{;; Exact pins — the Closure compiler version rides on these two, and the
;; committed dist/ must rebuild byte-identical (deploy/check-dist.sh). They
;; are also the pair ardegazu-id-kit was released with: once its CLJS sources
;; are compiled from this classpath (below), a different pair would mean a
;; different compile of somebody else's released kit.
;;
;; Relative paths only — never :local/root, never an absolute path: the idpat
;; publish gate scans every decompressed git object for local path fragments.
;;
;; The rule: OUR OWN kits are meant to be consumed as ClojureScript SOURCE off
;; the classpath, never as their npm dist — one compiled copy per build means
;; one cljs.core, real DCE, and exactly one `Identity` class in the process
;; (the "two classes, broken instanceof" hazard only exists in a mixed
;; regime). Foreign JS/native packages — @noble/curves, the libp2p family —
;; stay string requires: that is ordinary interop, not the hybrid.
;;
;; ardegazu-id-kit is still reached through its npm install, so the sha pin in
;; package.json stays the ONE cross-repo dependency mechanism (dev/docs/CLJS.md);
;; this path only points the compiler at what that pin unpacked.
;;
;; THE REQUIRES ARE LIVE. src/ binds ardegazu.id.{crypto,identity,profile,
;; xkey} — the DEFINING namespaces, never `index`, which is only a re-export
;; shim for the ESM surface and has no business on a classpath consumer's
;; requires. The dist no longer imports "ardegazu-id-kit" at all; it reaches
;; @noble/curves/ed25519 directly, as it already did for its own signing.
;;
;; Classpath consumption is TRANSITIVE: every consumer that classpaths THIS
;; kit (peer-kit does) must now carry id-kit's src on its own :paths too, or
;; its build breaks on the next pin bump. That is why the unused path landed
;; one commit ahead of these requires, and why it must land in peer-kit
;; before this kit is released to it.
;;
;; Compiling id-kit in is only safe because id-kit dropped its :advanced DCE
;; cliff first (13d4e15). Its `crypto` and `identity` used to require
;; clojure.string alongside a multi-arg cljs.core/str; that pair defeats DCE
;; and retains cljs.core's seq/collection runtime — ~91 KB raw, 19.8 KB
;; gzipped. It lands in :shared, because more than one module reaches it, so
;; `./join` — the chip nine apps pull at first paint — would have paid it too:
;; shared.js 1.25 KB -> 21.1 KB gzipped, and test/module-budget.test.mjs
;; fires, which is exactly what that tripwire is for. Measured after: shared
;; 1,251 B gz (unmoved), join 1,495 B, index 17,958 -> 19,459 B against its
;; 24 KB cap — id-kit's code simply moved from an import into the bundle.
:paths ["src" "node_modules/ardegazu-id-kit/src"]
:deps {org.clojure/clojurescript {:mvn/version "1.12.134"}
thheller/shadow-cljs {:mvn/version "3.3.6"}}
:aliases
{:dev {:extra-deps {cider/cider-nrepl {:mvn/version "0.59.0"}}}}}