openpencil/tools/release-packages/tests/native/draft.test.ts
Danila Poyarkov c4a3dae2a4
ci: unify verified release builds (#711)
* ci: fix desktop build cache ownership

* build: centralize native release artifact validation

Reuse package command execution and npm artifact paths. Share release identity and target metadata, consume explicit Tauri artifact outputs, and reject incomplete or mixed-run artifact sets before draft publication.

* refactor: use release package aliases across directories

* ci: coordinate verified native and npm releases

Build shared frontend inputs once and keep native targets parallel. Bind their complete artifact set to immutable source and workflow revisions, verify updater signatures and attestations, and replace draft assets only after preflight and verified npm publication.

* test: group native release tests by domain
2026-09-16 21:58:38 +03:00

53 lines
1.7 KiB
TypeScript

import { expect, test } from 'bun:test'
import type { ReleaseIdentity } from '#release/native/context'
import { assertDraftReplacement } from '#release/native/draft'
const identity: ReleaseIdentity = {
tag: 'v0.15.0',
sourceCommit: 'a'.repeat(40),
workflowCommit: 'b'.repeat(40),
runId: '123',
runAttempt: '1',
frontendSha256: 'c'.repeat(64)
}
const names = ['release-manifest.json', 'SHA256SUMS', 'installer.exe']
const draft = { id: 123, tag_name: identity.tag, draft: true, assets: [{ name: 'installer.exe' }] }
test('permits creating a draft or replacing its known assets', () => {
expect(() =>
assertDraftReplacement(undefined, names, identity.sourceCommit, identity)
).not.toThrow()
expect(() => assertDraftReplacement(draft, names, identity.sourceCommit, identity)).not.toThrow()
})
test('refuses to modify a published release', () => {
expect(() =>
assertDraftReplacement({ ...draft, draft: false }, names, identity.sourceCommit, identity)
).toThrow('published release')
})
test('refuses a tag moved after artifact construction', () => {
expect(() => assertDraftReplacement(draft, names, 'd'.repeat(40), identity)).toThrow(
'tag changed'
)
})
test('refuses to silently delete unexpected draft assets', () => {
const unexpected = { ...draft, assets: [{ name: 'unrelated.zip' }] }
expect(() => assertDraftReplacement(unexpected, names, identity.sourceCommit, identity)).toThrow(
'unexpected draft assets'
)
})
test.each(['release-manifest.json', 'SHA256SUMS'])('requires %s before publication', (missing) => {
expect(() =>
assertDraftReplacement(
draft,
names.filter((name) => name !== missing),
identity.sourceCommit,
identity
)
).toThrow('Missing release manifest')
})