Packages
mob_dev
0.3.34
0.6.23
0.6.22
0.6.21
0.6.20
0.6.19
0.6.18
0.6.17
0.6.16
0.6.15
0.6.14
0.6.13
0.6.12
0.6.11
0.6.10
0.6.9
0.6.8
0.6.7
0.6.6
0.6.5
0.6.4
0.6.3
0.6.2
0.6.1
0.6.0
0.5.17
0.5.16
0.5.15
0.5.14
0.5.13
0.5.12
0.5.11
0.5.10
0.5.9
0.5.8
0.5.7
0.5.6
0.5.5
0.5.4
0.5.3
0.5.2
0.5.1
0.5.0
0.4.0
0.3.37
0.3.35
0.3.34
0.3.33
0.3.28
0.3.26
0.3.23
0.3.21
0.3.19
0.3.18
0.3.17
0.3.16
0.3.15
0.3.14
0.3.13
0.3.12
0.3.11
0.3.10
0.3.9
0.3.8
0.3.7
0.3.6
0.3.5
0.3.4
0.3.3
0.3.2
0.3.1
0.3.0
0.2.18
0.2.17
0.2.15
0.2.14
0.2.13
0.2.12
0.2.11
0.2.10
0.2.9
0.2.8
0.2.7
0.2.6
0.2.5
0.2.4
0.2.3
0.2.2
0.2.1
0.2.0
0.1.0
Development tooling for the Mob mobile framework
Current section
Files
Jump to
Current section
Files
priv/security/bundled_versions.exs
# Source-of-truth manifest for what versions ship inside the OTP
# tarballs that `MobDev.OtpDownloader` fetches.
#
# This file MUST be updated every time those tarballs are rebuilt
# and re-uploaded to the GitHub release. The bundled-runtime scan
# layer fingerprints the cached tarballs at scan time and raises if
# the binaries disagree with what's declared here — drift between
# what we say we shipped and what we actually shipped is exactly
# the failure mode this manifest is designed to catch.
#
# When updating:
#
# 1. Bump the appropriate `:otp_hash` entry (or add a new one)
# 2. Update the version fields under `:bundles`
# 3. Run `mix mob.security_scan` — the bundled-runtime layer
# will fingerprint the cached tarball and assert that the
# binary matches the manifest. If it doesn't, fix the
# manifest, the tarball, or both.
#
# The OTP hash matches `MobDev.OtpDownloader`'s `@otp_hash`. There
# is exactly one active hash per published Mob release.
#
# Format:
#
# %{
# active_hash: "73ba6e0f",
# bundles: %{
# "73ba6e0f" => %{
# erts: "16.3", # erts-* directory in tarball
# otp_release: "28", # major OTP release number
# elixir: "1.19.5", # bundled Elixir stdlib version
# openssl: "3.4.0", # statically linked into libcrypto.a
# exqlite_beam: "0.36.0",
# openssl_release_date: "2024-10-22",
# platforms: [:android, :android_arm32, :ios_sim, :ios_device]
# }
# }
# }
%{
active_hash: "73ba6e0f",
bundles: %{
"73ba6e0f" => %{
erts: "16.3",
otp_release: "28",
elixir: "1.19.5",
openssl: "3.4.0",
exqlite_beam: "0.36.0",
openssl_release_date: "2024-10-22",
platforms: [:android, :android_arm32, :ios_sim, :ios_device],
# Per-platform overrides. A field here replaces the bundle-level
# default for that platform; setting it to `nil` means "this
# platform deliberately does not ship that artifact" (and the
# fingerprinter should not flag its absence as drift).
per_platform: %{
ios_sim: %{exqlite_beam: nil},
ios_device: %{exqlite_beam: nil}
}
}
}
}