package pi import ( "os" "path/filepath" "strings" "testing" ) func TestCoreDockerfileBuildsAnIsolatedResolvedPiDependency(t *testing.T) { path := filepath.Join("..", "..", "..", "..", "docker", "core.Dockerfile") contents, err := os.ReadFile(path) if err != nil { t.Fatal(err) } dockerfile := string(contents) for _, required := range []string{ "ARG PI_RUNTIME_PACKAGE_VERSION", "if [ -n \"$PI_RUNTIME_PACKAGE_VERSION\" ]; then", "npm install --package-lock-only --ignore-scripts --omit=dev \"$PI_PACKAGE_NAME@$PI_RUNTIME_PACKAGE_VERSION\"", "npm ci --omit=dev", "test \"$(./node_modules/.bin/pi --version)\" = \"$PI_VERSION\"", } { if !strings.Contains(dockerfile, required) { t.Fatalf("docker/core.Dockerfile does not contain required isolated Pi build contract %q", required) } } if strings.Contains(dockerfile, "COPY docker/pi-runtime/package.json docker/pi-runtime/package-lock.json ./\nRUN npm install @") { t.Fatal("docker/core.Dockerfile mutates the checkout dependency state outside its isolated build stage") } }