test: assert release.yml and pre-release.yml stay one pipeline and attach the artifacts docs/releasing.md lists - #268
Conversation
|
Important Held for human review by the hive's ACMM level gate. This PR was opened by the "quality" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the Hive will keep the |
jeefy
left a comment
There was a problem hiding this comment.
Checking that the two workflows stay in sync is useful. About half the file just repeats single values, though, so harmless edits will break it without it catching any real drift.
- Keep the parity checks between the two workflows: waybill pin, action shas in order, identical install/SBOM/sign/rename scripts, and the verify job. Also keep sha256-before-tar, permissions, the attached files vs the documented artifacts, and the version-pattern accept/reject table. Drop assertions that restate one value: the exact
rename.run,prepend.if,release.onandwith.namestrings, theExtract versionecho lines, the--format/--exclude-*/sign-blob --yesflags, step-name lookups like'Create tag', and the error-wording regex. - Drop the
docs/releasing.mdtext checks that aren't compared with anything (theManual (workflow_dispatch)wording and the cosign/gh attestationcommand strings). Take theX.Y.Z-(rc|alpha|beta).Npattern from the workflow's grep pattern instead of hard-coding it. - Don't re-declare
Mapping/Step/Job/Workflow,expression,readorloadYaml; they're copied verbatim fromworkflows.test.tsL32–52.
…tach the artifacts docs/releasing.md lists Signed-off-by: quality <quality@hive.kubestellar.io>
9c4c190 to
5774edb
Compare
|
Addressed all three: kept only the parity checks, sha256-before-tar, permissions, attached-files-vs-doc and the version-pattern table (pattern read from the workflow's grep); dropped every single-value restatement, the error-wording regex ( 🐝 Hive Agent: — hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88 |
|
/kind cleanup |
Test Improvement
__tests__/releaseWorkflows.test.tsfails whenrelease.ymlandpre-release.yml— two hand-mirrored copies of one pipeline — drift apart, or apart from whatdocs/releasing.mdlists:release.yml and pre-release.yml are the same pipeline): same waybill version/sha256 pin, same action shas in the same order in both jobs, identicalInstall waybill/Generate SBOM/Sign SBOM/Rename provenance bundlescripts, same attestation subjects, same verify job apart from the pre-release input check (::error::lines are ignored instead of normalised by regex)sha256sum -cruns beforetar -xzf; top-levelcontents: readand the release job's exact write/id-token/attestations grants; the attached files equal theprow-github-actions-<version>…list parsed out ofdocs/releasing.mdValidate version inputstep and run through an accept/reject tableDropped on review: every assertion that restated one value (
rename.run,prepend.if,release.on,with.name, theExtract versionecho lines, the--format/--exclude-*/sign-blob --yesflags,Create tag/floating-tag step lookups), and thedocs/releasing.mdtext checks not compared with anything (theworkflow_dispatchwording, the cosign/gh attestationcommands, the hard-codedX.Y.Z-(rc|alpha|beta).Nstring). 291 → 131 lines.Mapping/Step/Job/Workflow,expression,read,loadYamlandrootnow live in__tests__/utils/workflowYaml.ts;workflows.test.tsimports them from there instead of declaring them (no behaviour change there: 43 tests still pass).Verification on
main@ a270568:npx eslint,npx vitest run __tests__/releaseWorkflows.test.ts __tests__/workflows.test.ts— 68 pass.Related Issue
Closes #267
Filed by quality agent (hold-gated mode). Human review required.