blob: c7ce6ccce1c7efed067670b9c5246684d1243063 [file]
import assert from 'node:assert/strict';
import { readFileSync } from 'node:fs';
import { join } from 'node:path';
import { describe, test } from 'node:test';
const workflowPath = join(import.meta.dirname, '../.github/workflows/asf-source-candidate.yml');
describe('ASF source workflow policy', () => {
test('binds the candidate handoff to the dispatched commit and artifact', () => {
const workflow = readFileSync(workflowPath, 'utf8');
assert.doesNotMatch(workflow, /RELEASE_SHA/);
assert.match(workflow, /ref: \$\{\{ github\.sha \}\}/);
assert.match(workflow, /--revision "\$GITHUB_SHA"/);
assert.match(workflow, /Commit: \\`\$GITHUB_SHA\\`/);
assert.match(workflow, /tar -xzf "\$CANDIDATE_PATH"/);
assert.match(workflow, /npm run check:third-party-notices/);
assert.match(workflow, /npm run check:cli-third-party-notices/);
assert.match(workflow, /npm run check:windows-cargo-notices/);
assert.doesNotMatch(workflow, /rc_number/);
assert.match(workflow, /name: apache-maka-.*-incubating-\$\{\{ github\.sha \}\}-unsigned/);
assert.match(workflow, /\$\{\{ env\.CANDIDATE_PATH \}\}\.sha512/);
assert.match(
workflow,
/RUNBOOK_URL: .*\/blob\/\$\{\{ github\.sha \}\}\/\.github\/ASF_SOURCE_RELEASE\.md/,
);
});
});