aboutsummaryrefslogtreecommitdiff
path: root/scripts/check-wrapper
blob: 31531b66a2a13e4183a07b699166cdd2b772c299 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
#!/bin/sh
# Verify the checked-in gradle-wrapper.jar matches the expected SHA-256.
# Catches accidental swaps or supply-chain mischief.

set -eu

cd "$(git rev-parse --show-toplevel)"

WRAPPER='gradle/wrapper/gradle-wrapper.jar'
EXPECTED_FILE="$WRAPPER.sha256"

if [ ! -f "$WRAPPER" ]; then
    echo "check-wrapper: $WRAPPER is missing" >&2
    exit 1
fi
if [ ! -f "$EXPECTED_FILE" ]; then
    echo "check-wrapper: $EXPECTED_FILE is missing" >&2
    exit 1
fi

# sha256sum reads its first column from the .sha256 sidecar; the second
# column ('gradle-wrapper.jar') is informational.
( cd "$(dirname "$WRAPPER")" && sha256sum -c "$(basename "$EXPECTED_FILE")" >/dev/null )
echo "check-wrapper: ok"