The runtime every module stands on is built from its own repository

It copied in a compiled directory that is not in source control and resolved
the toolkit to a sibling checkout, so only a workstation with two repositories
side by side could produce it — and its fingerprint was then typed into every
module by hand. Nothing could rebuild it, so nothing could check it, and the
rule that catches a base moving had no version on the far end of its edge.

The recipe now also says what the image in service actually is. It claimed
Alpine and has been serving Debian for as long as nobody could rebuild it.
This commit is contained in:
2026-09-13 02:39:11 +02:00
parent 991fb6faec
commit a174dfd404
3 changed files with 43 additions and 12 deletions
+2 -2
View File
@@ -1,7 +1,7 @@
{
"name": "@novox/mesh-tools",
"version": "0.1.0",
"description": "The Novox Mesh tool runtime — binds the mesh broker and serves the assigned modules' tools.",
"description": "The Novox Mesh tool runtime \u2014 binds the mesh broker and serves the assigned modules' tools.",
"type": "module",
"bin": {
"mesh-tools": "./dist/main.js"
@@ -11,7 +11,7 @@
"test": "node --test --experimental-strip-types 'test/*.test.ts'"
},
"dependencies": {
"@novox/mesh-sdk": "^0.1.0",
"@novox/mesh-sdk": "git+https://git.novox.be/novox/mesh-sdk.git#a1ed33b",
"amqplib": "^0.10.9"
},
"devDependencies": {