Skip to content

Commit 36373ad

Browse files
guyofeckdorrclaude
authored
ci: enforce wix gateway proxy, with npm cooldown + OIDC in publish (#248)
* ci: enforce wix gateway proxy in all workflows Routes every npm-registry fetch in this repo's CI through the Wix npm embargo gateway, ported from base44-dev/vite-plugin#105. All jobs run on ubuntu-latest; the action is byte-identical to the vite-plugin/apper copy. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * ci: npm cooldown for installs, no gateway in publish, OIDC Ports base44/cli#597 (596104f) to this repo. The Wix gateway cannot carry `npm publish` — it rejects `PUT /<package>` — so the two publish workflows were the one place the embargo rollout had to cheat, deleting the /etc/hosts pin mid-job right before publishing. Per secplatform's interim policy for OSS repos, publish workflows are exempt from the gateway and protected by the lockfile plus a release cooldown instead: - .npmrc gets `min-release-age=14`, matching the gateway's 14-day window, so a freshly published version cannot enter package-lock.json. - Both publish workflows drop the gateway action and the `sed -i /etc/hosts` unpin hack. check_wix_proxy_steps.py records the exemption explicitly in PUBLISH_WORKFLOWS, so every other workflow — present and future — still fails CI without the proxy. - preview-publish.yml installs with `npm ci` instead of `npm install`: with no gateway in front of the job, a resolving install was the only step that could still pull a fresh release. Both publish jobs now resolve nothing. - Both bump to Node 24 and drop `npm install -g npm@11`, which fetched a floating npm release outside the cooldown. Node 24's bundled npm (>= 11.17) already covers trusted publishing (>= 11.5.1) and min-release-age (>= 11.10.0). - Publish steps keep authenticating via npm trusted publishing (OIDC), and `permissions` moves to the job with a note on why each scope is there. `packages: write` goes away — nothing here publishes to GHCR. Verified: `check_wix_proxy_steps.py` passes at 8 of 8 jobs across 8 non-exempt workflows, and its 11 tests pass, including three new ones covering the exemption. --------- Co-authored-by: dorr <dorr@base44.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
1 parent 60a7259 commit 36373ad

17 files changed

Lines changed: 861 additions & 21 deletions
Lines changed: 46 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,46 @@
1+
name: wix gateway proxy
2+
description: >-
3+
Mandatory first step of every job: routes registry.npmjs.org through the
4+
Wix npm embargo gateway by pinning the registry hostname to the gateway IP,
5+
trusting the gateway CA system-wide, and pointing npm at the CA bundle.
6+
Being a local action, the repository must be checked out before it runs.
7+
Enforced for every job by .github/workflows/check-wix-proxy.yml.
8+
9+
inputs:
10+
proxy-ip:
11+
description: IP address of the Wix npm embargo gateway
12+
required: false
13+
default: "23.21.39.196"
14+
15+
runs:
16+
using: composite
17+
steps:
18+
- name: Point registry.npmjs.org at the gateway
19+
shell: bash
20+
run: |
21+
echo "${{ inputs.proxy-ip }} registry.npmjs.org" | sudo tee -a /etc/hosts
22+
getent hosts registry.npmjs.org
23+
24+
- name: Trust the gateway CA
25+
shell: bash
26+
run: |
27+
sudo cp "$GITHUB_ACTION_PATH/../../certs/wix-embargo.pem" /usr/local/share/ca-certificates/wix-embargo.crt
28+
sudo update-ca-certificates
29+
30+
- name: Trust the gateway CA in Node
31+
# Node ignores the OS trust store; NODE_EXTRA_CA_CERTS covers npm, pnpm,
32+
# corepack, and npx. Never use `npm config set cafile` here — it REPLACES
33+
# the trust bundle and breaks other registries (npm.jsr.io), whereas
34+
# NODE_EXTRA_CA_CERTS appends. The /usr/local/share copy survives later
35+
# checkouts and workspace cleans, unlike the in-workspace pem.
36+
shell: bash
37+
run: echo "NODE_EXTRA_CA_CERTS=/usr/local/share/ca-certificates/wix-embargo.crt" >> "$GITHUB_ENV"
38+
39+
- name: Trust the gateway CA in Deno
40+
# Deno (rustls) reads neither the OS store nor NODE_EXTRA_CA_CERTS by
41+
# default; "system" points it at the OS store where the gateway CA is
42+
# installed, "mozilla" keeps public roots for every other host.
43+
# NOTE: rustls still rejects the gateway until it serves a CA-signed
44+
# leaf cert instead of the CA cert itself (CaUsedAsEndEntity).
45+
shell: bash
46+
run: echo "DENO_TLS_CA_STORE=system,mozilla" >> "$GITHUB_ENV"

.github/certs/wix-embargo.pem

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
-----BEGIN CERTIFICATE-----
2+
MIIDzjCCAragAwIBAgIUVpbbERZ/oqaGxJAznohpw7hc/9swDQYJKoZIhvcNAQEL
3+
BQAwZzELMAkGA1UEBhMCVVMxETAPBgNVBAgMCFNlY3VyaXR5MQ0wCwYDVQQHDARN
4+
SVRNMRkwFwYDVQQKDBBOUE0gUG9saWN5IFByb3h5MRswGQYDVQQDDBJyZWdpc3Ry
5+
eS5ucG1qcy5vcmcwHhcNMjYwMTE0MTUwMDQwWhcNMjcwMTE0MTUwMDQwWjBnMQsw
6+
CQYDVQQGEwJVUzERMA8GA1UECAwIU2VjdXJpdHkxDTALBgNVBAcMBE1JVE0xGTAX
7+
BgNVBAoMEE5QTSBQb2xpY3kgUHJveHkxGzAZBgNVBAMMEnJlZ2lzdHJ5Lm5wbWpz
8+
Lm9yZzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKBX6fToCIZ4mSvQ
9+
02/sSVh8xn82DHXW33a5MpVRqMTNa9r7S5TeCLJTmdfJQYi1GYnjRjgIiUK7UwBn
10+
cmyV4fK9PACGsdzmstbGsBQNBmLrCNpFIPG96EmE7u93CyZgVQzzoM0WxTkKmCFR
11+
e4WbhsY2DGSvOQwa/Bj9rusEb3WwHvbzDLfF2BOfiauizHl6dVdRcj8xmN748Kxp
12+
H2AZ3Q3sTe3sfeJVkFKbQ61JBE8YYLe5PtXwZGsumT6K6MjRtlFeXK59D9pXJKmC
13+
rS3zVsExx/NaZmqXUBx/ikdStBbTNEqAkuEHXMArAZYMXXCEbPChCkn/pDCvBofV
14+
S/WAvnUCAwEAAaNyMHAwHQYDVR0OBBYEFG9FHU6u08PGgzDhY3X6RSnUXz1OMB8G
15+
A1UdIwQYMBaAFG9FHU6u08PGgzDhY3X6RSnUXz1OMA8GA1UdEwEB/wQFMAMBAf8w
16+
HQYDVR0RBBYwFIIScmVnaXN0cnkubnBtanMub3JnMA0GCSqGSIb3DQEBCwUAA4IB
17+
AQAG6u7BXGfLe+VttUVZYbqOV3uW0skwAsjK6wcbwW7WEKk0k5oJRCbRGYzSe7hc
18+
fRXkezENYfgsWJOXhOrIm89F2e0dbJTNmefFzS+56RRllHmBEQxxI2f446qBx4w0
19+
/N6QqpE1QxzuvAJDs/wki3CMsnz5Eu3IdM/1Els6Ap794xBXJAwgh7fNa0V5NMLT
20+
hknLtKy6nu1nfoyfZ9fTLr8IKuEfB6vYJ00FDVyVmWGfXam5yAfL8uhCQcBd1AI9
21+
pRHzoBDRNqIWaRF2lWQCWV4pt132oxln0n3iG/TSodbAXp3WFJaKQ0HwXSb5NXjI
22+
nbDI4K0FXvrAhfXRomBSQ3WM
23+
-----END CERTIFICATE-----
Lines changed: 186 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,186 @@
1+
#!/usr/bin/env python3
2+
"""Fail if any GitHub Actions job skips the mandatory Wix gateway proxy action.
3+
4+
There is no per-job opt-out marker by design. A job that genuinely cannot run the
5+
proxy changes this script in the same PR, so the exception gets reviewed in the
6+
open — which is exactly how PUBLISH_WORKFLOWS below came to exist.
7+
"""
8+
9+
from __future__ import annotations
10+
11+
import pathlib
12+
import sys
13+
14+
import yaml
15+
16+
REPO_ROOT = pathlib.Path(__file__).resolve().parents[2]
17+
PROXY_ACTION = "./.github/actions/wix-gateway-proxy"
18+
# The action copies .github/certs/wix-embargo.pem via a path relative to itself,
19+
# so a sparse checkout has to materialize both directories.
20+
REQUIRED_PATHS = (".github/actions/wix-gateway-proxy", ".github/certs")
21+
22+
# Publish workflows, exempt from the gateway by secplatform's interim policy for
23+
# OSS repos: the gateway cannot carry `npm publish`, so these rely on the
24+
# committed package-lock.json plus .npmrc's min-release-age instead.
25+
#
26+
# Adding a file here drops its embargo protection. That is a security decision,
27+
# not a formality — do not do it lightly.
28+
PUBLISH_WORKFLOWS = frozenset(
29+
{
30+
".github/workflows/manual-publish.yml",
31+
".github/workflows/preview-publish.yml",
32+
}
33+
)
34+
35+
FIX_HINT = """Every job must run the Wix gateway proxy immediately after a checkout that
36+
puts it on disk, or that job's npm installs bypass the Wix embargo gateway.
37+
38+
Job that already checks out this repo first:
39+
40+
- uses: actions/checkout@v7
41+
42+
- name: Wix gateway proxy (mandatory)
43+
uses: ./.github/actions/wix-gateway-proxy
44+
45+
Job with no leading same-repo checkout -- prepend a bootstrap one. The action
46+
installs the CA under /usr/local/share, so a later full checkout does not undo it:
47+
48+
- name: Checkout for wix gateway proxy
49+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
50+
with:
51+
sparse-checkout: .github
52+
53+
- name: Wix gateway proxy (mandatory)
54+
uses: ./.github/actions/wix-gateway-proxy
55+
56+
Non-cone sparse checkout -- list both paths explicitly:
57+
58+
with:
59+
sparse-checkout: |
60+
<your existing paths>
61+
.github/actions/wix-gateway-proxy
62+
.github/certs
63+
sparse-checkout-cone-mode: false
64+
"""
65+
66+
67+
def _uses(step: dict) -> str:
68+
return str(step.get("uses", "")).strip().rstrip("/")
69+
70+
71+
def _covers(pattern: str, path: str) -> bool:
72+
return path == pattern or path.startswith(pattern + "/")
73+
74+
75+
def _overlaps(pattern: str, path: str) -> bool:
76+
# An exclusion breaks the action whether it removes the whole directory or a
77+
# single file inside it, so overlap in either direction disqualifies.
78+
return _covers(pattern, path) or _covers(path, pattern)
79+
80+
81+
def _sparse_covers_action(patterns: str) -> bool:
82+
listed = [p.strip().rstrip("/") for p in patterns.splitlines() if p.strip()]
83+
included = [p for p in listed if not p.startswith("!")]
84+
excluded = [p[1:] for p in listed if p.startswith("!")]
85+
return all(
86+
any(_covers(p, required) for p in included)
87+
and not any(_overlaps(p, required) for p in excluded)
88+
for required in REQUIRED_PATHS
89+
)
90+
91+
92+
def _checkout_problem(step: dict) -> str | None:
93+
if not _uses(step).startswith("actions/checkout"):
94+
return f'is preceded by "{_uses(step) or "a run step"}" instead of a checkout'
95+
with_ = step.get("with") or {}
96+
if with_.get("repository"):
97+
return f'is preceded by a checkout of {with_["repository"]}'
98+
if with_.get("path"):
99+
return f'is preceded by a checkout into {with_["path"]}/, not the workspace root'
100+
patterns = with_.get("sparse-checkout")
101+
if patterns and not _sparse_covers_action(str(patterns)):
102+
return "is preceded by a sparse checkout that omits " + " or ".join(REQUIRED_PATHS)
103+
return None
104+
105+
106+
def job_problem(job: dict, workflows: frozenset[str]) -> str | None:
107+
"""Describe why this job fails to run the proxy, or None if it runs it correctly."""
108+
if "uses" in job:
109+
target = str(job["uses"]).strip()
110+
if target.removeprefix("./") in workflows:
111+
return None
112+
return f"calls {target}, whose jobs this check cannot verify"
113+
114+
steps = job.get("steps") or []
115+
index = next((i for i, s in enumerate(steps) if _uses(s) == PROXY_ACTION), None)
116+
if index is None:
117+
return "does not run the Wix gateway proxy"
118+
if index == 0:
119+
return "runs the Wix gateway proxy first, but a local action needs a checkout before it"
120+
if index > 1:
121+
return f"runs the Wix gateway proxy at step {index + 1}; it must be step 2"
122+
step = steps[index]
123+
# Presence, not truthiness: `if: false` parses to False and would skip the step.
124+
if "if" in step:
125+
return "guards the Wix gateway proxy behind an if:, but it is mandatory"
126+
if step.get("continue-on-error"):
127+
return "lets the Wix gateway proxy fail via continue-on-error, but it is mandatory"
128+
with_ = step.get("with") or {}
129+
if "proxy-ip" in with_ and not str(with_["proxy-ip"]).strip():
130+
return "passes an empty proxy-ip, leaving registry.npmjs.org resolving publicly"
131+
return _checkout_problem(steps[0])
132+
133+
134+
def _job_lines(text: str) -> dict[str, int]:
135+
document = yaml.compose(text)
136+
if document is None:
137+
return {}
138+
for key, value in document.value:
139+
if key.value == "jobs":
140+
return {job.value: job.start_mark.line + 1 for job, _ in value.value}
141+
return {}
142+
143+
144+
def main(repo_root: pathlib.Path = REPO_ROOT) -> int:
145+
workflows_dir = repo_root / ".github" / "workflows"
146+
paths = sorted(p for p in workflows_dir.iterdir() if p.suffix in (".yml", ".yaml"))
147+
workflows = frozenset(p.relative_to(repo_root).as_posix() for p in paths)
148+
problems = []
149+
jobs = calls = 0
150+
exempt_paths = set()
151+
152+
for path in paths:
153+
rel = path.relative_to(repo_root).as_posix()
154+
if rel in PUBLISH_WORKFLOWS:
155+
exempt_paths.add(rel)
156+
continue
157+
text = path.read_text(encoding="utf-8")
158+
lines = _job_lines(text)
159+
for job_id, job in ((yaml.safe_load(text) or {}).get("jobs") or {}).items():
160+
job = job or {}
161+
jobs += 1
162+
calls += "uses" in job
163+
problem = job_problem(job, workflows)
164+
if problem:
165+
problems.append((path.relative_to(repo_root), lines[job_id], job_id, problem))
166+
167+
for path, line, job_id, problem in problems:
168+
print(f'::error file={path},line={line}::Job "{job_id}" {problem}.')
169+
170+
if problems:
171+
print(f"\n{len(problems)} job(s) skip the Wix gateway proxy.\n")
172+
print(FIX_HINT)
173+
return 1
174+
175+
print(
176+
f"Wix gateway proxy: verified {jobs - calls} of {jobs} jobs across "
177+
f"{len(paths) - len(exempt_paths)} workflows ({calls} reusable-workflow calls "
178+
f"delegate to the workflow they call)."
179+
)
180+
if exempt_paths:
181+
print("Publish workflows exempt by policy: " + ", ".join(sorted(exempt_paths)))
182+
return 0
183+
184+
185+
if __name__ == "__main__":
186+
sys.exit(main())
Lines changed: 78 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,78 @@
1+
# PyYAML for .github/scripts/check_wix_proxy_steps.py, hash-pinned so the
2+
# supply-chain guard does not itself install an unverified package.
3+
# PyYAML has no dependencies; hashes are PyPI's published sha256 set for
4+
# pyyaml 6.0.3, ported verbatim from base44-dev/vite-plugin.
5+
pyyaml==6.0.3 \
6+
--hash=sha256:00c4bdeba853cc34e7dd471f16b4114f4162dc03e6b7afcc2128711f0eca823c \
7+
--hash=sha256:0150219816b6a1fa26fb4699fb7daa9caf09eb1999f3b70fb6e786805e80375a \
8+
--hash=sha256:02893d100e99e03eda1c8fd5c441d8c60103fd175728e23e431db1b589cf5ab3 \
9+
--hash=sha256:02ea2dfa234451bbb8772601d7b8e426c2bfa197136796224e50e35a78777956 \
10+
--hash=sha256:0f29edc409a6392443abf94b9cf89ce99889a1dd5376d94316ae5145dfedd5d6 \
11+
--hash=sha256:10892704fc220243f5305762e276552a0395f7beb4dbf9b14ec8fd43b57f126c \
12+
--hash=sha256:16249ee61e95f858e83976573de0f5b2893b3677ba71c9dd36b9cf8be9ac6d65 \
13+
--hash=sha256:1d37d57ad971609cf3c53ba6a7e365e40660e3be0e5175fa9f2365a379d6095a \
14+
--hash=sha256:1ebe39cb5fc479422b83de611d14e2c0d3bb2a18bbcb01f229ab3cfbd8fee7a0 \
15+
--hash=sha256:214ed4befebe12df36bcc8bc2b64b396ca31be9304b8f59e25c11cf94a4c033b \
16+
--hash=sha256:2283a07e2c21a2aa78d9c4442724ec1eb15f5e42a723b99cb3d822d48f5f7ad1 \
17+
--hash=sha256:22ba7cfcad58ef3ecddc7ed1db3409af68d023b7f940da23c6c2a1890976eda6 \
18+
--hash=sha256:27c0abcb4a5dac13684a37f76e701e054692a9b2d3064b70f5e4eb54810553d7 \
19+
--hash=sha256:28c8d926f98f432f88adc23edf2e6d4921ac26fb084b028c733d01868d19007e \
20+
--hash=sha256:2e71d11abed7344e42a8849600193d15b6def118602c4c176f748e4583246007 \
21+
--hash=sha256:34d5fcd24b8445fadc33f9cf348c1047101756fd760b4dacb5c3e99755703310 \
22+
--hash=sha256:37503bfbfc9d2c40b344d06b2199cf0e96e97957ab1c1b546fd4f87e53e5d3e4 \
23+
--hash=sha256:3c5677e12444c15717b902a5798264fa7909e41153cdf9ef7ad571b704a63dd9 \
24+
--hash=sha256:3ff07ec89bae51176c0549bc4c63aa6202991da2d9a6129d7aef7f1407d3f295 \
25+
--hash=sha256:41715c910c881bc081f1e8872880d3c650acf13dfa8214bad49ed4cede7c34ea \
26+
--hash=sha256:418cf3f2111bc80e0933b2cd8cd04f286338bb88bdc7bc8e6dd775ebde60b5e0 \
27+
--hash=sha256:44edc647873928551a01e7a563d7452ccdebee747728c1080d881d68af7b997e \
28+
--hash=sha256:4a2e8cebe2ff6ab7d1050ecd59c25d4c8bd7e6f400f5f82b96557ac0abafd0ac \
29+
--hash=sha256:4ad1906908f2f5ae4e5a8ddfce73c320c2a1429ec52eafd27138b7f1cbe341c9 \
30+
--hash=sha256:501a031947e3a9025ed4405a168e6ef5ae3126c59f90ce0cd6f2bfc477be31b7 \
31+
--hash=sha256:5190d403f121660ce8d1d2c1bb2ef1bd05b5f68533fc5c2ea899bd15f4399b35 \
32+
--hash=sha256:5498cd1645aa724a7c71c8f378eb29ebe23da2fc0d7a08071d89469bf1d2defb \
33+
--hash=sha256:5cf4e27da7e3fbed4d6c3d8e797387aaad68102272f8f9752883bc32d61cb87b \
34+
--hash=sha256:5e0b74767e5f8c593e8c9b5912019159ed0533c70051e9cce3e8b6aa699fcd69 \
35+
--hash=sha256:5ed875a24292240029e4483f9d4a4b8a1ae08843b9c54f43fcc11e404532a8a5 \
36+
--hash=sha256:5fcd34e47f6e0b794d17de1b4ff496c00986e1c83f7ab2fb8fcfe9616ff7477b \
37+
--hash=sha256:5fdec68f91a0c6739b380c83b951e2c72ac0197ace422360e6d5a959d8d97b2c \
38+
--hash=sha256:6344df0d5755a2c9a276d4473ae6b90647e216ab4757f8426893b5dd2ac3f369 \
39+
--hash=sha256:64386e5e707d03a7e172c0701abfb7e10f0fb753ee1d773128192742712a98fd \
40+
--hash=sha256:652cb6edd41e718550aad172851962662ff2681490a8a711af6a4d288dd96824 \
41+
--hash=sha256:66291b10affd76d76f54fad28e22e51719ef9ba22b29e1d7d03d6777a9174198 \
42+
--hash=sha256:66e1674c3ef6f541c35191caae2d429b967b99e02040f5ba928632d9a7f0f065 \
43+
--hash=sha256:6adc77889b628398debc7b65c073bcb99c4a0237b248cacaf3fe8a557563ef6c \
44+
--hash=sha256:79005a0d97d5ddabfeeea4cf676af11e647e41d81c9a7722a193022accdb6b7c \
45+
--hash=sha256:7c6610def4f163542a622a73fb39f534f8c101d690126992300bf3207eab9764 \
46+
--hash=sha256:7f047e29dcae44602496db43be01ad42fc6f1cc0d8cd6c83d342306c32270196 \
47+
--hash=sha256:8098f252adfa6c80ab48096053f512f2321f0b998f98150cea9bd23d83e1467b \
48+
--hash=sha256:850774a7879607d3a6f50d36d04f00ee69e7fc816450e5f7e58d7f17f1ae5c00 \
49+
--hash=sha256:8d1fab6bb153a416f9aeb4b8763bc0f22a5586065f86f7664fc23339fc1c1fac \
50+
--hash=sha256:8da9669d359f02c0b91ccc01cac4a67f16afec0dac22c2ad09f46bee0697eba8 \
51+
--hash=sha256:8dc52c23056b9ddd46818a57b78404882310fb473d63f17b07d5c40421e47f8e \
52+
--hash=sha256:9149cad251584d5fb4981be1ecde53a1ca46c891a79788c0df828d2f166bda28 \
53+
--hash=sha256:93dda82c9c22deb0a405ea4dc5f2d0cda384168e466364dec6255b293923b2f3 \
54+
--hash=sha256:96b533f0e99f6579b3d4d4995707cf36df9100d67e0c8303a0c55b27b5f99bc5 \
55+
--hash=sha256:9c57bb8c96f6d1808c030b1687b9b5fb476abaa47f0db9c0101f5e9f394e97f4 \
56+
--hash=sha256:9c7708761fccb9397fe64bbc0395abcae8c4bf7b0eac081e12b809bf47700d0b \
57+
--hash=sha256:9f3bfb4965eb874431221a3ff3fdcddc7e74e3b07799e0e84ca4a0f867d449bf \
58+
--hash=sha256:a33284e20b78bd4a18c8c2282d549d10bc8408a2a7ff57653c0cf0b9be0afce5 \
59+
--hash=sha256:a80cb027f6b349846a3bf6d73b5e95e782175e52f22108cfa17876aaeff93702 \
60+
--hash=sha256:b30236e45cf30d2b8e7b3e85881719e98507abed1011bf463a8fa23e9c3e98a8 \
61+
--hash=sha256:b3bc83488de33889877a0f2543ade9f70c67d66d9ebb4ac959502e12de895788 \
62+
--hash=sha256:b865addae83924361678b652338317d1bd7e79b1f4596f96b96c77a5a34b34da \
63+
--hash=sha256:b8bb0864c5a28024fac8a632c443c87c5aa6f215c0b126c449ae1a150412f31d \
64+
--hash=sha256:ba1cc08a7ccde2d2ec775841541641e4548226580ab850948cbfda66a1befcdc \
65+
--hash=sha256:bdb2c67c6c1390b63c6ff89f210c8fd09d9a1217a465701eac7316313c915e4c \
66+
--hash=sha256:c1ff362665ae507275af2853520967820d9124984e0f7466736aea23d8611fba \
67+
--hash=sha256:c2514fceb77bc5e7a2f7adfaa1feb2fb311607c9cb518dbc378688ec73d8292f \
68+
--hash=sha256:c3355370a2c156cffb25e876646f149d5d68f5e0a3ce86a5084dd0b64a994917 \
69+
--hash=sha256:c458b6d084f9b935061bc36216e8a69a7e293a2f1e68bf956dcd9e6cbcd143f5 \
70+
--hash=sha256:d0eae10f8159e8fdad514efdc92d74fd8d682c933a6dd088030f3834bc8e6b26 \
71+
--hash=sha256:d76623373421df22fb4cf8817020cbb7ef15c725b9d5e45f17e189bfc384190f \
72+
--hash=sha256:ebc55a14a21cb14062aa4162f906cd962b28e2e9ea38f9b4391244cd8de4ae0b \
73+
--hash=sha256:eda16858a3cab07b80edaf74336ece1f986ba330fdb8ee0d6c0d68fe82bc96be \
74+
--hash=sha256:ee2922902c45ae8ccada2c5b501ab86c36525b883eff4255313a253a3160861c \
75+
--hash=sha256:efd7b85f94a6f21e4932043973a7ba2613b059c4a000551892ac9f1d11f5baf3 \
76+
--hash=sha256:f7057c9a337546edc7973c0d3ba84ddcdf0daa14533c2065749c9075001090e6 \
77+
--hash=sha256:fa160448684b4e94d80416c0fa4aac48967a969efe22931448d853ada8baf926 \
78+
--hash=sha256:fc09d0aa354569bc501d4e787133afc08552722d3ab34836a80547331bb5d4a0

0 commit comments

Comments
 (0)