Build and test
Checks
cd grpc && go build ./... && go vet ./... && go test ./...
cd flutter && flutter analyze && flutter testThere is no CI workflow in this repo. CORE verifies it centrally and posts core/ci on
its PR heads and on its default-branch HEAD. See Verification.
.github/ keeps only cd.yml (with its push trigger off), gatekeeper.yml (the
organisation-wide security gate) and actionlint.yaml.
Protobuf
Run these from the repo root:
buf generate grpc --template grpc/buf.gen.go.yaml
buf generate grpc --template grpc/buf.gen.dart.yamlThe grpc input matters. The workspace also holds proto-vendor/, which carries ui’s
judgement proto. That proto must be resolved, never generated: Go takes it from
github.com/org-runink/ui, and Dart takes it from runink_judgement.
Image
GH_TOKEN=$(gh auth token) podman build --secret id=gh_token,env=GH_TOKEN -f grpc/Dockerfile .The Dockerfile’s siblings stage clones the private security, store, billing, ui and
inference repos for both the Flutter stage and the Go stage, so the token must be able to
read them. The image:
- builds the web bundle with
--base-href /forge/,--no-source-mapsand--pwa-strategy=none, and contains no*.mapfiles; - sets
FORGE_LISTEN_HOST=::(TestImageListensOnIPv6Everywhereguards that line).
No service worker, and every file is revalidated. A stale bundle once masked a deploy.
So the bundle registers no service worker. flutter/web/index.html unregisters any worker
an earlier FORGE bundle installed, but only workers scoped under /forge/, since CORE’s own
worker is not FORGE’s to remove. The server also sends Cache-Control: no-cache on every
file, because Flutter’s file names are not content-hashed. --pwa-strategy is deprecated in
Flutter 3.44. When it is removed, the build will fail at that flag, and the flag should then
be dropped.
Licence checks
FORGE is proprietary Runink IP. No workflow here runs these checks, so run them before you push:
sh scripts/check-licenses.sh # licence policy over grpc/go.sum and flutter/pubspec.lock
sh scripts/gen-third-party-notices.sh --checkNew files start with an SPDX header: // SPDX-License-Identifier: LicenseRef-Runink-Proprietary,
or # for shell, YAML and TOML. Vendored third-party files get a REUSE.toml annotation
under their real licence.
Sources
CLAUDE.md (“Build & verify”, “Licence”); grpc/Dockerfile; grpc/cmd/webstatic.go;
grpc/cmd/serve_test.go.