INNER CODE UNIT · Go

TestReleaseBuildUsesVerifiedTagCommit

minekube/gate · ci_write_token_isolation_test.go:184

func TestReleaseBuildUsesVerifiedTagCommit(t *testing.T) {
	workflow, _ := readCIIsolationWorkflowAt(t, trustedReleaseWorkflowPath)
	imageBuild := ciIsolationJob(t, workflow, "image-build")
	if got := imageBuild.Outputs["tag_sha"]; got != "${{ steps.verify-tag.outputs.tag_sha }}" {
		t.Fatalf("image-build tag_sha output is %q; it must propagate the verified tag commit", got)
	}

	releaseBuild := ciIsolationJob(t, workflow, "release-build")
	if got := releaseBuild.Outputs["tag_sha"]; got != "${{ steps.verify-release.outputs.tag_sha }}" {
		t.Fatalf("release-build tag_sha output is %q; it must propagate the revalidated release identity", got)
	}
	checkoutAt := ciIsolationStepIndex(releaseBuild.Steps, "Checkout the release tag")
	if checkoutAt < 0 {
		t.Fatal("release-build has no tag checkout")
	}
	if got := fmt.Sprint(releaseBuild.Steps[checkoutAt].With["ref"]); got != "${{ needs.image-build.outputs.tag_sha }}" {
		t.Errorf("release-build checkout ref is %q; it must use the verified tag commit", got)
	}

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…