fix(release): execute publication request safely
This commit is contained in:
@@ -194,13 +194,13 @@ jobs:
|
|||||||
;;
|
;;
|
||||||
esac
|
esac
|
||||||
METHOD="$(printf '%s' "${REQUEST}" | python3 -c "import json,sys; print(json.load(sys.stdin)['method'])")"
|
METHOD="$(printf '%s' "${REQUEST}" | python3 -c "import json,sys; print(json.load(sys.stdin)['method'])")"
|
||||||
PATH="$(printf '%s' "${REQUEST}" | python3 -c "import json,sys; print(json.load(sys.stdin)['path'])")"
|
RELEASE_PATH="$(printf '%s' "${REQUEST}" | python3 -c "import json,sys; print(json.load(sys.stdin)['path'])")"
|
||||||
PAYLOAD="$(printf '%s' "${REQUEST}" | python3 -c "import json,sys; print(json.dumps(json.load(sys.stdin)['payload']))")"
|
PAYLOAD="$(printf '%s' "${REQUEST}" | python3 -c "import json,sys; print(json.dumps(json.load(sys.stdin)['payload']))")"
|
||||||
curl --fail --silent --show-error -X "${METHOD}" \
|
curl --fail --silent --show-error -X "${METHOD}" \
|
||||||
-H "Authorization: token ${GITEA_PUBLISH_TOKEN}" \
|
-H "Authorization: token ${GITEA_PUBLISH_TOKEN}" \
|
||||||
-H "Content-Type: application/json" \
|
-H "Content-Type: application/json" \
|
||||||
-d "${PAYLOAD}" \
|
-d "${PAYLOAD}" \
|
||||||
"https://git.bongbetic.com/api/v1/repos/xavierk/Fenris${PATH}"
|
"https://git.bongbetic.com/api/v1/repos/xavierk/Fenris${RELEASE_PATH}"
|
||||||
|
|
||||||
- name: Attach artifacts to release
|
- name: Attach artifacts to release
|
||||||
env:
|
env:
|
||||||
|
|||||||
@@ -11,7 +11,7 @@ sudo zypper install fenris # openSUSE Tumbleweed
|
|||||||
## Verify downloads
|
## Verify downloads
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
gpg --verify SHA256SUMS.asc SHA256SUMS
|
gpg --output SHA256SUMS --decrypt SHA256SUMS.asc
|
||||||
sha256sum -c SHA256SUMS
|
sha256sum -c SHA256SUMS
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|||||||
@@ -70,6 +70,15 @@ def test_checked_in_changelog_keeps_unreleased_first_and_categories_limited():
|
|||||||
assert set(categories) <= {"Added", "Changed", "Fixed"}
|
assert set(categories) <= {"Added", "Changed", "Fixed"}
|
||||||
|
|
||||||
|
|
||||||
|
def test_release_footer_verifies_the_clearsigned_checksum_asset():
|
||||||
|
footer = (REPO_ROOT / "packaging" / "release-footer.md").read_text(
|
||||||
|
encoding="utf-8"
|
||||||
|
)
|
||||||
|
|
||||||
|
assert "gpg --output SHA256SUMS --decrypt SHA256SUMS.asc" in footer
|
||||||
|
assert "sha256sum -c SHA256SUMS" in footer
|
||||||
|
|
||||||
|
|
||||||
@pytest.mark.parametrize(
|
@pytest.mark.parametrize(
|
||||||
("changelog", "expected_error"),
|
("changelog", "expected_error"),
|
||||||
[
|
[
|
||||||
|
|||||||
@@ -337,6 +337,8 @@ class TestCIWorkflow:
|
|||||||
"Workflow must make the create-versus-update decision through the request seam"
|
"Workflow must make the create-versus-update decision through the request seam"
|
||||||
assert '"${METHOD}"' in content, \
|
assert '"${METHOD}"' in content, \
|
||||||
"Workflow must execute the helper-selected create-or-update request"
|
"Workflow must execute the helper-selected create-or-update request"
|
||||||
|
assert 'RELEASE_PATH="$(printf' in content and '\n PATH="$(printf' not in content, \
|
||||||
|
"Workflow must not overwrite the shell PATH while preparing the request URL"
|
||||||
|
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
|
|||||||
Reference in New Issue
Block a user