g1t/services/runner/src/bump.test.ts
| 1 | import assert from "node:assert/strict"; |
| 2 | import { test } from "node:test"; |
| 3 | |
| 4 | import type { BumpArgs } from "@g1t/contracts"; |
| 5 | |
| 6 | import { bumpEnv, bumpProblem, bumpSandboxName, isSystem, systemActor } from "./bump.ts"; |
| 7 | import { buildHosts } from "./egress.ts"; |
| 8 | |
| 9 | const PREFIX = "g1t/security/"; |
| 10 | |
| 11 | const args: BumpArgs = { |
| 12 | repo: { namespace: "Acme", name: "site" }, |
| 13 | ecosystem: "npm", |
| 14 | package: "@babel/traverse", |
| 15 | version: "7.23.2", |
| 16 | lockfiles: ["package-lock.json", "web/package-lock.json"], |
| 17 | branch: "g1t/security/babel-traverse-7.23.2", |
| 18 | message: "Update @babel/traverse to 7.23.2", |
| 19 | }; |
| 20 | |
| 21 | test("a well-formed update can start", () => { |
| 22 | assert.equal(bumpProblem(args, PREFIX), null); |
| 23 | for (const ecosystem of ["crates.io", "Go", "PyPI"]) { |
| 24 | assert.equal(bumpProblem({ ...args, ecosystem }, PREFIX), null, ecosystem); |
| 25 | } |
| 26 | }); |
| 27 | |
| 28 | test("the branch must be a security update's", () => { |
| 29 | for (const branch of ["main", "g1t/security/", "feature/g1t/security/x", "g1t/security/a..b", "g1t/security/a b", "g1t/security/a:b"]) { |
| 30 | assert.match(bumpProblem({ ...args, branch }, PREFIX) ?? "", /starts with g1t\/security\//, branch); |
| 31 | } |
| 32 | }); |
| 33 | |
| 34 | test("names, versions and lockfiles are checked before anything starts", () => { |
| 35 | assert.match(bumpProblem({ ...args, ecosystem: "RubyGems" }, PREFIX) ?? "", /cannot update RubyGems/); |
| 36 | assert.match(bumpProblem({ ...args, package: "--registry=evil" }, PREFIX) ?? "", /package's name/); |
| 37 | assert.match(bumpProblem({ ...args, version: "1.0; rm -rf /" }, PREFIX) ?? "", /version/); |
| 38 | assert.match(bumpProblem({ ...args, lockfiles: [] }, PREFIX) ?? "", /between 1 and/); |
| 39 | assert.match(bumpProblem({ ...args, lockfiles: ["../Cargo.lock"] }, PREFIX) ?? "", /not a path inside/); |
| 40 | assert.match(bumpProblem({ ...args, lockfiles: ["/etc/Cargo.lock"] }, PREFIX) ?? "", /not a path inside/); |
| 41 | assert.match(bumpProblem({ ...args, repo: { namespace: "", name: "site" } }, PREFIX) ?? "", /repository/); |
| 42 | assert.match(bumpProblem(null, PREFIX) ?? "", /arguments/); |
| 43 | }); |
| 44 | |
| 45 | test("g1t acts as itself, a member of the workspace", () => { |
| 46 | const actor = systemActor("Acme"); |
| 47 | assert.deepEqual(actor, { id: "g1t", username: "g1t", kind: "system", verified: true, workspaces: [{ slug: "acme", role: "member" }] }); |
| 48 | assert.equal(isSystem(actor), true); |
| 49 | assert.equal(isSystem({ id: "usr_1", username: "ada" }), false); |
| 50 | assert.equal(isSystem(null), false); |
| 51 | }); |
| 52 | |
| 53 | test("the sandbox is given what bump mode reads", () => { |
| 54 | const env = bumpEnv(args, "main", "g1t_token"); |
| 55 | assert.deepEqual(env, { |
| 56 | MODE: "bump", |
| 57 | G1T_USER: "acme", |
| 58 | G1T_TOKEN: "g1t_token", |
| 59 | GIT_REMOTE: "https://g1t.sh/Acme/site.git", |
| 60 | GIT_BRANCH_BASE: "main", |
| 61 | GIT_BRANCH: "g1t/security/babel-traverse-7.23.2", |
| 62 | BUMP_ECOSYSTEM: "npm", |
| 63 | BUMP_PACKAGE: "@babel/traverse", |
| 64 | BUMP_VERSION: "7.23.2", |
| 65 | BUMP_LOCKFILES: '["package-lock.json","web/package-lock.json"]', |
| 66 | COMMIT_MESSAGE: "Update @babel/traverse to 7.23.2", |
| 67 | }); |
| 68 | assert.equal(bumpEnv({ ...args, message: " " }, "main", "t").COMMIT_MESSAGE, "Update @babel/traverse to 7.23.2"); |
| 69 | assert.equal(bumpSandboxName(args), "bump:acme/site:g1t/security/babel-traverse-7.23.2"); |
| 70 | }); |
| 71 | |
| 72 | test("a security update reaches the package registries and nothing else builds get", () => { |
| 73 | const hosts = buildHosts("bump"); |
| 74 | for (const host of ["registry.npmjs.org", "repo.yarnpkg.com", "index.crates.io", "static.crates.io", "proxy.golang.org", "sum.golang.org", "pypi.org", "files.pythonhosted.org"]) { |
| 75 | assert.ok(hosts.includes(host), host); |
| 76 | } |
| 77 | for (const host of ["github.com", "api.cloudflare.com", "ghcr.io"]) assert.ok(!hosts.includes(host), host); |
| 78 | }); |