refactor: derive the release identity from the package name
The supply-chain builder id and the two verifier ids each hardcoded the
repository name, in three source files plus a copy in the test fixture.
A project derived from this template had to edit all four, and all four
then became permanent conflict points for every merge back from here.
They now read the `name` this repository already declares in
package.json, so deriving a project is one line. The name is read once
at module load from a URL relative to the module itself, not from the
working directory, because these ids end up in signed provenance and
must not depend on where a script was invoked from. A missing or empty
name throws rather than falling back, for the same reason.
The value is hosted in scripts/lib/supply-chain.ts because all three
consumers already import it and it is already registered in
LOCAL_EVIDENCE_VERIFIER_SOURCE_PATHS. A new module would have needed to
join that list, which is itself part of the evidence surface.
This repository's own name is unchanged, so every emitted id is
byte-identical to before.
Also registers the three adapter files that 5cc4146 added without
updating the inventory ledger, which had left check:adapter-inventory
failing on develop.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
8dd7cbaea3
commit
ebea300e4f
@@ -21,6 +21,7 @@ import {
|
||||
flattenPnpmDependencyTree,
|
||||
isValidSha512Integrity,
|
||||
parsePnpmLockfilePackages,
|
||||
PROJECT_NAME,
|
||||
supplyChainDigest,
|
||||
verifySupplyChainCoherence,
|
||||
} from "./lib/supply-chain.ts";
|
||||
@@ -270,7 +271,7 @@ const provenance = {
|
||||
],
|
||||
},
|
||||
runDetails: {
|
||||
builder: { id: "local:clean-architecture-frontend-template" },
|
||||
builder: { id: `local:${PROJECT_NAME}` },
|
||||
metadata: { invocationId: "LOCAL_UNSIGNED" },
|
||||
},
|
||||
materials: {
|
||||
|
||||
Reference in New Issue
Block a user