g1t/services/runner/src/bump.test.ts
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 1 | import assert from "node:assert/strict"; |
| 2 | import { test } from "node:test"; | |
| 3 | ||
| 4 | import type { BumpArgs } from "@g1t/contracts"; | |
| 5 | ||
| 6 | import { bumpEnv, bumpProblem, bumpSandboxName, isSystem, systemActor } from "./bump.ts"; | |
| 7 | import { buildHosts } from "./egress.ts"; | |
| 8 | ||
| 9 | const PREFIX = "g1t/security/"; | |
| 10 | ||
| 11 | const args: BumpArgs = { | |
| 12 | repo: { namespace: "Acme", name: "site" }, | |
| 13 | ecosystem: "npm", | |
| 14 | package: "@babel/traverse", | |
| 15 | version: "7.23.2", | |
| 16 | lockfiles: ["package-lock.json", "web/package-lock.json"], | |
| 17 | branch: "g1t/security/babel-traverse-7.23.2", | |
| 18 | message: "Update @babel/traverse to 7.23.2", | |
| 19 | }; | |
| 20 | ||
| 21 | test("a well-formed update can start", () => { | |
| 22 | assert.equal(bumpProblem(args, PREFIX), null); | |
| 23 | for (const ecosystem of ["crates.io", "Go", "PyPI"]) { | |
| 24 | assert.equal(bumpProblem({ ...args, ecosystem }, PREFIX), null, ecosystem); | |
| 25 | } | |
| 26 | }); | |
| 27 | ||
| 28 | test("the branch must be a security update's", () => { | |
| 29 | for (const branch of ["main", "g1t/security/", "feature/g1t/security/x", "g1t/security/a..b", "g1t/security/a b", "g1t/security/a:b"]) { | |
| 30 | assert.match(bumpProblem({ ...args, branch }, PREFIX) ?? "", /starts with g1t\/security\//, branch); | |
| 31 | } | |
| 32 | }); | |
| 33 | ||
| 34 | test("names, versions and lockfiles are checked before anything starts", () => { | |
| 35 | assert.match(bumpProblem({ ...args, ecosystem: "RubyGems" }, PREFIX) ?? "", /cannot update RubyGems/); | |
| 36 | assert.match(bumpProblem({ ...args, package: "--registry=evil" }, PREFIX) ?? "", /package's name/); | |
| 37 | assert.match(bumpProblem({ ...args, version: "1.0; rm -rf /" }, PREFIX) ?? "", /version/); | |
| 38 | assert.match(bumpProblem({ ...args, lockfiles: [] }, PREFIX) ?? "", /between 1 and/); | |
| 39 | assert.match(bumpProblem({ ...args, lockfiles: ["../Cargo.lock"] }, PREFIX) ?? "", /not a path inside/); | |
| 40 | assert.match(bumpProblem({ ...args, lockfiles: ["/etc/Cargo.lock"] }, PREFIX) ?? "", /not a path inside/); | |
| 41 | assert.match(bumpProblem({ ...args, repo: { namespace: "", name: "site" } }, PREFIX) ?? "", /repository/); | |
| 42 | assert.match(bumpProblem(null, PREFIX) ?? "", /arguments/); | |
| 43 | }); | |
| 44 | ||
| 45 | test("g1t acts as itself, a member of the workspace", () => { | |
| 46 | const actor = systemActor("Acme"); | |
| 47 | assert.deepEqual(actor, { id: "g1t", username: "g1t", kind: "system", verified: true, workspaces: [{ slug: "acme", role: "member" }] }); | |
| 48 | assert.equal(isSystem(actor), true); | |
| 49 | assert.equal(isSystem({ id: "usr_1", username: "ada" }), false); | |
| 50 | assert.equal(isSystem(null), false); | |
| 51 | }); | |
| 52 | ||
| 53 | test("the sandbox is given what bump mode reads", () => { | |
| 54 | const env = bumpEnv(args, "main", "g1t_token"); | |
| 55 | assert.deepEqual(env, { | |
| 56 | MODE: "bump", | |
| 57 | G1T_USER: "acme", | |
| 58 | G1T_TOKEN: "g1t_token", | |
| 59 | GIT_REMOTE: "https://g1t.sh/Acme/site.git", | |
| 60 | GIT_BRANCH_BASE: "main", | |
| 61 | GIT_BRANCH: "g1t/security/babel-traverse-7.23.2", | |
| 62 | BUMP_ECOSYSTEM: "npm", | |
| 63 | BUMP_PACKAGE: "@babel/traverse", | |
| 64 | BUMP_VERSION: "7.23.2", | |
| 65 | BUMP_LOCKFILES: '["package-lock.json","web/package-lock.json"]', | |
| 66 | COMMIT_MESSAGE: "Update @babel/traverse to 7.23.2", | |
| 67 | }); | |
| 68 | assert.equal(bumpEnv({ ...args, message: " " }, "main", "t").COMMIT_MESSAGE, "Update @babel/traverse to 7.23.2"); | |
| 69 | assert.equal(bumpSandboxName(args), "bump:acme/site:g1t/security/babel-traverse-7.23.2"); | |
| 70 | }); | |
| 71 | ||
| 72 | test("a security update reaches the package registries and nothing else builds get", () => { | |
| 73 | const hosts = buildHosts("bump"); | |
| 74 | for (const host of ["registry.npmjs.org", "repo.yarnpkg.com", "index.crates.io", "static.crates.io", "proxy.golang.org", "sum.golang.org", "pypi.org", "files.pythonhosted.org"]) { | |
| 75 | assert.ok(hosts.includes(host), host); | |
| 76 | } | |
| 77 | for (const host of ["github.com", "api.cloudflare.com", "ghcr.io"]) assert.ok(!hosts.includes(host), host); | |
| 78 | }); |