diff --git a/.github/workflows/publish-workflow-catalog.yml b/.github/workflows/publish-workflow-catalog.yml index 71fac77..0210f5d 100644 --- a/.github/workflows/publish-workflow-catalog.yml +++ b/.github/workflows/publish-workflow-catalog.yml @@ -22,6 +22,15 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: + - name: Validate workflow update token + env: + WORKFLOW_UPDATE_TOKEN: ${{ secrets.WORKFLOW_UPDATE_TOKEN }} + run: | + if [ -z "$WORKFLOW_UPDATE_TOKEN" ]; then + echo "::error::WORKFLOW_UPDATE_TOKEN is not configured. It must have access to the target repositories and permission to create/update pull requests." + exit 1 + fi + - name: Checkout workflow source uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: diff --git a/.github/workflows/sync-consumers.yml b/.github/workflows/sync-consumers.yml index 9a4a1aa..428b58f 100644 --- a/.github/workflows/sync-consumers.yml +++ b/.github/workflows/sync-consumers.yml @@ -26,6 +26,15 @@ jobs: outputs: matrix: ${{ steps.matrix.outputs.matrix }} steps: + - name: Validate workflow update token + env: + WORKFLOW_UPDATE_TOKEN: ${{ secrets.WORKFLOW_UPDATE_TOKEN }} + run: | + if [ -z "$WORKFLOW_UPDATE_TOKEN" ]; then + echo "::error::WORKFLOW_UPDATE_TOKEN is not configured. It must have access to the target repositories and permission to create/update pull requests." + exit 1 + fi + - name: Checkout workflow source uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: diff --git a/tests/test_render_upstream.py b/tests/test_render_upstream.py index 6f017b5..5234f05 100644 --- a/tests/test_render_upstream.py +++ b/tests/test_render_upstream.py @@ -127,6 +127,24 @@ def test_sync_reports_failure_and_continues(self) -> None: self.assertEqual(failed["name"], "broken") self.assertIn("failed to apply", failed["error"]) + def test_failed_patch_preserves_previous_generated_template(self) -> None: + with tempfile.TemporaryDirectory() as directory: + root, manifest = self.fixture(directory) + source = root / "upstream/vendor/example.yml" + source.write_text("name: Changed upstream\n", encoding="utf-8") + destination = root / "workflow-templates/example.yml" + destination.parent.mkdir(parents=True) + destination.write_text("name: Last known good\n", encoding="utf-8") + + report = sync(load_templates(manifest), root) + + self.assertFalse(report["ok"]) + self.assertEqual(report["failed"], 1) + self.assertEqual( + destination.read_text(encoding="utf-8"), + "name: Last known good\n", + ) + def test_write_report(self) -> None: with tempfile.TemporaryDirectory() as directory: report_path = Path(directory) / "report.json" diff --git a/tests/test_sync_catalog.py b/tests/test_sync_catalog.py index b2512e1..556b8d0 100644 --- a/tests/test_sync_catalog.py +++ b/tests/test_sync_catalog.py @@ -104,6 +104,26 @@ def test_requires_custom_svg_icon(self) -> None: ) collect_publishable(source) + def test_invalid_source_does_not_partially_modify_catalog(self) -> None: + with tempfile.TemporaryDirectory() as directory: + root = Path(directory) + source = root / "source" + target = root / "target" + self.write_template(source) + target.mkdir() + existing = target / "reuse.yml" + existing.write_text("name: Published\n", encoding="utf-8") + + (source / "reuse.properties.json").unlink() + + with self.assertRaisesRegex(ValueError, "missing template metadata"): + sync_catalog(source, target) + + self.assertEqual( + existing.read_text(encoding="utf-8"), + "name: Published\n", + ) + def test_check_detects_drift(self) -> None: with tempfile.TemporaryDirectory() as directory: root = Path(directory)