flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/services/runner/src/bump.test.ts

78 lines3,632 bytesCodeBlame
1import assert from "node:assert/strict";
2import { test } from "node:test";
3
4import type { BumpArgs } from "@g1t/contracts";
5
6import { bumpEnv, bumpProblem, bumpSandboxName, isSystem, systemActor } from "./bump.ts";
7import { buildHosts } from "./egress.ts";
8
9const PREFIX = "g1t/security/";
10
11const args: BumpArgs = {
12 repo: { namespace: "Acme", name: "site" },
13 ecosystem: "npm",
14 package: "@babel/traverse",
15 version: "7.23.2",
16 lockfiles: ["package-lock.json", "web/package-lock.json"],
17 branch: "g1t/security/babel-traverse-7.23.2",
18 message: "Update @babel/traverse to 7.23.2",
19};
20
21test("a well-formed update can start", () => {
22 assert.equal(bumpProblem(args, PREFIX), null);
23 for (const ecosystem of ["crates.io", "Go", "PyPI"]) {
24 assert.equal(bumpProblem({ ...args, ecosystem }, PREFIX), null, ecosystem);
25 }
26});
27
28test("the branch must be a security update's", () => {
29 for (const branch of ["main", "g1t/security/", "feature/g1t/security/x", "g1t/security/a..b", "g1t/security/a b", "g1t/security/a:b"]) {
30 assert.match(bumpProblem({ ...args, branch }, PREFIX) ?? "", /starts with g1t\/security\//, branch);
31 }
32});
33
34test("names, versions and lockfiles are checked before anything starts", () => {
35 assert.match(bumpProblem({ ...args, ecosystem: "RubyGems" }, PREFIX) ?? "", /cannot update RubyGems/);
36 assert.match(bumpProblem({ ...args, package: "--registry=evil" }, PREFIX) ?? "", /package's name/);
37 assert.match(bumpProblem({ ...args, version: "1.0; rm -rf /" }, PREFIX) ?? "", /version/);
38 assert.match(bumpProblem({ ...args, lockfiles: [] }, PREFIX) ?? "", /between 1 and/);
39 assert.match(bumpProblem({ ...args, lockfiles: ["../Cargo.lock"] }, PREFIX) ?? "", /not a path inside/);
40 assert.match(bumpProblem({ ...args, lockfiles: ["/etc/Cargo.lock"] }, PREFIX) ?? "", /not a path inside/);
41 assert.match(bumpProblem({ ...args, repo: { namespace: "", name: "site" } }, PREFIX) ?? "", /repository/);
42 assert.match(bumpProblem(null, PREFIX) ?? "", /arguments/);
43});
44
45test("g1t acts as itself, a member of the workspace", () => {
46 const actor = systemActor("Acme");
47 assert.deepEqual(actor, { id: "g1t", username: "g1t", kind: "system", verified: true, workspaces: [{ slug: "acme", role: "member" }] });
48 assert.equal(isSystem(actor), true);
49 assert.equal(isSystem({ id: "usr_1", username: "ada" }), false);
50 assert.equal(isSystem(null), false);
51});
52
53test("the sandbox is given what bump mode reads", () => {
54 const env = bumpEnv(args, "main", "g1t_token");
55 assert.deepEqual(env, {
56 MODE: "bump",
57 G1T_USER: "acme",
58 G1T_TOKEN: "g1t_token",
59 GIT_REMOTE: "https://g1t.sh/Acme/site.git",
60 GIT_BRANCH_BASE: "main",
61 GIT_BRANCH: "g1t/security/babel-traverse-7.23.2",
62 BUMP_ECOSYSTEM: "npm",
63 BUMP_PACKAGE: "@babel/traverse",
64 BUMP_VERSION: "7.23.2",
65 BUMP_LOCKFILES: '["package-lock.json","web/package-lock.json"]',
66 COMMIT_MESSAGE: "Update @babel/traverse to 7.23.2",
67 });
68 assert.equal(bumpEnv({ ...args, message: " " }, "main", "t").COMMIT_MESSAGE, "Update @babel/traverse to 7.23.2");
69 assert.equal(bumpSandboxName(args), "bump:acme/site:g1t/security/babel-traverse-7.23.2");
70});
71
72test("a security update reaches the package registries and nothing else builds get", () => {
73 const hosts = buildHosts("bump");
74 for (const host of ["registry.npmjs.org", "repo.yarnpkg.com", "index.crates.io", "static.crates.io", "proxy.golang.org", "sum.golang.org", "pypi.org", "files.pythonhosted.org"]) {
75 assert.ok(hosts.includes(host), host);
76 }
77 for (const host of ["github.com", "api.cloudflare.com", "ghcr.io"]) assert.ok(!hosts.includes(host), host);
78});