INNER CODE UNIT · Go

TestReleasePublishRevalidatesRemoteTagBeforePublish

minekube/gate · ci_write_token_isolation_test.go:208

func TestReleasePublishRevalidatesRemoteTagBeforePublish(t *testing.T) {
	workflow, raw := readCIIsolationWorkflowAt(t, trustedReleaseWorkflowPath)
	verify := ciIsolationJob(t, workflow, "verify-release-tag")
	if got := verify.Permissions; len(got) != 1 || got["contents"] != "read" {
		t.Errorf("release tag verification permissions are %v; it must have contents: read only", got)
	}
	if len(verify.Needs) != 1 || verify.Needs[0] != "release-build" {
		t.Errorf("release tag verification needs %v; it must follow release-build", verify.Needs)
	}
	verifyRaw := fmt.Sprint(verify.Steps)
	for _, want := range []string{
		"GH_TOKEN",
		"git/ref/tags/",
		"git/tags/",
		"object.type",
		"tag_sha=",
		"does not match the expected commit",
	} {

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…