social-kit / deps.edn
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
{;; Exact pins — the Closure compiler version rides on these two, and the
 ;; committed dist/ must rebuild byte-identical (deploy/check-dist.sh). They
 ;; are also the pair ardegazu-id-kit was released with: once its CLJS sources
 ;; are compiled from this classpath (below), a different pair would mean a
 ;; different compile of somebody else's released kit.
 ;;
 ;; Relative paths only — never :local/root, never an absolute path: the idpat
 ;; publish gate scans every decompressed git object for local path fragments.
 ;;
 ;; The rule: OUR OWN kits are meant to be consumed as ClojureScript SOURCE off
 ;; the classpath, never as their npm dist — one compiled copy per build means
 ;; one cljs.core, real DCE, and exactly one `Identity` class in the process
 ;; (the "two classes, broken instanceof" hazard only exists in a mixed
 ;; regime). Foreign JS/native packages — @noble/curves, the libp2p family —
 ;; stay string requires: that is ordinary interop, not the hybrid.
 ;;
 ;; ardegazu-id-kit is still reached through its npm install, so the sha pin in
 ;; package.json stays the ONE cross-repo dependency mechanism (dev/docs/CLJS.md);
 ;; this path only points the compiler at what that pin unpacked.
 ;;
 ;; THE REQUIRES ARE LIVE. src/ binds ardegazu.id.{crypto,identity,profile,
 ;; xkey} — the DEFINING namespaces, never `index`, which is only a re-export
 ;; shim for the ESM surface and has no business on a classpath consumer's
 ;; requires. The dist no longer imports "ardegazu-id-kit" at all; it reaches
 ;; @noble/curves/ed25519 directly, as it already did for its own signing.
 ;;
 ;; Classpath consumption is TRANSITIVE: every consumer that classpaths THIS
 ;; kit (peer-kit does) must now carry id-kit's src on its own :paths too, or
 ;; its build breaks on the next pin bump. That is why the unused path landed
 ;; one commit ahead of these requires, and why it must land in peer-kit
 ;; before this kit is released to it.
 ;;
 ;; Compiling id-kit in is only safe because id-kit dropped its :advanced DCE
 ;; cliff first (13d4e15). Its `crypto` and `identity` used to require
 ;; clojure.string alongside a multi-arg cljs.core/str; that pair defeats DCE
 ;; and retains cljs.core's seq/collection runtime — ~91 KB raw, 19.8 KB
 ;; gzipped. It lands in :shared, because more than one module reaches it, so
 ;; `./join` — the chip nine apps pull at first paint — would have paid it too:
 ;; shared.js 1.25 KB -> 21.1 KB gzipped, and test/module-budget.test.mjs
 ;; fires, which is exactly what that tripwire is for. Measured after: shared
 ;; 1,251 B gz (unmoved), join 1,495 B, index 17,958 -> 19,459 B against its
 ;; 24 KB cap — id-kit's code simply moved from an import into the bundle.
 :paths ["src" "node_modules/ardegazu-id-kit/src"]
 :deps {org.clojure/clojurescript {:mvn/version "1.12.134"}
        thheller/shadow-cljs {:mvn/version "3.3.6"}}
 :aliases
 {:dev {:extra-deps {cider/cider-nrepl {:mvn/version "0.59.0"}}}}}

static mirror of HEAD · about · clone: git clone https://git.ardegazu.ro/social-kit.git