INNER CODE UNIT · Go

TestReleaseVerificationRequiresRealBuildArtifact

minekube/gate · release_asset_verification_test.go:186

func TestReleaseVerificationRequiresRealBuildArtifact(t *testing.T) {
	steps := readReleaseJobSteps(t)

	verifyAt := stepIndex(steps, verifyAssetsStepName)
	if verifyAt < 0 {
		t.Fatalf("publish-release job is missing the %q step", verifyAssetsStepName)
	}
	script := steps[verifyAt].Run

	// The metadata types that must NOT satisfy the guard on their own.
	for _, excluded := range []string{
		`^checksums\\.txt$`,        // the manifest itself
		`^SHA(256|512)SUMS$`,       // checksum manifests
		`^LICENSE`,                 // license metadata
		`^README`,                  // readme metadata
		`\\.sig$`,                  // detached signatures
		`\\.sigstore\\.json$`,      // signature bundles
		`\\.attest\\.spdx\\.json$`, // SBOM attestations

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…