Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .github/workflows/instant-sync.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,8 +15,14 @@
dispatch:
runs-on: ubuntu-latest
timeout-minutes: 15
# `secrets` is not available in step `if:`; job-level env is. Without the
# PAT the dispatch falls back to GITHUB_TOKEN and fails 401 cross-repo, so
# skip cleanly where FARM_DISPATCH_TOKEN has not been propagated.
env:
FARM_DISPATCH_TOKEN: ${{ secrets.FARM_DISPATCH_TOKEN }}

Check warning on line 22 in .github/workflows/instant-sync.yml

View workflow job for this annotation

GitHub Actions / Hypatia neurosymbolic scan

[hypatia] job in .github/workflows/instant-sync.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
steps:
- name: Trigger Propagation
if: ${{ env.FARM_DISPATCH_TOKEN != '' }}
uses: peter-evans/repository-dispatch@v4.0.1
with:
token: ${{ secrets.FARM_DISPATCH_TOKEN }}
Expand All @@ -30,6 +36,7 @@
"forges": ""
}
- name: Confirm
if: ${{ env.FARM_DISPATCH_TOKEN != '' }}
env:
REPO_NAME: ${{ github.event.repository.name }}
run: echo "::notice::Propagation triggered for ${REPO_NAME}"
84 changes: 77 additions & 7 deletions build/setup.sh
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,7 @@
# Then hands off to `just setup` for project-specific configuration.
#
# Usage:
# curl -fsSL https://raw.githubusercontent.com/hyperpolymath/rsr-template-repo/main/setup.sh | sh
# # or after cloning:
# ./setup.sh
# ./build/setup.sh # after cloning — read it first; never pipe a fetched script into a shell
#
# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath)

Expand Down Expand Up @@ -127,7 +125,79 @@
esac
}

# ── Verified just install ──
# Replaces `curl https://just.systems/install.sh | bash`: piping a remote script
# into a shell runs whatever the server returns, with no chance to check it.
# A pinned RELEASE BINARY is fetched instead and its digest checked before use
# (ported from hyperpolymath/standards setup.sh, 3079bc12). Digests computed
# 2026-08-07; casey/just publishes none, so this is trust-on-first-use — any
# later substitution fails loudly. An unrecognised platform returns failure
# rather than fetching a plausible-looking binary for the wrong target.
JUST_VERSION="1.58.0"

# Print the release target for the current Linux or macOS architecture.
# Unrecognised platforms print an empty line with a successful exit status.
just_target() {
case "$(uname -s 2>/dev/null):$(uname -m 2>/dev/null)" in
Linux:x86_64|Linux:amd64) echo "x86_64-unknown-linux-musl" ;;
Linux:aarch64|Linux:arm64) echo "aarch64-unknown-linux-musl" ;;
Darwin:x86_64) echo "x86_64-apple-darwin" ;;
Darwin:arm64|Darwin:aarch64) echo "aarch64-apple-darwin" ;;
*) echo "" ;;
esac
}

# Print the pinned release archive SHA-256 for the target in $1.
# Unrecognised targets print an empty line with a successful exit status.
just_sha256() {
case "$1" in
x86_64-unknown-linux-musl) echo "4a5cc2f53e6f0f8c59092a6cc38291eb729d46a7dd95d3ae582008881b84931d" ;;
aarch64-unknown-linux-musl) echo "748237128c4c40cbdabc65e841d05ceba13cc23a91eaba395495894c1d9764df" ;;
x86_64-apple-darwin) echo "9a09cfef66aaa79da58203970103a0684307716caaabd3e9844cacc4dc0f4023" ;;
aarch64-apple-darwin) echo "50ae3e996c974a0bf32ea7d10f495070df33f1b43e0616b2769e3d4821ed8f48" ;;
*) echo "" ;;
esac
}

# Print the SHA-256 of the file at $1 to standard output.
# sha256sum is GNU; macOS ships shasum instead.
# A hashing failure can produce no output yet return success via cut.
sha256_of() {
if command -v sha256sum >/dev/null 2>&1; then sha256sum "$1" | cut -d" " -f1
else shasum -a 256 "$1" | cut -d" " -f1
fi
}

# Download and checksum-verify JUST_VERSION for this platform, then use sudo
# to install it as /usr/local/bin/just with mode 0755, replacing any existing file.
# Return 1 for an unsupported platform, download failure, checksum mismatch or
# failure to create /usr/local/bin. Temporary files are removed on these handled
# failures and after installation. If execution reaches cleanup, return its status;
# in the conditional call from main, extraction or copy failures can be masked.
install_just_verified() {
jv_target="$(just_target)"
[ -z "$jv_target" ] && { fail "just: no verified build for $(uname -s)/$(uname -m); use your package manager"; return 1; }
jv_want="$(just_sha256 "$jv_target")"
jv_tmp="$(mktemp -d)"
jv_url="https://github.com/casey/just/releases/download/${JUST_VERSION}/just-${JUST_VERSION}-${jv_target}.tar.gz"
curl -fsSL --proto '=https' --tlsv1.2 -o "$jv_tmp/just.tar.gz" "$jv_url" || { rm -rf "$jv_tmp"; return 1; }
jv_got="$(sha256_of "$jv_tmp/just.tar.gz")"
if [ "$jv_got" != "$jv_want" ]; then
fail "just: CHECKSUM MISMATCH for $jv_url (expected $jv_want, got $jv_got)"
rm -rf "$jv_tmp"
return 1
fi
tar -xzf "$jv_tmp/just.tar.gz" -C "$jv_tmp" just
sudo install -d -m 0755 /usr/local/bin || { rm -rf "$jv_tmp"; return 1; }
sudo install -m 0755 "$jv_tmp/just" /usr/local/bin/just
Comment thread
hyperpolymath marked this conversation as resolved.
rm -rf "$jv_tmp"
}

# ── Install just ──
# Keep an existing just command, or install using the detected PKG_MGR.
# Use the verified release if apt fails or PKG_MGR has no supported install branch.
# Return 1 if just is still unavailable on PATH; the final availability check
# determines success in main's conditional call even if an installer failed.
install_just() {
if command -v just >/dev/null 2>&1; then
ok "just already installed: $(just --version 2>/dev/null | head -1)"
Expand All @@ -139,8 +209,8 @@
case "$PKG_MGR" in
dnf) sudo dnf install -y just ;;
apt) sudo apt-get install -y just 2>/dev/null || {
# just not in older apt repos — use installer
curl -fsSL https://just.systems/install.sh | bash -s -- --to /usr/local/bin
# just not in older apt repos — use the verified release binary
install_just_verified
} ;;
pacman) sudo pacman -S --noconfirm just ;;
apk) sudo apk add just ;;
Expand All @@ -150,8 +220,8 @@
rpm-ostree) sudo rpm-ostree install just ;;
guix) guix install just ;;
*)
info "Using just installer script..."
curl -fsSL https://just.systems/install.sh | bash -s -- --to /usr/local/bin
info "Installing verified just release..."
install_just_verified
;;
esac

Expand Down
Loading