASE_DIGEST"', " printf 'RELEASE_ASSET=%s\\n' \"$asset\" >> \"$GITHUB_ENV\"", ...secretly(secret, [ ...(said(asked, 'publish/once') === 'present' ? [`${said(asked, 'published')} "$(${said(asked, 'name')})@$(${said(asked, 'version')})" version >/dev/null 2>&1 && exit 0`] : []), `asset="$RELEASE_ASSET"`, said(asked, 'publish/command')])], diff --git a/test/workflow-contract.test.ts b/test/workflow-contract.test.ts index 7888044..e1f029f 100644 --- a/test/workflow-contract.test.ts +++ b/test/workflow-contract.test.ts @@ -111,3 +111,13 @@ for (const place of ['library', 'service']) test(`every declared release asset i test('release assets with identical filenames refuse before rendering', () => { assert.throws(() => render(asked({ ...base, 'release/assets': 'first/standing|second/standing' }), 'release'), /REFUSE.*share a filename/); }); + +for (const place of ['library', 'service']) test(`release preparation precedes packing and stays out of test/tag: ${place}`, () => { + const seed=asked({...base,branch:place}); + const input={...seed,lines:[...seed.lines,{scope:'pipeline/release/prepare',role:'writes',form:'alphabet',measure:'text',value:'lock',about:'verify-inputs\nrebuild-assets'}]}; + const release=render(input,'release').join('\n'); + assert.ok(release.indexOf('verify-inputs') < release.indexOf('rebuild-assets')); + assert.ok(release.indexOf('rebuild-assets') < release.indexOf('asset="$(pack-place)"')); + assert.ok(!render(input,'test').join('\n').includes('verify-inputs')); + assert.ok(!render(input,'tag').join('\n').includes('rebuild-assets')); +});