INNER CODE UNIT · Go
TestReleaseBuildUsesVerifiedTagCommit
minekube/gate · ci_write_token_isolation_test.go:184
func TestReleaseBuildUsesVerifiedTagCommit(t *testing.T) {
workflow, _ := readCIIsolationWorkflowAt(t, trustedReleaseWorkflowPath)
imageBuild := ciIsolationJob(t, workflow, "image-build")
if got := imageBuild.Outputs["tag_sha"]; got != "${{ steps.verify-tag.outputs.tag_sha }}" {
t.Fatalf("image-build tag_sha output is %q; it must propagate the verified tag commit", got)
}
releaseBuild := ciIsolationJob(t, workflow, "release-build")
if got := releaseBuild.Outputs["tag_sha"]; got != "${{ steps.verify-release.outputs.tag_sha }}" {
t.Fatalf("release-build tag_sha output is %q; it must propagate the revalidated release identity", got)
}
checkoutAt := ciIsolationStepIndex(releaseBuild.Steps, "Checkout the release tag")
if checkoutAt < 0 {
t.Fatal("release-build has no tag checkout")
}
if got := fmt.Sprint(releaseBuild.Steps[checkoutAt].With["ref"]); got != "${{ needs.image-build.outputs.tag_sha }}" {
t.Errorf("release-build checkout ref is %q; it must use the verified tag commit", got)
}