Skip to content

Commit 4471daf

Browse files
chore(license): name the build precondition when package license copies are absent
The release audit inspects build output and deliberately does not regenerate the package-local LICENSE/NOTICE copies; a clean checkout now fails with a message that points at `pnpm build` instead of a bare missing-file error.
1 parent 9285361 commit 4471daf

1 file changed

Lines changed: 12 additions & 7 deletions

File tree

‎scripts/audit-packed-release.mjs‎

Lines changed: 12 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -151,8 +151,11 @@ const validateSbom = (sbom, productManifest, installedPackages) => {
151151

152152
/**
153153
* Every publishable tarball must declare the project license and carry the
154-
* root LICENSE and NOTICE byte-for-byte; npm's implicit inclusion is not
155-
* trusted because the package copies are build outputs that may be stale.
154+
* root LICENSE and NOTICE byte-for-byte. Like the rest of this audit (attw and
155+
* the SBOM install both pack `dist`), it inspects build output and never
156+
* regenerates it: the package copies are written by each package's `build`
157+
* (scripts/sync-license-files.mjs), and syncing here would hide a build step
158+
* that stopped producing them.
156159
*/
157160
const validateLicenseFiles = async (packOutput, packageDirectory) => {
158161
const manifest = JSON.parse(await readFile(join(repositoryRoot, packageDirectory, 'package.json'), 'utf8'));
@@ -162,12 +165,14 @@ const validateLicenseFiles = async (packOutput, packageDirectory) => {
162165
if (!Array.isArray(packOutput.files)) fail(`${packageDirectory} npm pack did not list tarball files`);
163166
const packedPaths = new Set(packOutput.files.map((file) => asRecord(file, 'pack file must be an object').path));
164167
for (const file of licenseFiles) {
168+
const actual = await readFile(join(repositoryRoot, packageDirectory, file), 'utf8').catch(() => undefined);
169+
if (actual === undefined) {
170+
fail(`${packageDirectory}/${file} is missing; this audit inspects build output, so run \`pnpm build\` (which runs scripts/sync-license-files.mjs) first`);
171+
}
165172
if (!packedPaths.has(file)) fail(`${packageDirectory} tarball is missing ${file}`);
166-
const [expected, actual] = await Promise.all([
167-
readFile(join(repositoryRoot, file), 'utf8'),
168-
readFile(join(repositoryRoot, packageDirectory, file), 'utf8').catch(() => fail(`${packageDirectory}/${file} is not readable`)),
169-
]);
170-
if (expected !== actual) fail(`${packageDirectory}/${file} differs from the repository root ${file}`);
173+
if (actual !== await readFile(join(repositoryRoot, file), 'utf8')) {
174+
fail(`${packageDirectory}/${file} differs from the repository root ${file}`);
175+
}
171176
}
172177
};
173178

0 commit comments

Comments
 (0)