fix(ci): assert the release toolchain pins by shape, not by literal value - #1324
Merged
Merged
Conversation
…alue The release-workflow contract required five Renovate-managed values as exact literals. The value therefore lived in two places — the workflow, which Renovate edits, and this gate, which it does not — so every toolchain bump was born red and no rebase could fix it. PR #1298 was blocked on exactly this: Renovate moved the builder image to v1.27.1 and the contract rejected its own real workflow. The gate keeps its purpose. It exists so nobody silently UN-pins the release toolchain, and "pinned to an exact version and a full digest" is a shape a bump satisfies and an un-pinning does not. Seed hit this first and solved it the same way (seed#2622); this ports its require_pin helper.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
scripts/check-release-workflow-contract.shrequired five Renovate-managed values as exact literals. The value therefore lived in two places —release.yml, which Renovate edits, and this gate, which it does not — so every release-toolchain bump was born red and unfixable by a rebase.PR #1298 is blocked on exactly this: Renovate moved the builder image to
v1.27.1, and the contract'sWorkflow Lintjob failed withFAIL: contract rejected the real workflow. Note the shape of that failure — the gate was not catching a regression, it was rejecting the workflow it is supposed to describe.This replaces the five literals with
require_pin, which asserts the shape of each pin. The gate keeps its purpose: it exists so nobody silently un-pins the release toolchain, and "pinned to an exact version and a full digest" is a shape a legitimate bump satisfies and an un-pinning does not.Seed hit this first and solved it the same way — this ports seed's
require_pinhelper and its rationale verbatim, so the two repos' contracts stay readable side by side. Stem was the only repo still carrying literals: seed and trellis are already ongoreleaser-cross v1.27.1onmainand merged their bumps cleanly, which is why only stem's PR went red.Unblocks #1298. Does not itself bump any toolchain version —
release.ymlis untouched.Linked Issue
Related to #1298 (and seed#2622, the sibling finding)
Testing Evidence
RED — the old gate rejects the legitimate
v1.27.1bump that #1298 carries:GREEN — with
require_pin, against the same bumped workflow:The existing self-test still passes in full, including its
unpinned-builder-imagemutant (which substitutes:latest, so the shape regex still rejects it) and its positive case:Because a shape assertion is weaker than a literal, three further mutations confirm the new checks still catch an actual un-pinning — these are the cases the existing mutants do not cover:
Gate green on the unbumped workflow too (
EXIT=0), so this does not depend on #1298 landing first.shellcheck scripts/check-release-workflow-contract.shclean (exit 0).Security and Release Checklist
release.ymlis untouched in this PR.shellcheckclean.