Files
decePubClient/tools/tailwind.sh
T
thepraandClaude Opus 5.5 a097338121 Vendor Tailwind and daisyUI in the repo; never reach github.com
Builds used to download the Tailwind binary and the daisyUI plugins from GitHub
releases. They are now committed in tools/tailwind/:
- the Tailwind 4.3.3 standalone binary for linux-x64, xz -9e compressed (28 MB);
- daisyui.mjs and daisyui-theme.mjs 5.7.47;
- daisyUI's llms.txt component reference;
- Tailwind's MIT license.

tools/tailwind.sh no longer touches the network. "prepare" checks every file
against its pinned sha256 and unpacks the binary into .tools/. MSBuild reruns it
only when the archive or the script changes. A build from scratch was checked
inside a network namespace with no network at all.

.gitattributes keeps the vendored files byte-exact, and Tailwind no longer scans
tools/, whose llms.txt names every daisyUI class.

Both workflows used actions/checkout, which a Gitea runner downloads from
github.com. They now git fetch the commit from this Gitea, as they already did
for SocialPub.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
2026-10-03 12:43:07 +02:00

81 lines
3.5 KiB
Bash
Executable File

#!/usr/bin/env bash
# Tailwind CSS standalone + daisyUI, vendored in tools/tailwind/ so building never touches the network.
# MSBuild runs `prepare` (EnsureTailwindTools in decePubClient.csproj) and then compiles Styles/app.css itself.
# bash tools/tailwind.sh prepare verify the vendored files and unpack the binary into .tools/tailwind/
# bash tools/tailwind.sh build one-off build of wwwroot/css/app.css (what MSBuild does in Debug)
# bash tools/tailwind.sh watch rebuild wwwroot/css/app.css on every change, beside `dotnet watch`
#
# tools/tailwind/ holds:
# tailwindcss-linux-x64.xz the Tailwind CSS v4.3.3 standalone binary, xz -9e compressed
# daisyui.mjs, daisyui-theme.mjs the daisyUI v5.7.47 plugins (Styles/app.css and Styles/theme.css load them)
# daisyui-llms.txt daisyUI's component reference for v5.7.x, read when writing Components/Daisy
#
# To upgrade, take the new release assets (tailwindcss-linux-x64 from Tailwind's release, daisyui.mjs and
# daisyui-theme.mjs from daisyUI's), check them against the checksums the projects publish, replace the files here
# (`xz -9e -c tailwindcss-linux-x64 > tools/tailwind/tailwindcss-linux-x64.xz`), and update the versions and every
# sha256 below. Only linux-x64 is vendored; another platform needs its binary added the same way.
set -euo pipefail
TAILWIND_VERSION=4.3.3
pinned_sha256() {
case "$1" in
tailwindcss-linux-x64) echo dc61b3ac6b8c9ca874c0cc4c57b2409791a64c5540404ca5f5367360babc313a ;;
tailwindcss-linux-x64.xz) echo 8ad24bb6ac4f615fa9a1abdf4b49143690eaa5531a62a49e89f4eab0c91ad02b ;;
daisyui.mjs) echo 85819d3fe86a852237b439b13f481481aac58e562ac47694cd11c3038e994f2a ;;
daisyui-theme.mjs) echo d92d2f488933dab757f046e81ebd4986e51e9423307798dc3545d09a15542c89 ;;
*) echo "tailwind.sh: no pinned checksum for $1" >&2; exit 1 ;;
esac
}
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
VENDOR="$ROOT/tools/tailwind"
TOOLS="$ROOT/.tools/tailwind"
TAILWIND="$TOOLS/tailwindcss"
platform() {
case "$(uname -s)-$(uname -m)" in
Linux-x86_64|Linux-amd64) echo linux-x64 ;;
*) echo "tailwind.sh: only the linux-x64 Tailwind binary is vendored (this is $(uname -s)-$(uname -m))" >&2; exit 1 ;;
esac
}
sha256_of() {
if command -v sha256sum >/dev/null; then sha256sum "$1" | cut -d' ' -f1; else shasum -a 256 "$1" | cut -d' ' -f1; fi
}
# verify <file> <pinned name>
verify() {
local actual expected
actual="$(sha256_of "$1")"
expected="$(pinned_sha256 "$2")"
if [ "$actual" != "$expected" ]; then
echo "tailwind.sh: checksum mismatch for $1 (expected $expected, got $actual)" >&2
return 1
fi
}
prepare() {
local asset
asset="tailwindcss-$(platform)"
verify "$VENDOR/daisyui.mjs" daisyui.mjs
verify "$VENDOR/daisyui-theme.mjs" daisyui-theme.mjs
if [ -f "$TAILWIND" ] && verify "$TAILWIND" "$asset" 2>/dev/null; then return; fi
command -v xz >/dev/null || { echo "tailwind.sh: xz is needed to unpack $asset.xz" >&2; exit 1; }
verify "$VENDOR/$asset.xz" "$asset.xz"
echo "tailwind.sh: unpacking Tailwind CSS v$TAILWIND_VERSION ($asset) into .tools/tailwind/"
mkdir -p "$TOOLS"
xz -dc "$VENDOR/$asset.xz" > "$TAILWIND.part"
verify "$TAILWIND.part" "$asset" || { rm -f "$TAILWIND.part"; exit 1; }
chmod +x "$TAILWIND.part"
mv "$TAILWIND.part" "$TAILWIND"
}
cd "$ROOT"
case "${1:-build}" in
prepare) prepare ;;
build) prepare; "$TAILWIND" -i Styles/app.css -o wwwroot/css/app.css --optimize ;;
watch) prepare; exec "$TAILWIND" -i Styles/app.css -o wwwroot/css/app.css --watch ;;
*) echo "usage: tailwind.sh [prepare|build|watch]" >&2; exit 2 ;;
esac