aboutsummaryrefslogtreecommitdiff
path: root/scripts/check-wrapper
diff options
context:
space:
mode:
Diffstat (limited to 'scripts/check-wrapper')
-rwxr-xr-xscripts/check-wrapper24
1 files changed, 24 insertions, 0 deletions
diff --git a/scripts/check-wrapper b/scripts/check-wrapper
new file mode 100755
index 0000000..31531b6
--- /dev/null
+++ b/scripts/check-wrapper
@@ -0,0 +1,24 @@
+#!/bin/sh
+# Verify the checked-in gradle-wrapper.jar matches the expected SHA-256.
+# Catches accidental swaps or supply-chain mischief.
+
+set -eu
+
+cd "$(git rev-parse --show-toplevel)"
+
+WRAPPER='gradle/wrapper/gradle-wrapper.jar'
+EXPECTED_FILE="$WRAPPER.sha256"
+
+if [ ! -f "$WRAPPER" ]; then
+ echo "check-wrapper: $WRAPPER is missing" >&2
+ exit 1
+fi
+if [ ! -f "$EXPECTED_FILE" ]; then
+ echo "check-wrapper: $EXPECTED_FILE is missing" >&2
+ exit 1
+fi
+
+# sha256sum reads its first column from the .sha256 sidecar; the second
+# column ('gradle-wrapper.jar') is informational.
+( cd "$(dirname "$WRAPPER")" && sha256sum -c "$(basename "$EXPECTED_FILE")" >/dev/null )
+echo "check-wrapper: ok"