INNER CODE UNIT · Go

TestCISeparatesReleaseBuildFromContentsWrite

minekube/gate · ci_write_token_isolation_test.go:291

func TestCISeparatesReleaseBuildFromContentsWrite(t *testing.T) {
	workflow, _ := readCIIsolationWorkflowAt(t, trustedReleaseWorkflowPath)
	build := ciIsolationJob(t, workflow, "release-build")
	publish := ciIsolationJob(t, workflow, "publish-release")

	if got := publish.Permissions; len(got) != 2 ||
		got["actions"] != "read" || got["contents"] != "write" {
		t.Errorf("release publisher permissions are %v; expected actions: read and contents: write only", got)
	}
	if len(publish.Needs) != 2 || publish.Needs[0] != "release-build" || publish.Needs[1] != "verify-release-tag" {
		t.Errorf("release publisher needs %v; it must await release-build and tag verification", publish.Needs)
	}

	goreleaserAt := -1
	for i, step := range build.Steps {
		if strings.HasPrefix(step.Uses, "goreleaser/goreleaser-action@") {
			goreleaserAt = i
			args := fmt.Sprint(step.With["args"])

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…