diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index d502090..6bcb11f 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -194,13 +194,13 @@ jobs: ;; esac METHOD="$(printf '%s' "${REQUEST}" | python3 -c "import json,sys; print(json.load(sys.stdin)['method'])")" - PATH="$(printf '%s' "${REQUEST}" | python3 -c "import json,sys; print(json.load(sys.stdin)['path'])")" + RELEASE_PATH="$(printf '%s' "${REQUEST}" | python3 -c "import json,sys; print(json.load(sys.stdin)['path'])")" PAYLOAD="$(printf '%s' "${REQUEST}" | python3 -c "import json,sys; print(json.dumps(json.load(sys.stdin)['payload']))")" curl --fail --silent --show-error -X "${METHOD}" \ -H "Authorization: token ${GITEA_PUBLISH_TOKEN}" \ -H "Content-Type: application/json" \ -d "${PAYLOAD}" \ - "https://git.bongbetic.com/api/v1/repos/xavierk/Fenris${PATH}" + "https://git.bongbetic.com/api/v1/repos/xavierk/Fenris${RELEASE_PATH}" - name: Attach artifacts to release env: diff --git a/packaging/release-footer.md b/packaging/release-footer.md index 7d67892..2e5294a 100644 --- a/packaging/release-footer.md +++ b/packaging/release-footer.md @@ -11,7 +11,7 @@ sudo zypper install fenris # openSUSE Tumbleweed ## Verify downloads ```bash -gpg --verify SHA256SUMS.asc SHA256SUMS +gpg --output SHA256SUMS --decrypt SHA256SUMS.asc sha256sum -c SHA256SUMS ``` diff --git a/tests/test_changelog.py b/tests/test_changelog.py index e23beb7..18351f6 100644 --- a/tests/test_changelog.py +++ b/tests/test_changelog.py @@ -70,6 +70,15 @@ def test_checked_in_changelog_keeps_unreleased_first_and_categories_limited(): assert set(categories) <= {"Added", "Changed", "Fixed"} +def test_release_footer_verifies_the_clearsigned_checksum_asset(): + footer = (REPO_ROOT / "packaging" / "release-footer.md").read_text( + encoding="utf-8" + ) + + assert "gpg --output SHA256SUMS --decrypt SHA256SUMS.asc" in footer + assert "sha256sum -c SHA256SUMS" in footer + + @pytest.mark.parametrize( ("changelog", "expected_error"), [ diff --git a/tests/test_release.py b/tests/test_release.py index 7943fb3..f5425b0 100644 --- a/tests/test_release.py +++ b/tests/test_release.py @@ -337,6 +337,8 @@ class TestCIWorkflow: "Workflow must make the create-versus-update decision through the request seam" assert '"${METHOD}"' in content, \ "Workflow must execute the helper-selected create-or-update request" + assert 'RELEASE_PATH="$(printf' in content and '\n PATH="$(printf' not in content, \ + "Workflow must not overwrite the shell PATH while preparing the request URL" # ---------------------------------------------------------------------------