Files
Genarrative/apps/ai-game-creator-shell/scripts/macos-bundle-policy.mjs
T
kdletters 110f088d41
Project CI / AI game creator shell Rust lane 2/2 (push) Failing after 1m12s
Project CI / AI game creator shell Rust smoke (push) Failing after 1m12s
Project CI / AI game creator shell Rust lane 1/2 (push) Failing after 1m12s
Project CI / AI game creator shell Rust crates (push) Successful in 1m37s
Project CI / Frontend tests (push) Successful in 3m37s
Project CI / Repository checks (push) Successful in 4m4s
Project CI / AI game creator shell web tests (push) Successful in 2m11s
Project CI / Backend tests (push) Successful in 6m31s
Project CI / Native shell tests (push) Successful in 7m13s
修复 Jenkins 发布流水线与 macOS 包门禁
- 转义 Stdb Publish GString 内的 shell 命令替换,避免 Jenkinsfile 加载时 Groovy 编译失败
- 为 Stdb Publish 暂存清理命令补充生产运维回归门禁
- 抽离 macOS 包内容策略并放行随包 Claude Agent SDK 的受控 node_modules
- 违规资源现在会输出具体相对路径,并补充包内容白名单单测与排障记录
2026-09-30 16:01:21 +08:00

47 lines
1.5 KiB
JavaScript

/**
* macOS 安装包内容策略。
*
* `check-macos-bundle.mjs` 会扫描随包 resources。Node runtime 与 Claude Agent SDK
* sidecar 都需要 `node_modules` 形式的目录,但其它构建残留或第三方依赖不能被
* 静默带入安装包,因此这里只放行两棵明确的生产子树。
*/
const NODE_RUNTIME_NODE_MODULES = 'game-runtime/node/node_modules';
const CLAUDE_AGENT_NODE_MODULES = 'claude-agent/node_modules';
const CLAUDE_AGENT_SCOPE = `${CLAUDE_AGENT_NODE_MODULES}/@anthropic-ai`;
const CLAUDE_AGENT_PACKAGE_PATTERN =
/^(?:claude-agent-sdk|claude-agent-sdk-darwin-(?:arm64|x64))(?:\/.*)?$/u;
function isAllowedClaudeAgentNodeModulesPath(file) {
if (file === CLAUDE_AGENT_NODE_MODULES || file === CLAUDE_AGENT_SCOPE) {
return true;
}
if (!file.startsWith(`${CLAUDE_AGENT_SCOPE}/`)) {
return false;
}
return CLAUDE_AGENT_PACKAGE_PATTERN.test(
file.slice(`${CLAUDE_AGENT_SCOPE}/`.length),
);
}
export function isAllowedBundledNodeModulesPath(file) {
return (
file === NODE_RUNTIME_NODE_MODULES ||
file === `${NODE_RUNTIME_NODE_MODULES}/npm` ||
file.startsWith(`${NODE_RUNTIME_NODE_MODULES}/npm/`) ||
isAllowedClaudeAgentNodeModulesPath(file)
);
}
export function listForbiddenBundledResourceFiles(files) {
return files.filter(
(file) =>
/(^|\/)(\.env[^/]*|auth\.json|target|\.git)(\/|$)|\.(exe|dll)$/u.test(
file,
) ||
(/(^|\/)node_modules(\/|$)/u.test(file) &&
!isAllowedBundledNodeModulesPath(file)),
);
}