test(infra): expect org workflow pins at v1.0.21

The contract tests still asserted the v1.0.19 SHA after the workflow pin bump, so CI failed on the PyJWT bump PR.
This commit is contained in:
Adam Moussa 2026-10-02 18:06:38 -04:00
parent 228a0861f1
commit 07d43e5113
No known key found for this signature in database

View file

@ -101,7 +101,7 @@ def test_ecs_task_boundary_uses_static_arns():
def test_deploy_api_workflow_exists():
deploy_api = (ROOT / ".github" / "workflows" / "deploy-api.yaml").read_text()
pin = "cd-hcp-fargate.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19"
pin = "cd-hcp-fargate.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21"
assert deploy_api.count(pin) == 2
assert "ssm-prefix: /afterhours-shift-manager/deploy" in deploy_api
assert "docker-platform: linux/arm64" in deploy_api
@ -119,9 +119,9 @@ def test_in_repo_hcptf_roles():
def test_ci_runs_pytest_and_terraform_validate():
assert "ci-python-sam" not in CI
assert "ci-python-app.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19" in CI
assert "ci-terraform.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19" in CI
assert "ci-autofix.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19" in CI
assert "ci-python-app.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21" in CI
assert "ci-terraform.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21" in CI
assert "ci-autofix.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21" in CI
assert "name: ci-complete" in CI
assert "pytest" in CI
assert "terraform fmt -check" not in CI