Builds used to download the Tailwind binary and the daisyUI plugins from GitHub releases. They are now committed in tools/tailwind/: - the Tailwind 4.3.3 standalone binary for linux-x64, xz -9e compressed (28 MB); - daisyui.mjs and daisyui-theme.mjs 5.7.47; - daisyUI's llms.txt component reference; - Tailwind's MIT license. tools/tailwind.sh no longer touches the network. "prepare" checks every file against its pinned sha256 and unpacks the binary into .tools/. MSBuild reruns it only when the archive or the script changes. A build from scratch was checked inside a network namespace with no network at all. .gitattributes keeps the vendored files byte-exact, and Tailwind no longer scans tools/, whose llms.txt names every daisyUI class. Both workflows used actions/checkout, which a Gitea runner downloads from github.com. They now git fetch the commit from this Gitea, as they already did for SocialPub. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
81 lines
3.5 KiB
Bash
Executable File
81 lines
3.5 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Tailwind CSS standalone + daisyUI, vendored in tools/tailwind/ so building never touches the network.
|
|
# MSBuild runs `prepare` (EnsureTailwindTools in decePubClient.csproj) and then compiles Styles/app.css itself.
|
|
# bash tools/tailwind.sh prepare verify the vendored files and unpack the binary into .tools/tailwind/
|
|
# bash tools/tailwind.sh build one-off build of wwwroot/css/app.css (what MSBuild does in Debug)
|
|
# bash tools/tailwind.sh watch rebuild wwwroot/css/app.css on every change, beside `dotnet watch`
|
|
#
|
|
# tools/tailwind/ holds:
|
|
# tailwindcss-linux-x64.xz the Tailwind CSS v4.3.3 standalone binary, xz -9e compressed
|
|
# daisyui.mjs, daisyui-theme.mjs the daisyUI v5.7.47 plugins (Styles/app.css and Styles/theme.css load them)
|
|
# daisyui-llms.txt daisyUI's component reference for v5.7.x, read when writing Components/Daisy
|
|
#
|
|
# To upgrade, take the new release assets (tailwindcss-linux-x64 from Tailwind's release, daisyui.mjs and
|
|
# daisyui-theme.mjs from daisyUI's), check them against the checksums the projects publish, replace the files here
|
|
# (`xz -9e -c tailwindcss-linux-x64 > tools/tailwind/tailwindcss-linux-x64.xz`), and update the versions and every
|
|
# sha256 below. Only linux-x64 is vendored; another platform needs its binary added the same way.
|
|
set -euo pipefail
|
|
|
|
TAILWIND_VERSION=4.3.3
|
|
|
|
pinned_sha256() {
|
|
case "$1" in
|
|
tailwindcss-linux-x64) echo dc61b3ac6b8c9ca874c0cc4c57b2409791a64c5540404ca5f5367360babc313a ;;
|
|
tailwindcss-linux-x64.xz) echo 8ad24bb6ac4f615fa9a1abdf4b49143690eaa5531a62a49e89f4eab0c91ad02b ;;
|
|
daisyui.mjs) echo 85819d3fe86a852237b439b13f481481aac58e562ac47694cd11c3038e994f2a ;;
|
|
daisyui-theme.mjs) echo d92d2f488933dab757f046e81ebd4986e51e9423307798dc3545d09a15542c89 ;;
|
|
*) echo "tailwind.sh: no pinned checksum for $1" >&2; exit 1 ;;
|
|
esac
|
|
}
|
|
|
|
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
|
VENDOR="$ROOT/tools/tailwind"
|
|
TOOLS="$ROOT/.tools/tailwind"
|
|
TAILWIND="$TOOLS/tailwindcss"
|
|
|
|
platform() {
|
|
case "$(uname -s)-$(uname -m)" in
|
|
Linux-x86_64|Linux-amd64) echo linux-x64 ;;
|
|
*) echo "tailwind.sh: only the linux-x64 Tailwind binary is vendored (this is $(uname -s)-$(uname -m))" >&2; exit 1 ;;
|
|
esac
|
|
}
|
|
|
|
sha256_of() {
|
|
if command -v sha256sum >/dev/null; then sha256sum "$1" | cut -d' ' -f1; else shasum -a 256 "$1" | cut -d' ' -f1; fi
|
|
}
|
|
|
|
# verify <file> <pinned name>
|
|
verify() {
|
|
local actual expected
|
|
actual="$(sha256_of "$1")"
|
|
expected="$(pinned_sha256 "$2")"
|
|
if [ "$actual" != "$expected" ]; then
|
|
echo "tailwind.sh: checksum mismatch for $1 (expected $expected, got $actual)" >&2
|
|
return 1
|
|
fi
|
|
}
|
|
|
|
prepare() {
|
|
local asset
|
|
asset="tailwindcss-$(platform)"
|
|
verify "$VENDOR/daisyui.mjs" daisyui.mjs
|
|
verify "$VENDOR/daisyui-theme.mjs" daisyui-theme.mjs
|
|
if [ -f "$TAILWIND" ] && verify "$TAILWIND" "$asset" 2>/dev/null; then return; fi
|
|
command -v xz >/dev/null || { echo "tailwind.sh: xz is needed to unpack $asset.xz" >&2; exit 1; }
|
|
verify "$VENDOR/$asset.xz" "$asset.xz"
|
|
echo "tailwind.sh: unpacking Tailwind CSS v$TAILWIND_VERSION ($asset) into .tools/tailwind/"
|
|
mkdir -p "$TOOLS"
|
|
xz -dc "$VENDOR/$asset.xz" > "$TAILWIND.part"
|
|
verify "$TAILWIND.part" "$asset" || { rm -f "$TAILWIND.part"; exit 1; }
|
|
chmod +x "$TAILWIND.part"
|
|
mv "$TAILWIND.part" "$TAILWIND"
|
|
}
|
|
|
|
cd "$ROOT"
|
|
case "${1:-build}" in
|
|
prepare) prepare ;;
|
|
build) prepare; "$TAILWIND" -i Styles/app.css -o wwwroot/css/app.css --optimize ;;
|
|
watch) prepare; exec "$TAILWIND" -i Styles/app.css -o wwwroot/css/app.css --watch ;;
|
|
*) echo "usage: tailwind.sh [prepare|build|watch]" >&2; exit 2 ;;
|
|
esac
|