Skip to content

test: assert release.yml and pre-release.yml stay one pipeline and attach the artifacts docs/releasing.md lists - #268

Merged
github-actions[bot] merged 1 commit into
mainfrom
quality/test-release-workflows
Oct 3, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
quality/test-release-workflows

Conversation

@hivecommons-hive

@hivecommons-hive hivecommons-hive Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Test Improvement

__tests__/releaseWorkflows.test.ts fails when release.yml and pre-release.yml — two hand-mirrored copies of one pipeline — drift apart, or apart from what docs/releasing.md lists:

  • parity (release.yml and pre-release.yml are the same pipeline): same waybill version/sha256 pin, same action shas in the same order in both jobs, identical Install waybill / Generate SBOM / Sign SBOM / Rename provenance bundle scripts, same attestation subjects, same verify job apart from the pre-release input check (::error:: lines are ignored instead of normalised by regex)
  • per workflow: sha256sum -c runs before tar -xzf; top-level contents: read and the release job's exact write/id-token/attestations grants; the attached files equal the prow-github-actions-<version>… list parsed out of docs/releasing.md
  • pre-release version input: the grep pattern is taken from the workflow's Validate version input step and run through an accept/reject table

Dropped on review: every assertion that restated one value (rename.run, prepend.if, release.on, with.name, the Extract version echo lines, the --format/--exclude-*/sign-blob --yes flags, Create tag/floating-tag step lookups), and the docs/releasing.md text checks not compared with anything (the workflow_dispatch wording, the cosign/gh attestation commands, the hard-coded X.Y.Z-(rc|alpha|beta).N string). 291 → 131 lines.

Mapping/Step/Job/Workflow, expression, read, loadYaml and root now live in __tests__/utils/workflowYaml.ts; workflows.test.ts imports them from there instead of declaring them (no behaviour change there: 43 tests still pass).

Verification on main @ a270568: npx eslint, npx vitest run __tests__/releaseWorkflows.test.ts __tests__/workflows.test.ts — 68 pass.

Related Issue

Closes #267


Filed by quality agent (hold-gated mode). Human review required.

@hivecommons-hive
hivecommons-hive Bot requested a review from jpmcb as a code owner October 2, 2026 21:01
@hivecommons-hive hivecommons-hive Bot added the hold Indicates that a PR should not merge because someone has issued a /hold command. label Oct 2, 2026
@hivecommons-hive

Copy link
Copy Markdown
Contributor Author

Important

Held for human review by the hive's ACMM level gate.

This PR was opened by the "quality" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the outreach agent is always held because it publishes project-facing communication.

Hive will keep the hold label until a human removes it. Operators can make a deliberate one-off release during an ACMM level change with release_level_holds=true, but level changes never release this hold automatically.

@jeefy jeefy left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checking that the two workflows stay in sync is useful. About half the file just repeats single values, though, so harmless edits will break it without it catching any real drift.

  1. Keep the parity checks between the two workflows: waybill pin, action shas in order, identical install/SBOM/sign/rename scripts, and the verify job. Also keep sha256-before-tar, permissions, the attached files vs the documented artifacts, and the version-pattern accept/reject table. Drop assertions that restate one value: the exact rename.run, prepend.if, release.on and with.name strings, the Extract version echo lines, the --format/--exclude-*/sign-blob --yes flags, step-name lookups like 'Create tag', and the error-wording regex.
  2. Drop the docs/releasing.md text checks that aren't compared with anything (the Manual (workflow_dispatch) wording and the cosign/gh attestation command strings). Take the X.Y.Z-(rc|alpha|beta).N pattern from the workflow's grep pattern instead of hard-coding it.
  3. Don't re-declare Mapping/Step/Job/Workflow, expression, read or loadYaml; they're copied verbatim from workflows.test.ts L32–52.

…tach the artifacts docs/releasing.md lists

Signed-off-by: quality <quality@hive.kubestellar.io>
@hivecommons-hive
hivecommons-hive Bot force-pushed the quality/test-release-workflows branch from 9c4c190 to 5774edb Compare October 3, 2026 05:28
@hivecommons-hive hivecommons-hive Bot added the agent/quality Created by Hive for agent-filed issue provenance label Oct 3, 2026
@hivecommons-hive hivecommons-hive Bot changed the title test: assert release.yml and pre-release.yml run one pipeline and match docs/releasing.md test: assert release.yml and pre-release.yml stay one pipeline and attach the artifacts docs/releasing.md lists Oct 3, 2026
@hivecommons-hive hivecommons-hive Bot added the hive/hosted-available-lke648397-260827-5q9t Created by Hive for agent-filed issue provenance label Oct 3, 2026
@hivecommons-hive

Copy link
Copy Markdown
Contributor Author

Addressed all three: kept only the parity checks, sha256-before-tar, permissions, attached-files-vs-doc and the version-pattern table (pattern read from the workflow's grep); dropped every single-value restatement, the error-wording regex (::error:: lines are filtered instead), and the uncompared doc text checks; the Mapping/Step/Job/Workflow, expression, read, loadYaml declarations moved to __tests__/utils/workflowYaml.ts and workflows.test.ts imports them from there. 291 → 131 lines. Rebased on main @ a270568.


🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: 5774edb

— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

@jeefy jeefy left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Asks addressed, thanks.

@jeefy

jeefy commented Oct 3, 2026

Copy link
Copy Markdown
Member

/kind cleanup
/lgtm
/approve
/hold cancel

@github-actions github-actions Bot added kind/cleanup Categorizes issue or PR as related to cleaning up code, process, or technical debt. lgtm "Looks good to me", indicates that a PR is ready to be merged. and removed hold Indicates that a PR should not merge because someone has issued a /hold command. labels Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agent/quality Created by Hive for agent-filed issue provenance hive/hosted-available-lke648397-260827-5q9t Created by Hive for agent-filed issue provenance kind/cleanup Categorizes issue or PR as related to cleaning up code, process, or technical debt. lgtm "Looks good to me", indicates that a PR is ready to be merged.

Projects

None yet

1 participant