Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions e2e/scenarios/14-validate-check.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -36,3 +36,4 @@ steps:
- ".github/manifest.yaml"
- "validate-manifest:"
- "cascade parse-config"
- "token: ${{ github.token }}"
1 change: 1 addition & 0 deletions e2e/scenarios/15-merge-queue.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -35,3 +35,4 @@ steps:
- "merge-queue-validate:"
- "cascade parse-config"
- "cascade --dry-run orchestrate setup"
- "token: ${{ github.token }}"
1 change: 1 addition & 0 deletions e2e/scenarios/16-pr-preview.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -41,3 +41,4 @@ steps:
- "preview:"
- "Plan Preview"
- "--environment staging"
- "token: ${{ github.token }}"
3 changes: 3 additions & 0 deletions internal/generate/drift_check.go
Original file line number Diff line number Diff line change
Expand Up @@ -136,6 +136,9 @@ func (g *DriftCheckGenerator) writeCheckJob(sb *strings.Builder) {
fmt.Fprintf(sb, " uses: stablekernel/cascade/.github/actions/setup-cli@%s\n", g.getCLIRef())
sb.WriteString(" with:\n")
fmt.Fprintf(sb, " version: %s\n", g.config.GetCLIVersion())
// github.token is the built-in Actions token, sufficient to authenticate
// gh release download against the public stablekernel/cascade repository.
sb.WriteString(" token: ${{ github.token }}\n")
sb.WriteString("\n")

// Run verify, capturing stdout/stderr and the exit code without failing the
Expand Down
13 changes: 13 additions & 0 deletions internal/generate/drift_check_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -131,6 +131,19 @@ func TestDriftCheckGenerator_Deterministic(t *testing.T) {
assert.Equal(t, comment1, comment2)
}

// TestDriftCheckGenerator_SetupCLIPassesToken asserts that the setup-cli step
// passes github.token so that gh release download can authenticate on a cold
// tool-cache. Without the token: input the composite action's GH_TOKEN is
// empty and gh exits non-zero.
func TestDriftCheckGenerator_SetupCLIPassesToken(t *testing.T) {
gen := NewDriftCheckGenerator(driftCheckConfig(false), "")
check, err := gen.Generate()
require.NoError(t, err)

assert.Contains(t, check, "token: ${{ github.token }}",
"setup-cli step must pass github.token so gh release download succeeds on a cold cache")
}

// TestDriftCheckGenerator_PinModeSHA proves third-party actions are SHA-pinned
// when pin_mode is sha, matching how cascade pins actions elsewhere.
func TestDriftCheckGenerator_PinModeSHA(t *testing.T) {
Expand Down
3 changes: 3 additions & 0 deletions internal/generate/hotfix.go
Original file line number Diff line number Diff line change
Expand Up @@ -752,6 +752,9 @@ func (g *HotfixGenerator) writeSetupCLI(sb *strings.Builder) {
fmt.Fprintf(sb, " uses: stablekernel/cascade/.github/actions/setup-cli@%s\n", g.getCLIRef())
sb.WriteString(" with:\n")
fmt.Fprintf(sb, " version: %s\n", g.config.GetCLIVersion())
// github.token is the built-in Actions token, sufficient to authenticate
// gh release download against the public stablekernel/cascade repository.
sb.WriteString(" token: ${{ github.token }}\n")
}

// writeFetchEnvBranches emits a step that fetches the env/* branches and tags so
Expand Down
13 changes: 13 additions & 0 deletions internal/generate/hotfix_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -452,6 +452,19 @@ func TestHotfixGenerator_ValidYAML(t *testing.T) {
assert.Contains(t, parsed, "permissions")
}

// TestHotfixGenerator_SetupCLIPassesToken asserts that the setup-cli step
// passes github.token so that gh release download can authenticate on a cold
// tool-cache. Without the token: input the composite action's GH_TOKEN is
// empty and gh exits non-zero.
func TestHotfixGenerator_SetupCLIPassesToken(t *testing.T) {
gen := NewHotfixGenerator(threeEnvHotfixConfig(), "")
content, err := gen.Generate()
require.NoError(t, err)

assert.Contains(t, content, "token: ${{ github.token }}",
"setup-cli step must pass github.token so gh release download succeeds on a cold cache")
}

// TestHotfixGenerator_PinModeSHA confirms third-party action refs route through
// the shared pin helper rather than emitting a raw @v4.
func TestHotfixGenerator_PinModeSHA(t *testing.T) {
Expand Down
3 changes: 3 additions & 0 deletions internal/generate/merge_queue.go
Original file line number Diff line number Diff line change
Expand Up @@ -117,6 +117,9 @@ func (g *MergeQueueGenerator) writeJob(sb *strings.Builder) {
fmt.Fprintf(sb, " uses: stablekernel/cascade/.github/actions/setup-cli@%s\n", g.getCLIRef())
sb.WriteString(" with:\n")
fmt.Fprintf(sb, " version: %s\n", g.config.GetCLIVersion())
// github.token is the built-in Actions token, sufficient to authenticate
// gh release download against the public stablekernel/cascade repository.
sb.WriteString(" token: ${{ github.token }}\n")

// Validity gate: parse-config reports validity in its JSON output rather
// than via exit code, so gate on the parsed result.
Expand Down
17 changes: 17 additions & 0 deletions internal/generate/merge_queue_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -71,6 +71,23 @@ func TestMergeQueueGenerator_Steps(t *testing.T) {
assert.NotContains(t, content, "action: publish")
}

// TestMergeQueueGenerator_SetupCLIPassesToken asserts that the setup-cli step
// passes github.token so that gh release download can authenticate on a cold
// tool-cache. Without the token: input the composite action's GH_TOKEN is
// empty and gh exits non-zero.
func TestMergeQueueGenerator_SetupCLIPassesToken(t *testing.T) {
cfg := &config.TrunkConfig{
TrunkBranch: "main",
MergeQueue: &config.MergeQueueConfig{Enabled: true},
}
gen := NewMergeQueueGenerator(cfg, "")
content, err := gen.Generate()
require.NoError(t, err)

assert.Contains(t, content, "token: ${{ github.token }}",
"setup-cli step must pass github.token so gh release download succeeds on a cold cache")
}

// TestMergeQueueGenerator_PinModeSHA confirms third-party action refs route
// through the shared pin helper rather than emitting a raw @v4.
func TestMergeQueueGenerator_PinModeSHA(t *testing.T) {
Expand Down
4 changes: 4 additions & 0 deletions internal/generate/pr_preview.go
Original file line number Diff line number Diff line change
Expand Up @@ -115,6 +115,10 @@ func (g *PRPreviewGenerator) writeJob(sb *strings.Builder) {
fmt.Fprintf(sb, " uses: stablekernel/cascade/.github/actions/setup-cli@%s\n", g.getCLIRef())
sb.WriteString(" with:\n")
fmt.Fprintf(sb, " version: %s\n", g.config.GetCLIVersion())
// github.token is the built-in Actions token. It is sufficient to
// authenticate gh release download against the public stablekernel/cascade
// repository and requires no adopter configuration.
sb.WriteString(" token: ${{ github.token }}\n")
sb.WriteString("\n")

g.writeValidateStep(sb)
Expand Down
14 changes: 14 additions & 0 deletions internal/generate/pr_preview_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -173,6 +173,20 @@ func TestPRPreviewGenerator_CommentAddsScriptAndPermission(t *testing.T) {
assert.Contains(t, content, "createComment")
}

// TestPRPreviewGenerator_SetupCLIPassesToken asserts that the setup-cli step in
// the generated preview workflow passes the built-in github.token so that
// gh release download can authenticate even on a cold tool-cache. Without the
// token: input the composite action's GH_TOKEN is empty and gh exits non-zero.
func TestPRPreviewGenerator_SetupCLIPassesToken(t *testing.T) {
gen := NewPRPreviewGenerator(prPreviewConfig(false), "")
content, err := gen.Generate()
require.NoError(t, err)

// The setup-cli with: block must carry a token: line.
assert.Contains(t, content, "token: ${{ github.token }}",
"setup-cli step must pass github.token so gh release download succeeds on a cold cache")
}

func TestPRPreviewGenerator_ActionRefsPinUnderSHAMode(t *testing.T) {
cfg := prPreviewConfig(true)
cfg.PinMode = config.PinModeSHA
Expand Down
3 changes: 3 additions & 0 deletions internal/generate/validate_check.go
Original file line number Diff line number Diff line change
Expand Up @@ -112,6 +112,9 @@ func (g *ValidateCheckGenerator) writeJob(sb *strings.Builder) {
fmt.Fprintf(sb, " uses: stablekernel/cascade/.github/actions/setup-cli@%s\n", g.getCLIRef())
sb.WriteString(" with:\n")
fmt.Fprintf(sb, " version: %s\n", g.config.GetCLIVersion())
// github.token is the built-in Actions token, sufficient to authenticate
// gh release download against the public stablekernel/cascade repository.
sb.WriteString(" token: ${{ github.token }}\n")

sb.WriteString(" - name: Validate Manifest\n")
sb.WriteString(" run: |\n")
Expand Down
17 changes: 17 additions & 0 deletions internal/generate/validate_check_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -71,6 +71,23 @@ func TestValidateCheckGenerator_Steps(t *testing.T) {
assert.NotContains(t, content, "createComment")
}

// TestValidateCheckGenerator_SetupCLIPassesToken asserts that the setup-cli
// step passes github.token so that gh release download can authenticate on a
// cold tool-cache. Without the token: input the composite action's GH_TOKEN is
// empty and gh exits non-zero.
func TestValidateCheckGenerator_SetupCLIPassesToken(t *testing.T) {
cfg := &config.TrunkConfig{
TrunkBranch: "main",
ValidateCheck: &config.ValidateCheckConfig{Enabled: true},
}
gen := NewValidateCheckGenerator(cfg, "")
content, err := gen.Generate()
require.NoError(t, err)

assert.Contains(t, content, "token: ${{ github.token }}",
"setup-cli step must pass github.token so gh release download succeeds on a cold cache")
}

// TestValidateCheckGenerator_PinModeSHA confirms third-party action refs route
// through the shared pin helper rather than emitting a raw @v4.
func TestValidateCheckGenerator_PinModeSHA(t *testing.T) {
Expand Down
Loading