fix(release): execute publication request safely
This commit is contained in:
@@ -70,6 +70,15 @@ def test_checked_in_changelog_keeps_unreleased_first_and_categories_limited():
|
||||
assert set(categories) <= {"Added", "Changed", "Fixed"}
|
||||
|
||||
|
||||
def test_release_footer_verifies_the_clearsigned_checksum_asset():
|
||||
footer = (REPO_ROOT / "packaging" / "release-footer.md").read_text(
|
||||
encoding="utf-8"
|
||||
)
|
||||
|
||||
assert "gpg --output SHA256SUMS --decrypt SHA256SUMS.asc" in footer
|
||||
assert "sha256sum -c SHA256SUMS" in footer
|
||||
|
||||
|
||||
@pytest.mark.parametrize(
|
||||
("changelog", "expected_error"),
|
||||
[
|
||||
|
||||
@@ -337,6 +337,8 @@ class TestCIWorkflow:
|
||||
"Workflow must make the create-versus-update decision through the request seam"
|
||||
assert '"${METHOD}"' in content, \
|
||||
"Workflow must execute the helper-selected create-or-update request"
|
||||
assert 'RELEASE_PATH="$(printf' in content and '\n PATH="$(printf' not in content, \
|
||||
"Workflow must not overwrite the shell PATH while preparing the request URL"
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
Reference in New Issue
Block a user