# Customer installation example, NOT enabled or deployed into your repository.
# 1. Vendor release-sentinel-buyer.mjs under scripts/ after reviewing it.
# 2. Choose exactly one trusted package via RELEASE_PACKAGE repository variable.
# 3. Default: free metadata-only checks and zero charges.
# 4. Optional customer-authorized OSV checks need previously funded credits:
#    RELEASE_PAID_MODE=all, RELEASE_BUYER_AUTHORIZED=yes,
#    RELEASE_EXECUTE_PAID=yes, BOUNTY_API_KEY repository secret.
#    RELEASE_MAX_PRICE_USD / RELEASE_MAX_CREDITS_PER_CHECK cap each call;
#    the buyer controls total spend through finite prepaid credits.
name: Release Sentinel dependency checkpoint
on:
  push:
    branches: [main]
    paths: [package-lock.json]
  workflow_dispatch:
permissions:
  contents: read
jobs:
  dependency-checkpoint:
    runs-on: ubuntu-latest
    timeout-minutes: 3
    env:
      RELEASE_PACKAGE: ${{ vars.RELEASE_PACKAGE || 'lodash' }}
      RELEASE_PAID_MODE: ${{ vars.RELEASE_PAID_MODE || 'off' }}
      RELEASE_EXECUTE_PAID: ${{ vars.RELEASE_EXECUTE_PAID || 'no' }}
      RELEASE_BUYER_AUTHORIZED: ${{ vars.RELEASE_BUYER_AUTHORIZED || 'no' }}
      RELEASE_ENFORCE: ${{ vars.RELEASE_ENFORCE || 'no' }}
      RELEASE_MAX_PRICE_USD: "0.05"
      RELEASE_MAX_CREDITS_PER_CHECK: "5"
      BOUNTY_API_KEY: ${{ secrets.BOUNTY_API_KEY }}
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
        with:
          node-version: '22'
      - name: Read exact locked dependency and pinned integrity
        shell: bash
        run: |
          node --input-type=module -e '
            import {readFileSync,writeFileSync} from "node:fs";
            const lock=JSON.parse(readFileSync("package-lock.json","utf8"));
            const name=process.env.RELEASE_PACKAGE;
            if(!/^(?:@[a-z0-9][a-z0-9._~-]{0,99}\/)?[a-z0-9][a-z0-9._~-]{0,99}$/.test(name))throw Error("invalid_package");
            const row=lock.packages?.["node_modules/"+name];
            if(!row?.version)throw Error("selected_dependency_not_in_lockfile");
            const out={name,version:row.version,
              ...(row.integrity?.startsWith("sha512-")?{expected_integrity:row.integrity}:{}),
              policy:{block_on_vulnerability:true,block_install_scripts:true}};
            writeFileSync("/tmp/release-sentinel-check.json",JSON.stringify(out),{mode:0o600});
          '
      - name: Query independent release checkpoint
        shell: bash
        run: node ./scripts/release-sentinel-buyer.mjs < /tmp/release-sentinel-check.json
# Important: Do NOT run this workflow with pull_request_target against
# untrusted code. An owner must explicitly approve purchases and fund the
# buyer prepaid account. No code from package installations is executed here.
