Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions .github/inditextech-ci-sync-manifest.json
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@
"creation_year": 2026,
"integrity": {
"algorithm": "hmac-sha256",
"signature": "8cec9dc4b79d3d9cb1def4c57b7f7ee847ea16534c4e4451ac30b9b4f821e655"
"signature": "0e3eba3359012eb8df06afa4bbb44ebdb0778cf75acc8566bdd6f092888b7fcc"
},
"managed_by": "InditexTech CI governance",
"managed_paths": {
Expand All @@ -28,8 +28,8 @@
".github/PULL_REQUEST_TEMPLATE.md": "23a0b0ac79a9020ccac9c013582a01f86e2df2ae7f914673583b9a3368313041",
".github/inditextech-ci-node.json": "72449d1243d714b1ef9bd615e6dc67d0ec0b25f0c73440a08fa34d1e498864ac",
".github/workflows/code-npm_node-PR_verify.yml": "89e11bc8aae9ec44ab47222cc570c27dffb8b426e88665598ea7065a9cc95d54",
".github/workflows/code-npm_node-publish-release-and-snapshot.yml": "e51643d9fbbf5cdcee787e7ceb2fa3b3852868b454becfcc870b34c76a77bcbf",
".github/workflows/code-npm_node-release-core.yml": "3b409b668d51f67bb683b56905d314fd807de32f4f4c46555ce9de4cb3bc3c73",
".github/workflows/code-npm_node-publish-release-and-snapshot.yml": "adf500b9ac304359d560bbeab1176734c8b34b6571c979d80498a7b49064a8c1",
".github/workflows/code-npm_node-release-core.yml": "f58968dc8465418613deffc38d1077ddaed9921de3e64f766113eb78f2df142e",
".github/workflows/code-npm_node-sonarcloud-analysis.yml": "1a4227164d591980b02baddcc0814b735013b162d70cc3909401687287119b5e",
".github/workflows/code-release_preview.yml": "4e2e95d60a498eb12d97ba5c8330b1173f04b02c807140beddad06a6e225b166",
".github/workflows/codeql.yml": "94084661946332025fbc91374dba51e0c82ab53f95de717c491ba63f384fad75",
Expand Down Expand Up @@ -57,6 +57,6 @@
"schema_version": 2,
"source_digests": {
"base": "77bf82cf50d017f83cb2c98448f5abd89c838e085a747c1af3569034f6b38997",
"node": "77af7b2d039e81a4555bf9f299cdeab11fec00d79c54564c9868505862df6f92"
"node": "1540216f127bb4ab46877c3ea2212835327c9af870d055afb1bfbaf82deebfcd"
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -114,6 +114,19 @@ jobs:
github.sha
}}

- name: Betrayal check for comment-authorized snapshot
if: github.event_name == 'issue_comment'
shell: bash
run: |
set -euo pipefail
authorized="${{ needs.authorize.outputs.head_sha }}"
checked="$(git rev-parse HEAD)"
if [[ "$checked" != "$authorized" ]]; then
echo "::error title=Snapshot head race::The pull request advanced since the /publish-snapshot authorization (authorized $authorized, workspace $checked). Aborting before any build or publish."
exit 1
fi
echo "::notice title=Snapshot head verified::Checked-out commit matches the authorized snapshot head."

- name: Plan snapshot
id: plan
env:
Expand Down
36 changes: 30 additions & 6 deletions .github/workflows/code-npm_node-release-core.yml
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,7 @@ jobs:
(
github.event_name == 'pull_request' &&
github.event.pull_request.merged &&
github.event.pull_request.head.repo.full_name == github.repository &&
github.event.pull_request.head.ref != 'automated/ci-governance-sync' &&
!contains(join(github.event.pull_request.labels.*.name, ','), 'skip-release') &&
(
Expand Down Expand Up @@ -127,12 +128,12 @@ jobs:
esac
case "${PACKAGE_MANAGER:-npm}" in
npm)
npm ci
npm ci --ignore-scripts
npm run verify
;;
pnpm)
corepack enable
pnpm install --frozen-lockfile
pnpm install --frozen-lockfile --ignore-scripts
pnpm run verify
;;
*)
Expand All @@ -157,6 +158,7 @@ jobs:
(
github.event_name == 'pull_request' &&
github.event.pull_request.merged &&
github.event.pull_request.head.repo.full_name == github.repository &&
github.event.pull_request.head.ref != 'automated/ci-governance-sync' &&
!contains(join(github.event.pull_request.labels.*.name, ','), 'skip-release') &&
(
Expand Down Expand Up @@ -271,8 +273,8 @@ jobs:
run: |
set -euo pipefail
case "${PACKAGE_MANAGER:-npm}" in
npm) npm ci ;;
pnpm) corepack enable; pnpm install --frozen-lockfile ;;
npm) npm ci --ignore-scripts ;;
pnpm) corepack enable; pnpm install --frozen-lockfile --ignore-scripts ;;
*) echo "::error title=Invalid package manager::PACKAGE_MANAGER must be npm or pnpm."; exit 1 ;;
esac

Expand Down Expand Up @@ -739,10 +741,16 @@ jobs:
env:
HANDOFF_DIR: ${{ runner.temp }}/node-delegated-release-handoff
RELEASES: ${{ steps.delegated-plan.outputs.releases_intermediate }}
AUTHORIZED_COMMIT: ${{ steps.delegated-source.outputs.release_commit }}
working-directory: ${{ env.WORKING_DIRECTORY }}
shell: bash
run: |
set -euo pipefail
workspace_commit="$(git -C "$GITHUB_WORKSPACE" rev-parse HEAD)"
if [[ "$workspace_commit" != "$AUTHORIZED_COMMIT" ]]; then
echo "::error title=Release source race::The workspace commit ($workspace_commit) is not the sealed release source ($AUTHORIZED_COMMIT). Aborting before any packaging."
exit 1
fi
DIST_DIR="$HANDOFF_DIR/tarballs"
RECORDS_FILE="$HANDOFF_DIR/tarballs.jsonl"
rm -rf "$HANDOFF_DIR"
Expand Down Expand Up @@ -1087,6 +1095,22 @@ jobs:
persist-credentials: false
ref: ${{ needs.prepare-release.outputs.release_commit }}

- name: Verify sealed release commit
shell: bash
run: |
set -euo pipefail
expected="${{ needs.prepare-release.outputs.release_commit }}"
workspace="$(git rev-parse HEAD)"
if [[ "$workspace" != "$expected" ]]; then
echo "::error title=Sealed commit mismatch::The publish job checked out $workspace but the sealed release commit is $expected. Aborting."
exit 1
fi
digest="${{ needs.prepare-release.outputs.handoff_digest }}"
if [[ -n "$digest" && ! -f .ci-governance-handoff-digest ]]; then
echo "::error title=Missing handoff digest::The delegated release handoff artifact is absent for digest $digest."
exit 1
fi

- name: Read governed tool versions
id: tool-versions
working-directory: ${{ env.WORKING_DIRECTORY }}
Expand Down Expand Up @@ -1122,7 +1146,7 @@ jobs:
mkdir -p "$DIST_DIR"
case "${PACKAGE_MANAGER:-npm}" in
npm)
npm ci
npm ci --ignore-scripts
npm run build
case "$PROJECT_TYPE" in
single)
Expand All @@ -1141,7 +1165,7 @@ jobs:
;;
pnpm)
corepack enable
pnpm install --frozen-lockfile
pnpm install --frozen-lockfile --ignore-scripts
pnpm run build
case "$PROJECT_TYPE" in
single)
Expand Down
Loading