mirror of
https://github.com/DingTalk-Real-AI/dingtalk-workspace-cli.git
synced 2026-09-29 16:57:48 +08:00
fix: preserve release job identity
This commit is contained in:
@@ -1079,7 +1079,7 @@ jobs:
|
||||
retention-days: 1
|
||||
|
||||
verify-darwin-signatures:
|
||||
name: Validate signed runtime package
|
||||
name: Verify Apple Developer ID signatures
|
||||
if: ${{ !cancelled() && needs.release-contract.result == 'success' && needs.release.result == 'success' }}
|
||||
needs: [release-contract, release]
|
||||
runs-on: macos-latest
|
||||
@@ -1103,7 +1103,7 @@ jobs:
|
||||
name: finalized-release-dist
|
||||
path: dist
|
||||
|
||||
- name: Validate packaged runtime
|
||||
- name: Verify finalized Darwin signatures with Apple codesign
|
||||
run: |
|
||||
set -euo pipefail
|
||||
case "$(uname -m)" in
|
||||
|
||||
@@ -224,7 +224,7 @@ required = (
|
||||
"Seal cloud release tag",
|
||||
"release-contract",
|
||||
"Build signed release artifacts",
|
||||
"Validate signed runtime package",
|
||||
"Verify Apple Developer ID signatures",
|
||||
"Publish immutable GitHub Release",
|
||||
"Publish npm and mirrors",
|
||||
"Release delivery gate",
|
||||
@@ -379,7 +379,7 @@ def one_job(name):
|
||||
for name in (
|
||||
"release-contract",
|
||||
"Build signed release artifacts",
|
||||
"Validate signed runtime package",
|
||||
"Verify Apple Developer ID signatures",
|
||||
"Publish immutable GitHub Release",
|
||||
):
|
||||
if one_job(name).get("conclusion") != "success":
|
||||
@@ -543,7 +543,7 @@ def one_job(name):
|
||||
for name in (
|
||||
"release-contract",
|
||||
"Build signed release artifacts",
|
||||
"Validate signed runtime package",
|
||||
"Verify Apple Developer ID signatures",
|
||||
):
|
||||
one_job(name)
|
||||
|
||||
@@ -720,7 +720,7 @@ for job in jobs:
|
||||
done
|
||||
for required_job in \
|
||||
"Build signed release artifacts" \
|
||||
"Validate signed runtime package" \
|
||||
"Verify Apple Developer ID signatures" \
|
||||
"Publish immutable GitHub Release" \
|
||||
"Publish npm and mirrors"; do
|
||||
printf '%s\n' "$passed_jobs" | grep -Fqx "$required_job" || {
|
||||
|
||||
@@ -2189,7 +2189,7 @@ func TestReleaseWorkflowRecoveryReusesGuardedJobs(t *testing.T) {
|
||||
}
|
||||
}
|
||||
if strings.Count(workflow, "name: Build signed release artifacts") != 1 ||
|
||||
strings.Count(workflow, "name: Validate signed runtime package") != 1 ||
|
||||
strings.Count(workflow, "name: Verify Apple Developer ID signatures") != 1 ||
|
||||
strings.Count(workflow, "name: Publish immutable GitHub Release") != 1 ||
|
||||
strings.Count(workflow, "name: Publish npm and mirrors") != 1 {
|
||||
t.Fatal("normal and recovery publication must share one build/sign/publish job graph")
|
||||
|
||||
@@ -1003,7 +1003,7 @@ esac
|
||||
func TestReleaseWorkflowDeliveryJobNamesMatchWorkflow(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
const signedRuntimeJob = "Validate signed runtime package"
|
||||
const signedRuntimeJob = "Verify Apple Developer ID signatures"
|
||||
workflow := readReleaseWorkflow(t)
|
||||
if got := strings.Count(workflow, "name: "+signedRuntimeJob); got != 1 {
|
||||
t.Fatalf("release workflow contains %d %q jobs, want 1", got, signedRuntimeJob)
|
||||
@@ -1020,8 +1020,8 @@ func TestReleaseWorkflowDeliveryJobNamesMatchWorkflow(t *testing.T) {
|
||||
if got := strings.Count(string(verifier), `"`+signedRuntimeJob+`"`); got != 4 {
|
||||
t.Fatalf("delivery verifier contains %d %q requirements, want 4", got, signedRuntimeJob)
|
||||
}
|
||||
if strings.Contains(string(verifier), "Verify Apple Developer ID signatures") {
|
||||
t.Fatal("delivery verifier retains the superseded signed-runtime job name")
|
||||
if strings.Contains(string(verifier), "Validate signed runtime package") {
|
||||
t.Fatal("delivery verifier contains a renamed signed-runtime job")
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1048,7 +1048,7 @@ case "$endpoint" in
|
||||
*/actions/runs/42/jobs*)
|
||||
printf '{"jobs":['
|
||||
printf '{"name":"Build signed release artifacts","status":"completed","conclusion":"success","head_sha":"%s"},' "$WORKFLOW_SHA"
|
||||
printf '{"name":"Validate signed runtime package","status":"completed","conclusion":"success","head_sha":"%s"},' "$WORKFLOW_SHA"
|
||||
printf '{"name":"Verify Apple Developer ID signatures","status":"completed","conclusion":"success","head_sha":"%s"},' "$WORKFLOW_SHA"
|
||||
printf '{"name":"Publish immutable GitHub Release","status":"completed","conclusion":"success","head_sha":"%s"}' "$WORKFLOW_SHA"
|
||||
if [ "${MISSING_CHANNELS:-0}" != 1 ]; then
|
||||
printf ',{"name":"Publish npm and mirrors","status":"completed","conclusion":"success","head_sha":"%s"}' "$WORKFLOW_SHA"
|
||||
@@ -1142,7 +1142,7 @@ required = [
|
||||
"Seal cloud release tag",
|
||||
"release-contract",
|
||||
"Build signed release artifacts",
|
||||
"Validate signed runtime package",
|
||||
"Verify Apple Developer ID signatures",
|
||||
"Publish immutable GitHub Release",
|
||||
"Publish npm and mirrors",
|
||||
"Release delivery gate",
|
||||
@@ -1314,7 +1314,7 @@ commit = os.environ.get("JOB_SHA", os.environ["RELEASE_COMMIT"])
|
||||
core = [
|
||||
"release-contract",
|
||||
"Build signed release artifacts",
|
||||
"Validate signed runtime package",
|
||||
"Verify Apple Developer ID signatures",
|
||||
"Publish immutable GitHub Release",
|
||||
]
|
||||
jobs = [{
|
||||
|
||||
Reference in New Issue
Block a user