Archilyzer · Source

archilyzer

Archilyzer
git clone https://archilyzer.pages.dev/source/archilyzer.git
Log | Files | Refs | README | LICENSE

commit 4372e5cccb38555134acc2762c8dfd08cff5299a
parent 296b8a0418074971f8dd415228800e7339bc15ce
Author: I Mean I'm Just Saying <imeanimjustsaying@kiwifarms.st>
Date:   Mon, 28 Sep 2026 14:56:16 -0400

docs: PUBLISH.md — the deploy key covers gitleaks and every published file; refusals are masked; rebuild the editor after merging

The re-review's rollout note, in the source mirror section: the live editor
runs its built bundle, so after a merge that changes this step it must be
rebuilt and restarted before any /sites Homepage job — an old bundle's build
has no source step (or no withdrawal) and its deploy no source check.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

Diffstat:
MPUBLISH.md | 24++++++++++++++++++------
1 file changed, 18 insertions(+), 6 deletions(-)

diff --git a/PUBLISH.md b/PUBLISH.md @@ -125,9 +125,18 @@ before `next build`, and: tarball, `snapshot.json`); - **`deploy homepage` (and /sites → Deploy homepage) refuses** an `out/` holding a source unless the skip key says that publish was made under today's rules and step - version, of today's `main`, and is the one in `out/` (its mirror head and its - tarball's sha256): "run `archilyzer build homepage` (it re-audits), then deploy". - An `out/` with no source (`--no-source`) deploys as before. + version, of today's `main`, by today's gitleaks, and is exactly the one in `out/`: + its mirror head, and a digest over every published file (the mirror, the tree, the + manifest, the tarball, `snapshot.json` — sorted path, size and sha256, recomputed + over `out/`), so a mixed or edited `out/` refuses too: "run `archilyzer build + homepage` (it re-audits), then deploy". An `out/` whose `/source` page shows the empty + state (`--no-source`) deploys as before; one with no `/source` page (a refused build) + does not. + +**After merging a change to this step, rebuild and restart the editor before any +/sites Homepage job.** The editor runs its BUILT bundle: until it is rebuilt, its +Build homepage job runs the old `buildHomepage` (without this step, or without the +withdrawal) and its Deploy homepage job has no source check. `build homepage --no-source` (CLI only) removes the previously published source instead, because it was audited against the rules of its own day. A checkout with no @@ -159,7 +168,9 @@ What one publish does: characters, and a hit only by its object: kind, id, the blob's path in history, the byte offset, and for a commit or tag the field (`author`, `committer`, `tagger`, `message`). It prints no byte from the object, because what sits beside a denied - name (a surname, the rest of an address) is as private as the name. It ends with + name (a surname, the rest of an address) is as private as the name, and every + refusal message and path it prints is masked (`[REDACTED]`), so a literal that spans + path components (`a/b`) is not printed by a refusal that names a tree path. It ends with `add a rule to ~/.config/archilyzer/source-scrub.txt or drop the file from history, then re-run.` 5. The tree (`git archive` → `tar -x`, a page per directory; a tracked `index.html`, @@ -169,8 +180,9 @@ What one publish does: removed first and written **last**, so a crash leaves the page's empty state, never a manifest over a half-copied tree. -An unchanged `main` with unchanged rules, step version and filter-repo version skips -(`[source] up to date at …`; `--force` rebuilds). `--check` does everything but the +An unchanged `main` with unchanged rules, step version, filter-repo and gitleaks, and +published files that still match their digest, skips (`[source] up to date at …`; +`--force` rebuilds). `--check` does everything but the install and writes nothing. `--keep-scratch` leaves the scratch clone (`ARCHILYZER_SOURCE_SCRATCH`, default the OS temp dir) for a look, minus `replace.txt` (the scrub rules), which is always deleted; a scratch root inside the