diff --git a/.github/inditextech-ci-sync-manifest.json b/.github/inditextech-ci-sync-manifest.json index 64d82ea..3df27dd 100644 --- a/.github/inditextech-ci-sync-manifest.json +++ b/.github/inditextech-ci-sync-manifest.json @@ -17,7 +17,7 @@ "creation_year": 2026, "integrity": { "algorithm": "hmac-sha256", - "signature": "8cec9dc4b79d3d9cb1def4c57b7f7ee847ea16534c4e4451ac30b9b4f821e655" + "signature": "0e3eba3359012eb8df06afa4bbb44ebdb0778cf75acc8566bdd6f092888b7fcc" }, "managed_by": "InditexTech CI governance", "managed_paths": { @@ -28,8 +28,8 @@ ".github/PULL_REQUEST_TEMPLATE.md": "23a0b0ac79a9020ccac9c013582a01f86e2df2ae7f914673583b9a3368313041", ".github/inditextech-ci-node.json": "72449d1243d714b1ef9bd615e6dc67d0ec0b25f0c73440a08fa34d1e498864ac", ".github/workflows/code-npm_node-PR_verify.yml": "89e11bc8aae9ec44ab47222cc570c27dffb8b426e88665598ea7065a9cc95d54", - ".github/workflows/code-npm_node-publish-release-and-snapshot.yml": "e51643d9fbbf5cdcee787e7ceb2fa3b3852868b454becfcc870b34c76a77bcbf", - ".github/workflows/code-npm_node-release-core.yml": "3b409b668d51f67bb683b56905d314fd807de32f4f4c46555ce9de4cb3bc3c73", + ".github/workflows/code-npm_node-publish-release-and-snapshot.yml": "adf500b9ac304359d560bbeab1176734c8b34b6571c979d80498a7b49064a8c1", + ".github/workflows/code-npm_node-release-core.yml": "f58968dc8465418613deffc38d1077ddaed9921de3e64f766113eb78f2df142e", ".github/workflows/code-npm_node-sonarcloud-analysis.yml": "1a4227164d591980b02baddcc0814b735013b162d70cc3909401687287119b5e", ".github/workflows/code-release_preview.yml": "4e2e95d60a498eb12d97ba5c8330b1173f04b02c807140beddad06a6e225b166", ".github/workflows/codeql.yml": "94084661946332025fbc91374dba51e0c82ab53f95de717c491ba63f384fad75", @@ -57,6 +57,6 @@ "schema_version": 2, "source_digests": { "base": "77bf82cf50d017f83cb2c98448f5abd89c838e085a747c1af3569034f6b38997", - "node": "77af7b2d039e81a4555bf9f299cdeab11fec00d79c54564c9868505862df6f92" + "node": "1540216f127bb4ab46877c3ea2212835327c9af870d055afb1bfbaf82deebfcd" } } diff --git a/.github/workflows/code-npm_node-publish-release-and-snapshot.yml b/.github/workflows/code-npm_node-publish-release-and-snapshot.yml index d868d0c..87580c0 100644 --- a/.github/workflows/code-npm_node-publish-release-and-snapshot.yml +++ b/.github/workflows/code-npm_node-publish-release-and-snapshot.yml @@ -114,6 +114,19 @@ jobs: github.sha }} + - name: Betrayal check for comment-authorized snapshot + if: github.event_name == 'issue_comment' + shell: bash + run: | + set -euo pipefail + authorized="${{ needs.authorize.outputs.head_sha }}" + checked="$(git rev-parse HEAD)" + if [[ "$checked" != "$authorized" ]]; then + echo "::error title=Snapshot head race::The pull request advanced since the /publish-snapshot authorization (authorized $authorized, workspace $checked). Aborting before any build or publish." + exit 1 + fi + echo "::notice title=Snapshot head verified::Checked-out commit matches the authorized snapshot head." + - name: Plan snapshot id: plan env: diff --git a/.github/workflows/code-npm_node-release-core.yml b/.github/workflows/code-npm_node-release-core.yml index 8266cf6..82fede1 100644 --- a/.github/workflows/code-npm_node-release-core.yml +++ b/.github/workflows/code-npm_node-release-core.yml @@ -49,6 +49,7 @@ jobs: ( github.event_name == 'pull_request' && github.event.pull_request.merged && + github.event.pull_request.head.repo.full_name == github.repository && github.event.pull_request.head.ref != 'automated/ci-governance-sync' && !contains(join(github.event.pull_request.labels.*.name, ','), 'skip-release') && ( @@ -127,12 +128,12 @@ jobs: esac case "${PACKAGE_MANAGER:-npm}" in npm) - npm ci + npm ci --ignore-scripts npm run verify ;; pnpm) corepack enable - pnpm install --frozen-lockfile + pnpm install --frozen-lockfile --ignore-scripts pnpm run verify ;; *) @@ -157,6 +158,7 @@ jobs: ( github.event_name == 'pull_request' && github.event.pull_request.merged && + github.event.pull_request.head.repo.full_name == github.repository && github.event.pull_request.head.ref != 'automated/ci-governance-sync' && !contains(join(github.event.pull_request.labels.*.name, ','), 'skip-release') && ( @@ -271,8 +273,8 @@ jobs: run: | set -euo pipefail case "${PACKAGE_MANAGER:-npm}" in - npm) npm ci ;; - pnpm) corepack enable; pnpm install --frozen-lockfile ;; + npm) npm ci --ignore-scripts ;; + pnpm) corepack enable; pnpm install --frozen-lockfile --ignore-scripts ;; *) echo "::error title=Invalid package manager::PACKAGE_MANAGER must be npm or pnpm."; exit 1 ;; esac @@ -739,10 +741,16 @@ jobs: env: HANDOFF_DIR: ${{ runner.temp }}/node-delegated-release-handoff RELEASES: ${{ steps.delegated-plan.outputs.releases_intermediate }} + AUTHORIZED_COMMIT: ${{ steps.delegated-source.outputs.release_commit }} working-directory: ${{ env.WORKING_DIRECTORY }} shell: bash run: | set -euo pipefail + workspace_commit="$(git -C "$GITHUB_WORKSPACE" rev-parse HEAD)" + if [[ "$workspace_commit" != "$AUTHORIZED_COMMIT" ]]; then + echo "::error title=Release source race::The workspace commit ($workspace_commit) is not the sealed release source ($AUTHORIZED_COMMIT). Aborting before any packaging." + exit 1 + fi DIST_DIR="$HANDOFF_DIR/tarballs" RECORDS_FILE="$HANDOFF_DIR/tarballs.jsonl" rm -rf "$HANDOFF_DIR" @@ -1087,6 +1095,22 @@ jobs: persist-credentials: false ref: ${{ needs.prepare-release.outputs.release_commit }} + - name: Verify sealed release commit + shell: bash + run: | + set -euo pipefail + expected="${{ needs.prepare-release.outputs.release_commit }}" + workspace="$(git rev-parse HEAD)" + if [[ "$workspace" != "$expected" ]]; then + echo "::error title=Sealed commit mismatch::The publish job checked out $workspace but the sealed release commit is $expected. Aborting." + exit 1 + fi + digest="${{ needs.prepare-release.outputs.handoff_digest }}" + if [[ -n "$digest" && ! -f .ci-governance-handoff-digest ]]; then + echo "::error title=Missing handoff digest::The delegated release handoff artifact is absent for digest $digest." + exit 1 + fi + - name: Read governed tool versions id: tool-versions working-directory: ${{ env.WORKING_DIRECTORY }} @@ -1122,7 +1146,7 @@ jobs: mkdir -p "$DIST_DIR" case "${PACKAGE_MANAGER:-npm}" in npm) - npm ci + npm ci --ignore-scripts npm run build case "$PROJECT_TYPE" in single) @@ -1141,7 +1165,7 @@ jobs: ;; pnpm) corepack enable - pnpm install --frozen-lockfile + pnpm install --frozen-lockfile --ignore-scripts pnpm run build case "$PROJECT_TYPE" in single)