Automate policy source freshness and inventory
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 2s
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 2s
This commit is contained in:
parent
78d096bdd5
commit
03a4fab9e0
17 changed files with 1647 additions and 42 deletions
|
|
@ -46,6 +46,8 @@ def _release(root: Path) -> Path:
|
|||
"review_due": "2027-02-18",
|
||||
"canonical_path": "standards/example/v1/index.html",
|
||||
"revision_path": "standards/example/v1/revisions/draft-1/index.html",
|
||||
"source_repo": "canon",
|
||||
"source_path": "canon/standards/example.md",
|
||||
"source_revision": COMMIT,
|
||||
"source_digest": SOURCE_DIGEST,
|
||||
}
|
||||
|
|
@ -54,10 +56,38 @@ def _release(root: Path) -> Path:
|
|||
(build / "publication-manifest.json").write_text(
|
||||
json.dumps(manifest, sort_keys=True) + "\n", encoding="utf-8"
|
||||
)
|
||||
(build / "source-inventory.json").write_text(
|
||||
json.dumps(
|
||||
{
|
||||
"schema_version": "policy-nexus-source-inventory/v1",
|
||||
"source_set_digest": "3" * 64,
|
||||
"repositories": [
|
||||
{"name": "canon", "revision": COMMIT, "source_count": 1}
|
||||
],
|
||||
"sources": [
|
||||
{
|
||||
"source_repo": "canon",
|
||||
"source_path": "canon/standards/example.md",
|
||||
"disposition": "published",
|
||||
"reason": "test",
|
||||
}
|
||||
],
|
||||
},
|
||||
sort_keys=True,
|
||||
)
|
||||
+ "\n",
|
||||
encoding="utf-8",
|
||||
)
|
||||
return build
|
||||
|
||||
|
||||
class ReleaseVerificationTest(unittest.TestCase):
|
||||
def test_release_pipeline_does_not_delete_immutable_revision_tree(self) -> None:
|
||||
makefile = (ROOT / "Makefile").read_text(encoding="utf-8")
|
||||
containerfile = (ROOT / "Containerfile").read_text(encoding="utf-8")
|
||||
self.assertIn("release-build: build release-check", makefile)
|
||||
self.assertNotIn("RUN rm -rf build", containerfile)
|
||||
|
||||
def test_accepts_clean_provenance_and_returns_manifest_digest(self) -> None:
|
||||
with tempfile.TemporaryDirectory() as directory:
|
||||
build = _release(Path(directory))
|
||||
|
|
@ -67,6 +97,7 @@ class ReleaseVerificationTest(unittest.TestCase):
|
|||
).hexdigest()
|
||||
self.assertEqual(expected, evidence["publication_manifest_digest"])
|
||||
self.assertEqual(["example"], evidence["documents"])
|
||||
self.assertEqual("3" * 64, evidence["source_set_digest"])
|
||||
|
||||
def test_rejects_working_tree_source_revision(self) -> None:
|
||||
with tempfile.TemporaryDirectory() as directory:
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue