#!/usr/bin/env bash # Reproducible schema-v4-only release gate. The Git checkout is the trust root; # dependencies come from backend/package-lock.json and dist comes from a clean build. set -euo pipefail export PYTHONDONTWRITEBYTECODE=1 root="$(cd "$(dirname "$0")/.." && pwd -P)" if [[ ${1:-} == --dry-run ]]; then cat <<'EOF' export PYTHONDONTWRITEBYTECODE=1 export NPM_CONFIG_USERCONFIG= export NPM_CONFIG_GLOBALCONFIG= /bin/bash scripts/verify-schema-v3-only.sh --bootstrap-trust-only (cd backend && npm ci --ignore-scripts) (cd backend && npm run build) (cd backend && npm run test:schema-v4-verifier) /bin/bash scripts/test-verify-schema-v3-only.sh /bin/bash scripts/verify-schema-v3-only.sh EOF exit 0 fi [[ $# -eq 0 ]] || { echo "usage: $0 [--dry-run]" >&2; exit 2; } release_tmp="$(mktemp -d "${TMPDIR:-/tmp}/thoth-v3-release.XXXXXX")" trap 'rm -rf "$release_tmp"' EXIT HUP INT TERM : >"$release_tmp/npm-userconfig" : >"$release_tmp/npm-globalconfig" chmod 0600 "$release_tmp/npm-userconfig" "$release_tmp/npm-globalconfig" export NPM_CONFIG_USERCONFIG="$release_tmp/npm-userconfig" export NPM_CONFIG_GLOBALCONFIG="$release_tmp/npm-globalconfig" /bin/bash "$root/scripts/verify-schema-v3-only.sh" --bootstrap-trust-only (cd "$root/backend" && npm ci --ignore-scripts) (cd "$root/backend" && npm run build) (cd "$root/backend" && npm run test:schema-v4-verifier) /bin/bash "$root/scripts/test-verify-schema-v3-only.sh" /bin/bash "$root/scripts/verify-schema-v3-only.sh"