You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
DateKeys-App/package.json

44 lines
1.5 KiB

{
"name": "datekeys-app",
"version": "0.1.0-dev",
"private": true,
"description": "DateKeys in TypeScript: canonical CBOR codec, DKC1/DKK1 parsers, capsule inspector library and its static inspector page; later, browser encryption and decryption.",
"license": "Apache-2.0",
"type": "module",
"engines": {
"node": ">=20"
},
"scripts": {
"dev": "vite dev",
"build": "vite build",
"postbuild": "node scripts/check-build.mjs",
"preview": "vite preview",
"prepare": "svelte-kit sync || echo \"\"",
"check": "svelte-kit sync && svelte-check --tsconfig ./tsconfig.json --fail-on-warnings",
"test": "vitest run",
"coverage": "vitest run --coverage",
"typecheck": "svelte-kit sync && tsc --noEmit && tsc --noEmit -p tsconfig.lib.json",
"build:check": "node scripts/check-build.mjs",
"verify": "npm run check && npm run typecheck && npm run coverage && npm run build",
"testdata:sync": "node scripts/sync-testdata.mjs sync",
"testdata:check": "node scripts/sync-testdata.mjs check --against ../datekeys-go"
},
"devDependencies": {
"@sveltejs/adapter-static": "3.0.10",
"@sveltejs/kit": "2.70.3",
"@sveltejs/vite-plugin-svelte": "7.3.0",
"@types/node": "24.13.6",
"@vitest/coverage-v8": "5.0.1",
"svelte": "5.57.1",
"svelte-check": "4.7.6",
"typescript": "5.9.3",
"vite": "8.3.0",
"vitest": "5.0.1"
Phase 2, step 2: runtime dependencies and their guards - age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and @noble/hashes 2.4.0 become exact runtime dependencies (plan section 3, decision 5). The lockfile gains six packages: age-encryption, @noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports them yet, so the site does not change. - src/lib/dependencies.test.ts guards them. package.json declares exactly these three, pinned. The lockfile has no tlock-js, drand-client or noble 1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under @noble/post-quantum. No file of src/ imports tlock-js or drand-client. Only ibe.ts, release.ts and the tests name @noble/, always subpaths of @noble/curves or @noble/hashes that resolve to the root 2.4.0 copy. Every check also runs on bad inputs. It replaces the "only tests import @noble/curves" test of bls12381.contrast.test.ts. - vite.config.ts records the modules of each client chunk in .svelte-kit/output/client-modules.json. check-build.mjs fails if the bundle holds tlock-js, drand-client or @babel/*, or a nested copy other than noble under @noble/post-quantum. It also reports the JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip. - Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256 28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM recipients statically, so post-quantum and its nested noble copy are about 99 KB of the Decrypter's 212 KB of rendered code. - npm audit --omit=dev: no vulnerabilities. The full audit finds two low ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3, which is the latest version and affects only SvelteKit's server. npm run verify is green: 2,384 tests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
},
"dependencies": {
"@noble/curves": "2.4.0",
"@noble/hashes": "2.4.0",
"age-encryption": "0.3.1"
}
}

Powered by TurnKey Linux.