commit 4372e5cccb38555134acc2762c8dfd08cff5299a
parent 296b8a0418074971f8dd415228800e7339bc15ce
Author: I Mean I'm Just Saying <imeanimjustsaying@kiwifarms.st>
Date: Mon, 28 Sep 2026 14:56:16 -0400
docs: PUBLISH.md — the deploy key covers gitleaks and every published file; refusals are masked; rebuild the editor after merging
The re-review's rollout note, in the source mirror section: the live editor
runs its built bundle, so after a merge that changes this step it must be
rebuilt and restarted before any /sites Homepage job — an old bundle's build
has no source step (or no withdrawal) and its deploy no source check.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Diffstat:
1 file changed, 18 insertions(+), 6 deletions(-)
diff --git a/PUBLISH.md b/PUBLISH.md
@@ -125,9 +125,18 @@ before `next build`, and:
tarball, `snapshot.json`);
- **`deploy homepage` (and /sites → Deploy homepage) refuses** an `out/` holding a
source unless the skip key says that publish was made under today's rules and step
- version, of today's `main`, and is the one in `out/` (its mirror head and its
- tarball's sha256): "run `archilyzer build homepage` (it re-audits), then deploy".
- An `out/` with no source (`--no-source`) deploys as before.
+ version, of today's `main`, by today's gitleaks, and is exactly the one in `out/`:
+ its mirror head, and a digest over every published file (the mirror, the tree, the
+ manifest, the tarball, `snapshot.json` — sorted path, size and sha256, recomputed
+ over `out/`), so a mixed or edited `out/` refuses too: "run `archilyzer build
+ homepage` (it re-audits), then deploy". An `out/` whose `/source` page shows the empty
+ state (`--no-source`) deploys as before; one with no `/source` page (a refused build)
+ does not.
+
+**After merging a change to this step, rebuild and restart the editor before any
+/sites Homepage job.** The editor runs its BUILT bundle: until it is rebuilt, its
+Build homepage job runs the old `buildHomepage` (without this step, or without the
+withdrawal) and its Deploy homepage job has no source check.
`build homepage --no-source` (CLI only) removes the previously published source
instead, because it was audited against the rules of its own day. A checkout with no
@@ -159,7 +168,9 @@ What one publish does:
characters, and a hit only by its object: kind, id, the blob's path in history, the
byte offset, and for a commit or tag the field (`author`, `committer`, `tagger`,
`message`). It prints no byte from the object, because what sits beside a denied
- name (a surname, the rest of an address) is as private as the name. It ends with
+ name (a surname, the rest of an address) is as private as the name, and every
+ refusal message and path it prints is masked (`[REDACTED]`), so a literal that spans
+ path components (`a/b`) is not printed by a refusal that names a tree path. It ends with
`add a rule to ~/.config/archilyzer/source-scrub.txt or drop the file from history,
then re-run.`
5. The tree (`git archive` → `tar -x`, a page per directory; a tracked `index.html`,
@@ -169,8 +180,9 @@ What one publish does:
removed first and written **last**, so a crash leaves the page's empty state,
never a manifest over a half-copied tree.
-An unchanged `main` with unchanged rules, step version and filter-repo version skips
-(`[source] up to date at …`; `--force` rebuilds). `--check` does everything but the
+An unchanged `main` with unchanged rules, step version, filter-repo and gitleaks, and
+published files that still match their digest, skips (`[source] up to date at …`;
+`--force` rebuilds). `--check` does everything but the
install and writes nothing. `--keep-scratch` leaves the scratch clone
(`ARCHILYZER_SOURCE_SCRATCH`, default the OS temp dir) for a look, minus
`replace.txt` (the scrub rules), which is always deleted; a scratch root inside the