Vendor Tailwind and daisyUI in the repo; never reach github.com

Builds used to download the Tailwind binary and the daisyUI plugins from GitHub
releases. They are now committed in tools/tailwind/:
- the Tailwind 4.3.3 standalone binary for linux-x64, xz -9e compressed (28 MB);
- daisyui.mjs and daisyui-theme.mjs 5.7.47;
- daisyUI's llms.txt component reference;
- Tailwind's MIT license.

tools/tailwind.sh no longer touches the network. "prepare" checks every file
against its pinned sha256 and unpacks the binary into .tools/. MSBuild reruns it
only when the archive or the script changes. A build from scratch was checked
inside a network namespace with no network at all.

.gitattributes keeps the vendored files byte-exact, and Tailwind no longer scans
tools/, whose llms.txt names every daisyUI class.

Both workflows used actions/checkout, which a Gitea runner downloads from
github.com. They now git fetch the commit from this Gitea, as they already did
for SocialPub.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
thepraandClaude Opus 5.5 committed 2026-10-03 12:43:07 +02:00
1 parent e075c4040b
commit a097338121
12 files changed
+3667 -72

No files matched your search

+10 -3
View File
@@ -10,9 +10,16 @@ jobs:
name: Build
runs-on: build
steps:
- uses: actions/checkout@v4
with:
path: decePubClient
# A plain fetch from this Gitea rather than actions/checkout, which the runner would download from github.com.
- name: Check out this commit
env:
READ_TOKEN: ${{ secrets.THEPRA_READ_TOKEN }}
run: |
rm -rf decePubClient
git init -q decePubClient
git -C decePubClient -c http.extraHeader="Authorization: token $READ_TOKEN" fetch -q --depth 1 \
"$GITHUB_SERVER_URL/$GITHUB_REPOSITORY.git" "$GITHUB_SHA"
git -C decePubClient checkout -q FETCH_HEAD
- name: Fetch PrivaPub's client models beside it
env:
+10 -3
View File
@@ -16,9 +16,16 @@ jobs:
name: decepub.thepra.dev
runs-on: build
steps:
- uses: actions/checkout@v4
with:
path: decePubClient
# A plain fetch from this Gitea rather than actions/checkout, which the runner would download from github.com.
- name: Check out this commit
env:
READ_TOKEN: ${{ secrets.THEPRA_READ_TOKEN }}
run: |
rm -rf decePubClient
git init -q decePubClient
git -C decePubClient -c http.extraHeader="Authorization: token $READ_TOKEN" fetch -q --depth 1 \
"$GITHUB_SERVER_URL/$GITHUB_REPOSITORY.git" "$GITHUB_SHA"
git -C decePubClient checkout -q FETCH_HEAD
- name: Fetch PrivaPub's client models beside it
env: