fix(ci): isolate npm release configuration
This commit is contained in:
@@ -581,9 +581,15 @@ grep -Fq 'export PYTHONDONTWRITEBYTECODE=1' "$project_root/scripts/verify-schema
|
|||||||
|| fail "release wrapper does not disable Python bytecode"
|
|| fail "release wrapper does not disable Python bytecode"
|
||||||
release_plan="$($gate_bash "$project_root/scripts/verify-schema-v3-only-release.sh" --dry-run)"
|
release_plan="$($gate_bash "$project_root/scripts/verify-schema-v3-only-release.sh" --dry-run)"
|
||||||
first_command="$(printf '%s\n' "$release_plan" | sed -n '1p')"
|
first_command="$(printf '%s\n' "$release_plan" | sed -n '1p')"
|
||||||
|
user_config_command="$(printf '%s\n' "$release_plan" | sed -n '2p')"
|
||||||
|
global_config_command="$(printf '%s\n' "$release_plan" | sed -n '3p')"
|
||||||
bootstrap_command="$(printf '%s\n' "$release_plan" | sed -n '4p')"
|
bootstrap_command="$(printf '%s\n' "$release_plan" | sed -n '4p')"
|
||||||
[[ "$first_command" == 'export PYTHONDONTWRITEBYTECODE=1' ]] \
|
[[ "$first_command" == 'export PYTHONDONTWRITEBYTECODE=1' ]] \
|
||||||
|| fail "release dry-run does not print the Python bytecode export"
|
|| fail "release dry-run does not print the Python bytecode export"
|
||||||
|
[[ "$user_config_command" == 'export NPM_CONFIG_USERCONFIG=<private-empty-user-config>' ]] \
|
||||||
|
|| fail "release dry-run does not isolate npm user configuration"
|
||||||
|
[[ "$global_config_command" == 'export NPM_CONFIG_GLOBALCONFIG=<private-empty-global-config>' ]] \
|
||||||
|
|| fail "release dry-run does not isolate npm global configuration"
|
||||||
[[ "$bootstrap_command" == '/bin/bash scripts/verify-schema-v3-only.sh --bootstrap-trust-only' ]] \
|
[[ "$bootstrap_command" == '/bin/bash scripts/verify-schema-v3-only.sh --bootstrap-trust-only' ]] \
|
||||||
|| fail "release plan does not bootstrap trust before npm"
|
|| fail "release plan does not bootstrap trust before npm"
|
||||||
printf '%s\n' "$release_plan" | grep -Fq '(cd backend && npm ci --ignore-scripts)' \
|
printf '%s\n' "$release_plan" | grep -Fq '(cd backend && npm ci --ignore-scripts)' \
|
||||||
|
|||||||
@@ -3,14 +3,12 @@
|
|||||||
# dependencies come from backend/package-lock.json and dist comes from a clean build.
|
# dependencies come from backend/package-lock.json and dist comes from a clean build.
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
export PYTHONDONTWRITEBYTECODE=1
|
export PYTHONDONTWRITEBYTECODE=1
|
||||||
export NPM_CONFIG_USERCONFIG=/dev/null
|
|
||||||
export NPM_CONFIG_GLOBALCONFIG=/dev/null
|
|
||||||
root="$(cd "$(dirname "$0")/.." && pwd -P)"
|
root="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
if [[ ${1:-} == --dry-run ]]; then
|
if [[ ${1:-} == --dry-run ]]; then
|
||||||
cat <<'EOF'
|
cat <<'EOF'
|
||||||
export PYTHONDONTWRITEBYTECODE=1
|
export PYTHONDONTWRITEBYTECODE=1
|
||||||
export NPM_CONFIG_USERCONFIG=/dev/null
|
export NPM_CONFIG_USERCONFIG=<private-empty-user-config>
|
||||||
export NPM_CONFIG_GLOBALCONFIG=/dev/null
|
export NPM_CONFIG_GLOBALCONFIG=<private-empty-global-config>
|
||||||
/bin/bash scripts/verify-schema-v3-only.sh --bootstrap-trust-only
|
/bin/bash scripts/verify-schema-v3-only.sh --bootstrap-trust-only
|
||||||
(cd backend && npm ci --ignore-scripts)
|
(cd backend && npm ci --ignore-scripts)
|
||||||
(cd backend && npm run build)
|
(cd backend && npm run build)
|
||||||
@@ -21,6 +19,13 @@ EOF
|
|||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
[[ $# -eq 0 ]] || { echo "usage: $0 [--dry-run]" >&2; exit 2; }
|
[[ $# -eq 0 ]] || { echo "usage: $0 [--dry-run]" >&2; exit 2; }
|
||||||
|
release_tmp="$(mktemp -d "${TMPDIR:-/tmp}/thoth-v3-release.XXXXXX")"
|
||||||
|
trap 'rm -rf "$release_tmp"' EXIT HUP INT TERM
|
||||||
|
: >"$release_tmp/npm-userconfig"
|
||||||
|
: >"$release_tmp/npm-globalconfig"
|
||||||
|
chmod 0600 "$release_tmp/npm-userconfig" "$release_tmp/npm-globalconfig"
|
||||||
|
export NPM_CONFIG_USERCONFIG="$release_tmp/npm-userconfig"
|
||||||
|
export NPM_CONFIG_GLOBALCONFIG="$release_tmp/npm-globalconfig"
|
||||||
/bin/bash "$root/scripts/verify-schema-v3-only.sh" --bootstrap-trust-only
|
/bin/bash "$root/scripts/verify-schema-v3-only.sh" --bootstrap-trust-only
|
||||||
(cd "$root/backend" && npm ci --ignore-scripts)
|
(cd "$root/backend" && npm ci --ignore-scripts)
|
||||||
(cd "$root/backend" && npm run build)
|
(cd "$root/backend" && npm run build)
|
||||||
|
|||||||
Reference in New Issue
Block a user