📦 deps(thirdparty): update snapshots
This commit is contained in:
@@ -11,6 +11,7 @@ function readText(relativePath) {
|
||||
const packageJson = JSON.parse(readText("package.json"));
|
||||
const generatedFiles = JSON.parse(readText("tools/config/generated-files.json"));
|
||||
const ciWorkflow = readText(".github/workflows/ci.yml");
|
||||
const canonicalMergeScript = readText("tools/scripts/merge_canonical_sync_pr.cjs");
|
||||
const publishWorkflow = readText(".github/workflows/publish-npm.yml");
|
||||
const releaseWorkflowScript = readText("tools/scripts/release_workflow.js");
|
||||
const hygieneWorkflowPath = path.join(repoRoot, ".github", "workflows", "repo-hygiene.yml");
|
||||
@@ -120,6 +121,11 @@ assert.match(
|
||||
/- name: Run repo-state sync[\s\S]*?run: npm run sync:repo-state/,
|
||||
"main CI should use the unified repo-state sync command",
|
||||
);
|
||||
assert.ok(
|
||||
ciWorkflow.indexOf("- name: Install PR policy dependencies") <
|
||||
ciWorkflow.indexOf("- name: Intake PR change"),
|
||||
"PR policy dependencies must be installed before preflight executes",
|
||||
);
|
||||
assert.match(
|
||||
ciWorkflow,
|
||||
/GH_TOKEN: \$\{\{ github\.token \}\}/,
|
||||
@@ -147,7 +153,7 @@ assert.match(
|
||||
);
|
||||
assert.match(
|
||||
ciWorkflow,
|
||||
/source-validation:[\s\S]*?- name: Fetch base branch[\s\S]*?run: git fetch origin "\$\{\{ github\.base_ref \}\}"/,
|
||||
/source-validation:[\s\S]*?- name: Fetch base branch[\s\S]*?run: git fetch origin "\$\{\{ github\.base_ref \|\| 'main' \}\}"/,
|
||||
"source-validation should fetch the PR base branch before changed-skill README credit checks",
|
||||
);
|
||||
assert.match(
|
||||
@@ -187,8 +193,33 @@ assert.doesNotMatch(
|
||||
);
|
||||
assert.match(
|
||||
ciWorkflow,
|
||||
/git commit -m "chore: sync repo state \[ci skip\]"/,
|
||||
"main CI should keep bot-generated canonical sync commits out of the normal CI loop",
|
||||
/uses: peter-evans\/create-pull-request@[a-f0-9]{40}/,
|
||||
"main CI should publish canonical drift through a pinned pull-request action",
|
||||
);
|
||||
assert.match(
|
||||
ciWorkflow,
|
||||
/branch: automation\/canonical-repo-state/,
|
||||
"main CI should maintain one fixed canonical-sync branch",
|
||||
);
|
||||
assert.doesNotMatch(
|
||||
ciWorkflow,
|
||||
/gh workflow run ci\.yml --ref "\$PR_BRANCH" -f canonical_sync_pr=true/,
|
||||
"canonical checks must remain associated with the pull request",
|
||||
);
|
||||
assert.match(
|
||||
canonicalMergeScript,
|
||||
/actions\/runs\/\$\{run\.id\}\/rerun/,
|
||||
"main CI should restart the PR-associated workflow suppressed for a GITHUB_TOKEN-created PR",
|
||||
);
|
||||
assert.match(
|
||||
ciWorkflow,
|
||||
/- name: Reproduce canonical-sync PR from main[\s\S]*?GH_TOKEN: \$\{\{ github\.token \}\}[\s\S]*?run: npm run sync:repo-state/,
|
||||
"canonical reproducibility should scope a read token to contributor synchronization",
|
||||
);
|
||||
assert.doesNotMatch(
|
||||
ciWorkflow,
|
||||
/git push origin (?:HEAD|main)/,
|
||||
"main CI must not push directly to protected main",
|
||||
);
|
||||
assert.match(
|
||||
ciWorkflow,
|
||||
@@ -237,8 +268,18 @@ assert.match(
|
||||
);
|
||||
assert.match(
|
||||
hygieneWorkflow,
|
||||
/git commit -m "chore: scheduled repo hygiene sync \[ci skip\]"/,
|
||||
"repo hygiene workflow should keep bot-generated sync commits out of the normal CI loop",
|
||||
/uses: peter-evans\/create-pull-request@[a-f0-9]{40}/,
|
||||
"repo hygiene should publish canonical drift through a pinned pull-request action",
|
||||
);
|
||||
assert.doesNotMatch(
|
||||
hygieneWorkflow,
|
||||
/gh workflow run ci\.yml --ref "\$PR_BRANCH" -f canonical_sync_pr=true/,
|
||||
"repo hygiene should use the exact PR-associated workflow instead of a redundant dispatch",
|
||||
);
|
||||
assert.doesNotMatch(
|
||||
hygieneWorkflow,
|
||||
/git push origin (?:HEAD|main)/,
|
||||
"repo hygiene must not push directly to protected main",
|
||||
);
|
||||
assert.match(
|
||||
hygieneWorkflow,
|
||||
@@ -289,6 +330,16 @@ assert.ok(
|
||||
prepareReleaseBlock.indexOf("runReleaseSuite(projectRoot)"),
|
||||
"release preparation should refresh volatile metadata before generating canonical release artifacts",
|
||||
);
|
||||
assert.match(
|
||||
releaseWorkflowScript,
|
||||
/const releaseBranch = `release\/v\$\{version\}`/,
|
||||
"release preparation should use a protected release branch",
|
||||
);
|
||||
assert.doesNotMatch(
|
||||
releaseWorkflowScript,
|
||||
/\["push", "origin", "main"\]/,
|
||||
"release tooling must not push directly to protected main",
|
||||
);
|
||||
assert.match(
|
||||
publishWorkflow,
|
||||
/npm pack --dry-run --json/,
|
||||
|
||||
Reference in New Issue
Block a user