board / client / deps.edn
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
{;; Exact pins — the Closure compiler version rides on these two (the same
 ;; known-good pair as the kits, game1 and chat); half of the
 ;; deterministic-build story.
 ;;
 ;; Relative paths only — never :local/root, never an absolute path: the idpat
 ;; publish gate scans every decompressed git object for local path fragments.
 ;;
 ;; ardegazu-rooms-kit carries the shared rooms core (js + lib/{access,crypto,
 ;; descriptor,encryption,log,net,orbit-identity,turn}) that this app used to
 ;; vendor from chat under src/board/. It is reached through its npm install, so
 ;; the sha pin in package.json stays the ONE cross-repo dependency mechanism
 ;; (dev/docs/CLJS.md) — one bump path, one lockfile, ardz kit-release unchanged.
 ;;
 ;; NOT adopted, and deliberately still under src/board/lib: protocol.cljs (the
 ;; bespoke op union — board has add/edit/del/sealed plus a whole control plane
 ;; and no legacy op) and mailbox.cljs (an uncapped outgoing queue, per the no-silent-drop rule; the
 ;; kit has no mailbox at all). Both are safe to keep because NOTHING in the
 ;; shared core requires either of them: protocol is a documentation-only
 ;; namespace with no forms after its `ns`, required by no app namespace in
 ;; either repo, and mailbox is required only by board's own code. So keeping
 ;; them cannot silently reroute a shared file onto the kit's shapes. epoch,
 ;; policy, wrapbox and selftest are likewise board's own, and reach the shared
 ;; core the same way every app namespace now does.
 ;;
 ;; OUR OWN KITS ARE CLASSPATH SOURCE, NOT npm DISTS. rooms-kit, id-kit and
 ;; social-kit are ClojureScript libraries this suite owns; they are consumed as
 ;; ClojureScript — their `src` on this classpath, compiled once into this
 ;; build, requiring their defining namespaces (`ardegazu.rooms.*`,
 ;; `ardegazu.id.*`, `ardegazu.social.*`). Never `ardegazu.id.index` or
 ;; `ardegazu.social.index`: those are re-export shims that exist to shape each
 ;; kit's ESM surface and have no business on a source consumer's requires.
 ;; FOREIGN packages (@libp2p/*, @noble/*, helia, @orbitdb/core, events, …)
 ;; stay string requires — that is ordinary interop, not the hybrid.
 ;; The npm install still governs: the sha pin in package.json is what fixes
 ;; WHICH source lands here, so it remains the ONE cross-repo dependency
 ;; mechanism (dev/docs/CLJS.md) — one bump path, one lockfile, ardz
 ;; kit-release unchanged.
 ;;
 ;; This used to say id-kit had to stay a dist or two Identity classes would
 ;; break `instanceof`. That had the causation backwards: rooms-kit compiles
 ;; id-kit from SOURCE now and owns the class, so it is the leftover dist
 ;; import that would manufacture a second copy. Source everywhere = exactly
 ;; one compiled `Identity` per build, and the `Identity` that reaches
 ;; lib/wrapbox's xkey seals is the same object rooms-kit's orbit-identity
 ;; signs with.
 :paths ["src"
         "node_modules/ardegazu-rooms-kit/src"
         "node_modules/ardegazu-id-kit/src"
         "node_modules/ardegazu-social-kit/src"]
 :deps {org.clojure/clojurescript {:mvn/version "1.12.134"}
        thheller/shadow-cljs {:mvn/version "3.3.6"}}
 :aliases
 {:dev {:extra-deps {cider/cider-nrepl {:mvn/version "0.59.0"}}}
  ;; cljfmt is a TOOL, not a dependency. :replace-deps keeps it off the build
  ;; classpath (neither shadow-cljs nor clojurescript is loaded to run it) and
  ;; :replace-paths keeps the sources off it too — cljfmt only ever reads the
  ;; files named on the command line. Exact pin, same rule as the two above.
  ;; The config is committed beside this file; both paths are relative, because
  ;; the idpat publish gate aborts on a local filesystem path in any object.
  ;; Wired into `npm test` as the FIRST link of the test script itself, not as
  ;; a `pretest` hook: an npm lifecycle hook is skipped outright under
  ;; `ignore-scripts=true`, which is a gate that passes by not running.
  :cljfmt {:replace-deps {dev.weavejester/cljfmt {:mvn/version "0.13.1"}}
           :replace-paths []
           :main-opts ["-m" "cljfmt.main" "--config" ".cljfmt.edn"]}
  ;; clj-kondo is a TOOL too, same shape and same reasons as :cljfmt above:
  ;; :replace-deps keeps it off the build classpath and :replace-paths keeps the
  ;; sources off its own, since it reads only the paths named on the command
  ;; line. Running it as a pinned JVM dep rather than the native binary is
  ;; deliberate — the gate must not depend on what happens to be installed, and
  ;; three versions (2025.06.05, 2026.01.19 and this pin) were measured to give
  ;; identical findings on this tree, as did the native binary.
  ;; Config and the defclass hook are committed at .clj-kondo/ beside this file;
  ;; every path here is relative, because the idpat publish gate aborts on a
  ;; local filesystem path in any object.
  ;; Wired into `npm test` as the second link of the test script itself, right
  ;; after cljfmt and before anything compiles — never as a `pretest` hook, which
  ;; `ignore-scripts=true` skips outright (a gate that passes by not running).
  ;; --fail-level warning is the default and is what makes this a gate; the
  ;; config promotes the one :info linter this tree can trip so it cannot print
  ;; a finding and still exit 0.
  :clj-kondo {:replace-deps {clj-kondo/clj-kondo {:mvn/version "2026.08.04"}}
              :replace-paths []
              :main-opts ["-m" "clj-kondo.main" "--lint" "src" "--fail-level" "warning"]}}}

static mirror of HEAD · about · clone: git clone https://git.ardegazu.ro/board.git