Files
ECC/.github/workflows/ito-cli-artifact.yml
T

98 lines
4.2 KiB
YAML

name: Itô CLI Artifact Gate
on:
pull_request:
branches: [main]
paths:
- '.github/workflows/ito-cli-artifact.yml'
- 'scripts/ito.js'
- 'scripts/lib/ito-environment.js'
- 'skills/ito-compute/**'
- 'skills/ito-inference/**'
- 'skills/ito-training/**'
- 'tests/ci/ito-*-skill.test.js'
- 'tests/scripts/ito-cli-bridge.test.js'
push:
branches: [main]
paths:
- '.github/workflows/ito-cli-artifact.yml'
- 'scripts/ito.js'
- 'scripts/lib/ito-environment.js'
- 'skills/ito-compute/**'
- 'skills/ito-inference/**'
- 'skills/ito-training/**'
- 'tests/ci/ito-*-skill.test.js'
- 'tests/scripts/ito-cli-bridge.test.js'
permissions:
contents: read
jobs:
clean-installed-canonical-cli:
name: Clean-installed canonical CLI
runs-on: ubuntu-latest
timeout-minutes: 10
env:
ITO_COMPUTE_CLI_VERSION: ${{ vars.ITO_COMPUTE_CLI_VERSION }}
ITO_COMPUTE_CLI_EXPECTED_INTEGRITY: ${{ vars.ITO_COMPUTE_CLI_EXPECTED_INTEGRITY }}
ITO_COMPUTE_CLI_EXPECTED_PUBLISHER: ${{ vars.ITO_COMPUTE_CLI_EXPECTED_PUBLISHER }}
steps:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- name: Setup Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: '22.x'
registry-url: 'https://registry.npmjs.org'
- name: Verify official release metadata
shell: bash
run: |
set -euo pipefail
: "${ITO_COMPUTE_CLI_VERSION:?Set the reviewed canonical CLI version repository variable}"
: "${ITO_COMPUTE_CLI_EXPECTED_INTEGRITY:?Set the reviewed npm integrity repository variable}"
: "${ITO_COMPUTE_CLI_EXPECTED_PUBLISHER:?Set the reviewed npm publisher repository variable}"
npm view "ito-compute-cli@${ITO_COMPUTE_CLI_VERSION}" \
name version dist.integrity dist.attestations maintainers --json > "${RUNNER_TEMP}/ito-cli-metadata.json"
node - "${RUNNER_TEMP}/ito-cli-metadata.json" <<'NODE'
const fs = require('fs');
const metadata = JSON.parse(fs.readFileSync(process.argv[2], 'utf8'));
if (metadata.name !== 'ito-compute-cli') throw new Error('unexpected npm package name');
if (metadata.version !== process.env.ITO_COMPUTE_CLI_VERSION) throw new Error('unexpected npm package version');
if (metadata.dist?.integrity !== process.env.ITO_COMPUTE_CLI_EXPECTED_INTEGRITY) throw new Error('npm integrity mismatch');
if (!metadata.dist?.attestations?.url) throw new Error('npm provenance attestation is missing');
const publishers = (metadata.maintainers ?? []).map((entry) => entry.name);
if (!publishers.includes(process.env.ITO_COMPUTE_CLI_EXPECTED_PUBLISHER)) throw new Error('reviewed npm publisher is absent');
NODE
- name: Clean-install and exercise canonical artifact
shell: bash
run: |
set -euo pipefail
install_root="$(mktemp -d)"
npm install --global --prefix "${install_root}" --ignore-scripts --no-audit --no-fund \
"ito-compute-cli@${ITO_COMPUTE_CLI_VERSION}"
executable="${install_root}/lib/node_modules/ito-compute-cli/dist/bin/ito.js"
test -f "${executable}"
set +e
ECC_ITO_CLI_EXECUTABLE="${executable}" node scripts/ecc.js ito auth --json \
> "${RUNNER_TEMP}/ito-auth.stdout" 2> "${RUNNER_TEMP}/ito-auth.stderr"
auth_status=$?
set -e
test "${auth_status}" -eq 3
node - "${RUNNER_TEMP}/ito-auth.stderr" <<'NODE'
const fs = require('fs');
const envelope = JSON.parse(fs.readFileSync(process.argv[2], 'utf8'));
if (envelope.ok !== false || envelope.error?.code !== 'AUTH_REQUIRED') {
throw new Error('clean-installed canonical CLI did not return the expected fail-closed auth envelope');
}
NODE
node --test \
tests/scripts/ito-cli-bridge.test.js \
tests/ci/ito-compute-skill.test.js \
tests/ci/ito-inference-skill.test.js \
tests/ci/ito-training-skill.test.js