flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/services/runner/src/bump.test.ts

78 lines3,632 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily1import assert from "node:assert/strict";
2import { test } from "node:test";
3
4import type { BumpArgs } from "@g1t/contracts";
5
6import { bumpEnv, bumpProblem, bumpSandboxName, isSystem, systemActor } from "./bump.ts";
7import { buildHosts } from "./egress.ts";
8
9const PREFIX = "g1t/security/";
10
11const args: BumpArgs = {
12 repo: { namespace: "Acme", name: "site" },
13 ecosystem: "npm",
14 package: "@babel/traverse",
15 version: "7.23.2",
16 lockfiles: ["package-lock.json", "web/package-lock.json"],
17 branch: "g1t/security/babel-traverse-7.23.2",
18 message: "Update @babel/traverse to 7.23.2",
19};
20
21test("a well-formed update can start", () => {
22 assert.equal(bumpProblem(args, PREFIX), null);
23 for (const ecosystem of ["crates.io", "Go", "PyPI"]) {
24 assert.equal(bumpProblem({ ...args, ecosystem }, PREFIX), null, ecosystem);
25 }
26});
27
28test("the branch must be a security update's", () => {
29 for (const branch of ["main", "g1t/security/", "feature/g1t/security/x", "g1t/security/a..b", "g1t/security/a b", "g1t/security/a:b"]) {
30 assert.match(bumpProblem({ ...args, branch }, PREFIX) ?? "", /starts with g1t\/security\//, branch);
31 }
32});
33
34test("names, versions and lockfiles are checked before anything starts", () => {
35 assert.match(bumpProblem({ ...args, ecosystem: "RubyGems" }, PREFIX) ?? "", /cannot update RubyGems/);
36 assert.match(bumpProblem({ ...args, package: "--registry=evil" }, PREFIX) ?? "", /package's name/);
37 assert.match(bumpProblem({ ...args, version: "1.0; rm -rf /" }, PREFIX) ?? "", /version/);
38 assert.match(bumpProblem({ ...args, lockfiles: [] }, PREFIX) ?? "", /between 1 and/);
39 assert.match(bumpProblem({ ...args, lockfiles: ["../Cargo.lock"] }, PREFIX) ?? "", /not a path inside/);
40 assert.match(bumpProblem({ ...args, lockfiles: ["/etc/Cargo.lock"] }, PREFIX) ?? "", /not a path inside/);
41 assert.match(bumpProblem({ ...args, repo: { namespace: "", name: "site" } }, PREFIX) ?? "", /repository/);
42 assert.match(bumpProblem(null, PREFIX) ?? "", /arguments/);
43});
44
45test("g1t acts as itself, a member of the workspace", () => {
46 const actor = systemActor("Acme");
47 assert.deepEqual(actor, { id: "g1t", username: "g1t", kind: "system", verified: true, workspaces: [{ slug: "acme", role: "member" }] });
48 assert.equal(isSystem(actor), true);
49 assert.equal(isSystem({ id: "usr_1", username: "ada" }), false);
50 assert.equal(isSystem(null), false);
51});
52
53test("the sandbox is given what bump mode reads", () => {
54 const env = bumpEnv(args, "main", "g1t_token");
55 assert.deepEqual(env, {
56 MODE: "bump",
57 G1T_USER: "acme",
58 G1T_TOKEN: "g1t_token",
59 GIT_REMOTE: "https://g1t.sh/Acme/site.git",
60 GIT_BRANCH_BASE: "main",
61 GIT_BRANCH: "g1t/security/babel-traverse-7.23.2",
62 BUMP_ECOSYSTEM: "npm",
63 BUMP_PACKAGE: "@babel/traverse",
64 BUMP_VERSION: "7.23.2",
65 BUMP_LOCKFILES: '["package-lock.json","web/package-lock.json"]',
66 COMMIT_MESSAGE: "Update @babel/traverse to 7.23.2",
67 });
68 assert.equal(bumpEnv({ ...args, message: " " }, "main", "t").COMMIT_MESSAGE, "Update @babel/traverse to 7.23.2");
69 assert.equal(bumpSandboxName(args), "bump:acme/site:g1t/security/babel-traverse-7.23.2");
70});
71
72test("a security update reaches the package registries and nothing else builds get", () => {
73 const hosts = buildHosts("bump");
74 for (const host of ["registry.npmjs.org", "repo.yarnpkg.com", "index.crates.io", "static.crates.io", "proxy.golang.org", "sum.golang.org", "pypi.org", "files.pythonhosted.org"]) {
75 assert.ok(hosts.includes(host), host);
76 }
77 for (const host of ["github.com", "api.cloudflare.com", "ghcr.io"]) assert.ok(!hosts.includes(host), host);
78});