#!/usr/bin/env bash # Reproducible schema-v3-only release gate. The Git checkout is the trust root; # dependencies come from backend/package-lock.json and dist comes from a clean build. set -euo pipefail export PYTHONDONTWRITEBYTECODE=1 export NPM_CONFIG_USERCONFIG=/dev/null export NPM_CONFIG_GLOBALCONFIG=/dev/null root="$(cd "$(dirname "$0")/.." && pwd -P)" if [[ ${1:-} == --dry-run ]]; then cat <<'EOF' export PYTHONDONTWRITEBYTECODE=1 export NPM_CONFIG_USERCONFIG=/dev/null export NPM_CONFIG_GLOBALCONFIG=/dev/null /bin/bash scripts/verify-schema-v3-only.sh --bootstrap-trust-only (cd backend && npm ci --ignore-scripts) (cd backend && npm run build) (cd backend && npm run test:schema-v3-verifier) /bin/bash scripts/test-verify-schema-v3-only.sh /bin/bash scripts/verify-schema-v3-only.sh EOF exit 0 fi [[ $# -eq 0 ]] || { echo "usage: $0 [--dry-run]" >&2; exit 2; } /bin/bash "$root/scripts/verify-schema-v3-only.sh" --bootstrap-trust-only (cd "$root/backend" && npm ci --ignore-scripts) (cd "$root/backend" && npm run build) (cd "$root/backend" && npm run test:schema-v3-verifier) /bin/bash "$root/scripts/test-verify-schema-v3-only.sh" /bin/bash "$root/scripts/verify-schema-v3-only.sh"