Convert README.nfo to README.org !1
3 files changed, +173 −73
Layout: unified · split
.github/workflows/build.yml added +94
| @@ -0,0 +1,94 @@ | |||
| 1 | name: Build | ||
| 2 | |||
| 3 | # 9201ef0 retired the previous workflow because the accessibility audit it ran | ||
| 4 | # reported findings that did not reproduce locally. That commit also recorded | ||
| 5 | # what went with it: nothing built a clean checkout of the merge result any | ||
| 6 | # more, and DomainDig.xcodeproj uses file-system-synchronized groups, so a | ||
| 7 | # folder missing from a commit still builds on the machine that has it and | ||
| 8 | # breaks for everyone else. The pre-push hook cannot catch that — it runs | ||
| 9 | # against a working tree where the file is still present. | ||
| 10 | # | ||
| 11 | # This restores the compile gate without the audit. -only-testing runs the unit | ||
| 12 | # suite alone; DomainDigUITests, which holds AccessibilityAuditTests, is not | ||
| 13 | # run. The app, widget and share extension are still built, because the scheme | ||
| 14 | # builds them as dependencies — which is the part that was actually missed. | ||
| 15 | on: | ||
| 16 | pull_request: | ||
| 17 | paths-ignore: ['*.md', 'Docs/*.md', '*.txt', 'Docs/*.txt'] | ||
| 18 | workflow_dispatch: | ||
| 19 | |||
| 20 | permissions: | ||
| 21 | contents: read | ||
| 22 | |||
| 23 | concurrency: | ||
| 24 | group: build-${{ github.ref }} | ||
| 25 | cancel-in-progress: true | ||
| 26 | |||
| 27 | jobs: | ||
| 28 | test: | ||
| 29 | name: xcodebuild test | ||
| 30 | # macos-latest still points at macOS 15, which lacks the iOS 26+ SDK this | ||
| 31 | # app is built against. | ||
| 32 | runs-on: macos-26 | ||
| 33 | |||
| 34 | steps: | ||
| 35 | - uses: actions/checkout@v7 | ||
| 36 | |||
| 37 | - name: Show toolchain | ||
| 38 | run: | | ||
| 39 | xcodebuild -version | ||
| 40 | swift --version | ||
| 41 | |||
| 42 | - name: Select simulator | ||
| 43 | id: sim | ||
| 44 | run: | | ||
| 45 | set -euo pipefail | ||
| 46 | |||
| 47 | # Newest available iPhone runtime; "newest" is always at or above the | ||
| 48 | # deployment target, so no floor filtering is needed. | ||
| 49 | selected=$(xcrun simctl list devices available --json \ | ||
| 50 | | jq -c ' | ||
| 51 | [ .devices | to_entries[] | ||
| 52 | | (.key | capture("SimRuntime\\.iOS-(?<maj>[0-9]+)-(?<min>[0-9]+)$")) as $v | ||
| 53 | | (($v.maj | tonumber) * 1000 + ($v.min | tonumber)) as $rank | ||
| 54 | | .value[] | ||
| 55 | | select(.name | startswith("iPhone")) | ||
| 56 | | { rank: $rank, udid: .udid, name: .name, os: "\($v.maj).\($v.min)" } | ||
| 57 | ] | ||
| 58 | | sort_by(.rank, .name) | ||
| 59 | | last | ||
| 60 | ') | ||
| 61 | |||
| 62 | if [ -z "$selected" ] || [ "$selected" = "null" ]; then | ||
| 63 | echo "::error::No iPhone simulator available on this image" | ||
| 64 | xcrun simctl list devices available >&2 | ||
| 65 | exit 1 | ||
| 66 | fi | ||
| 67 | |||
| 68 | label=$(echo "$selected" | jq -r '"\(.name) (iOS \(.os))"') | ||
| 69 | echo "Selected $label" | ||
| 70 | echo "udid=$(echo "$selected" | jq -r .udid)" >> "$GITHUB_OUTPUT" | ||
| 71 | echo "label=$label" >> "$GITHUB_OUTPUT" | ||
| 72 | |||
| 73 | # CODE_SIGNING_ALLOWED=NO builds without a signing identity, which strips | ||
| 74 | # entitlements. OwnerAccess guards CloudKit behind an entitlements check | ||
| 75 | # for exactly that reason — without it the app aborts before its first | ||
| 76 | # screen. | ||
| 77 | - name: Test on ${{ steps.sim.outputs.label }} | ||
| 78 | run: | | ||
| 79 | set -o pipefail | ||
| 80 | xcodebuild test \ | ||
| 81 | -project DomainDig.xcodeproj \ | ||
| 82 | -scheme DomainDig \ | ||
| 83 | -destination "id=${{ steps.sim.outputs.udid }}" \ | ||
| 84 | -only-testing:DomainDigTests \ | ||
| 85 | -resultBundlePath TestResults.xcresult \ | ||
| 86 | CODE_SIGNING_ALLOWED=NO | ||
| 87 | |||
| 88 | - name: Upload results | ||
| 89 | if: failure() | ||
| 90 | uses: actions/upload-artifact@v7 | ||
| 91 | with: | ||
| 92 | name: test-results | ||
| 93 | path: TestResults.xcresult | ||
| 94 | retention-days: 7 | ||
README.nfo deleted −73
| @@ -1,73 +0,0 @@ | |||
| 1 | ┌──────────────────────────────────────────────────────────────┐ | ||
| 2 | │ D O M A I N D I G [ KRZ ] krz.sh │ | ||
| 3 | └──────────────────────────────────────────────────────────────┘ | ||
| 4 | |||
| 5 | WHAT | ||
| 6 | local-first ios domain inspection toolkit. dns, web, ownership, | ||
| 7 | monitoring, reporting, audit. takes a point-in-time snapshot of a | ||
| 8 | domain, normalizes it into a DomainReport, and keeps data on device | ||
| 9 | unless you export, share, or sync it. | ||
| 10 | |||
| 11 | DOES | ||
| 12 | - inspects dns records, email security, tls certs, http headers, | ||
| 13 | redirects, ip geolocation, reachability, open ports, rdap, | ||
| 14 | ownership, subdomains, availability | ||
| 15 | - DomainReport output used by the ui and exports | ||
| 16 | - history snapshots with change summaries, risk scoring, notes | ||
| 17 | - dashboard, watchlist, monitoring, workflows, batch results, | ||
| 18 | integrations, data portability | ||
| 19 | - audit mode: sessions, checklists, reviewer notes, findings, | ||
| 20 | evidence snapshots, timelines, markdown/json/pdf export | ||
| 21 | - backup and restore for tracked domains, history, audit sessions, | ||
| 22 | workflows, monitoring, settings, feature metadata | ||
| 23 | - optional local api for automation-compatible output | ||
| 24 | |||
| 25 | PRIVACY | ||
| 26 | app data lives in on-device storage. network requests go out only | ||
| 27 | to run the checks you asked for or the resolver you configured. no | ||
| 28 | hosted backend required. | ||
| 29 | |||
| 30 | BUILD | ||
| 31 | needs xcode with a current ios sdk and a simulator or device. | ||
| 32 | |||
| 33 | git clone https://github.com/krazywarez/domain-dig.git | ||
| 34 | |||
| 35 | open DomainDig.xcodeproj, pick the DomainDig scheme, build and run. | ||
| 36 | |||
| 37 | build check: | ||
| 38 | |||
| 39 | xcodebuild -project DomainDig.xcodeproj -scheme DomainDig \ | ||
| 40 | -destination 'platform=iOS Simulator,name=iPhone 16' build | ||
| 41 | |||
| 42 | TESTS | ||
| 43 | deterministic core coverage lives in DomainDigTests: | ||
| 44 | |||
| 45 | xcodebuild test -project DomainDig.xcodeproj -scheme DomainDig \ | ||
| 46 | -destination 'platform=iOS Simulator,name=iPhone 16' \ | ||
| 47 | -only-testing:DomainDigTests | ||
| 48 | |||
| 49 | the scheme's test action also runs the DomainDigUITests | ||
| 50 | accessibility audit. | ||
| 51 | |||
| 52 | ./Scripts/audit-a11y.sh # oldest supported + newest | ||
| 53 | ./Scripts/audit-a11y.sh floor # oldest only (~85s) | ||
| 54 | |||
| 55 | findings are reported, not enforced. optional pre-push hook: | ||
| 56 | |||
| 57 | git config core.hooksPath .githooks | ||
| 58 | |||
| 59 | DOCS | ||
| 60 | local api: Docs/local-api.txt | ||
| 61 | data migration: Docs/data-migration.txt | ||
| 62 | accessibility: Docs/ACCESSIBILITY.txt | ||
| 63 | security: SECURITY.txt | ||
| 64 | |||
| 65 | LICENSE | ||
| 66 | 0bsd. see LICENSE. | ||
| 67 | |||
| 68 | CONTACT | ||
| 69 | root@krz.sh | ||
| 70 | |||
| 71 | ┌──────────────────────────────────────────────────────────────┐ | ||
| 72 | │ krz.sh │ | ||
| 73 | └──────────────────────────────────────────────────────────────┘ | ||
README.org added +79
| @@ -0,0 +1,79 @@ | |||
| 1 | #+title: domaindig | ||
| 2 | |||
| 3 | * what | ||
| 4 | local-first ios domain inspection toolkit. dns, web, ownership, | ||
| 5 | monitoring, reporting, audit. takes a point-in-time snapshot of a | ||
| 6 | domain, normalizes it into a DomainReport, and keeps data on device | ||
| 7 | unless you export, share, or sync it. | ||
| 8 | |||
| 9 | * does | ||
| 10 | - inspects dns records, email security, tls certs, http headers, | ||
| 11 | redirects, ip geolocation, reachability, open ports, rdap, | ||
| 12 | ownership, subdomains, availability | ||
| 13 | - DomainReport output used by the ui and exports | ||
| 14 | - history snapshots with change summaries, risk scoring, notes | ||
| 15 | - dashboard, watchlist, monitoring, workflows, batch results, | ||
| 16 | integrations, data portability | ||
| 17 | - audit mode: sessions, checklists, reviewer notes, findings, | ||
| 18 | evidence snapshots, timelines, markdown/json/pdf export | ||
| 19 | - backup and restore for tracked domains, history, audit sessions, | ||
| 20 | workflows, monitoring, settings, feature metadata | ||
| 21 | - optional local api for automation-compatible output | ||
| 22 | |||
| 23 | * privacy | ||
| 24 | app data lives in on-device storage. network requests go out only | ||
| 25 | to run the checks you asked for or the resolver you configured. no | ||
| 26 | hosted backend required. | ||
| 27 | |||
| 28 | * build | ||
| 29 | needs xcode with a current ios sdk and a simulator or device. | ||
| 30 | |||
| 31 | #+begin_src sh | ||
| 32 | git clone https://github.com/krazywarez/domain-dig.git | ||
| 33 | #+end_src | ||
| 34 | |||
| 35 | open DomainDig.xcodeproj, pick the DomainDig scheme, build and run. | ||
| 36 | |||
| 37 | build check: | ||
| 38 | |||
| 39 | #+begin_src sh | ||
| 40 | xcodebuild -project DomainDig.xcodeproj -scheme DomainDig \ | ||
| 41 | -destination 'platform=iOS Simulator,name=iPhone 16' build | ||
| 42 | #+end_src | ||
| 43 | |||
| 44 | * tests | ||
| 45 | deterministic core coverage lives in DomainDigTests: | ||
| 46 | |||
| 47 | #+begin_src sh | ||
| 48 | xcodebuild test -project DomainDig.xcodeproj -scheme DomainDig \ | ||
| 49 | -destination 'platform=iOS Simulator,name=iPhone 16' \ | ||
| 50 | -only-testing:DomainDigTests | ||
| 51 | #+end_src | ||
| 52 | |||
| 53 | the scheme's test action also runs the DomainDigUITests | ||
| 54 | accessibility audit. | ||
| 55 | |||
| 56 | #+begin_src sh | ||
| 57 | ./Scripts/audit-a11y.sh # oldest supported + newest | ||
| 58 | ./Scripts/audit-a11y.sh floor # oldest only (~85s) | ||
| 59 | #+end_src | ||
| 60 | |||
| 61 | findings are reported, not enforced. optional pre-push hook: | ||
| 62 | |||
| 63 | #+begin_src sh | ||
| 64 | git config core.hooksPath .githooks | ||
| 65 | #+end_src | ||
| 66 | |||
| 67 | * docs | ||
| 68 | #+begin_example | ||
| 69 | local api: Docs/local-api.txt | ||
| 70 | data migration: Docs/data-migration.txt | ||
| 71 | accessibility: Docs/ACCESSIBILITY.txt | ||
| 72 | security: SECURITY.txt | ||
| 73 | #+end_example | ||
| 74 | |||
| 75 | * license | ||
| 76 | 0bsd. see LICENSE. | ||
| 77 | |||
| 78 | * contact | ||
| 79 | - root@krz.sh | ||