afterhours-shift-manager/tests/shared/test_changelog.py
Adam Moussa 53c85f7eed
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Add changelog-driven releases and App Home tab (#112)
* Add changelog-driven releases and App Home tab

Version the bot continuously from CHANGELOG.md (the single source of
truth for both the version and the staff-readable notes) and surface
changes to users in two ways:

- A new afterhours-release-notifier Lambda posts a "What's New" message
  to the shift channel on minor/major releases (patches stay silent).
- The bot gains an App Home "About" tab showing what it does, the
  command list, and the current version's notes.

release.yaml runs on Deploy success (not release:published — GITHUB_TOKEN
events don't start downstream workflows), checks out the deployed commit,
and tags + publishes a GitHub Release + invokes the notifier. It assumes a
dedicated, boundary-carrying OIDC role scoped to InvokeFunction on the
notifier; the account's cfn role gates role creation on that boundary.
The manual Version Bump workflow is retired. A CI guard enforces that a
CHANGELOG edit is a clean SemVer bump and that the in-package copy matches.

* Harden release workflow and regex against CodeQL findings

Address three code-scanning alerts on the PR:

- Critical (actions/untrusted-checkout): split release.yaml into a
  read-only `prepare` job that checks out and runs repo code, and a
  privileged `publish` job (contents:write + OIDC) that never checks out
  repo code — it tags, releases, and invokes purely through the GitHub
  and AWS APIs. Also assert head_branch == main.
- High x2 (py/polynomial-redos): rewrite the italic and link regexes in
  markdown_to_mrkdwn with possessive quantifiers and exclusive character
  classes so they run in linear time on adversarial input. Adds a
  regression test.

* Move release/announce into Deploy workflow to clear CodeQL

The workflow_run-triggered release.yaml kept tripping CodeQL's
privileged-context rules (untrusted-checkout, then cache-poisoning) —
CodeQL distrusts any workflow_run that checks out a ref, regardless of
the main-only guarantee, and there is no autofix.

Fold the release job into deploy.yaml gated on `needs: deploy`. A
push-to-main run is a trusted context, so checking out and running repo
code with write/OIDC is safe there. This still gates on deploy success
and serializes via the deploy concurrency group, and removes the
separate workflow entirely.
2026-06-11 19:41:31 -04:00

119 lines
3.2 KiB
Python

"""Tests for the CHANGELOG parser — the single source of truth for versioning."""
import pytest
from shared.changelog import (
bump_kind,
entry_for,
is_valid_bump,
latest_entry,
parse_changelog,
top_version,
version_entries,
)
# A faithful slice of the real file: preamble prose, a plain version entry, a
# legacy combined entry, and date-only historical headers with no version.
SAMPLE = """# Changelog
What's changed in the **After-Hours Shift Manager**. Newest first.
Versions are `MAJOR.MINOR.PATCH`.
---
## v1.10.0 — June 11, 2026
**Release notes now announce themselves.** Big new feature line.
## v1.9.2 — June 1, 2026
**Setup-guide fix.** A patch.
## v1.9.0 / v1.9.1 — June 1, 2026
**Last-minute drops blocked.** Combined entry. *(v1.9.1 was a library update.)*
---
## May 2026 — Phone-system automation
- Live phone routing follows the schedule.
## April 3, 2026 — Launch 🎉
The first version.
"""
def test_preamble_is_not_an_entry():
# The "# Changelog" h1 and prose before the first "##" must not parse as entries.
entries = parse_changelog(SAMPLE)
assert all("Changelog" not in e.title for e in entries)
def test_top_version_skips_preamble():
assert top_version(SAMPLE) == "1.10.0"
def test_latest_entry_fields():
entry = latest_entry(SAMPLE)
assert entry.version == "1.10.0"
assert entry.date_label == "June 11, 2026"
assert "announce themselves" in entry.body
def test_combined_header_reports_higher_version():
entry = entry_for(SAMPLE, "1.9.0")
assert entry.versions == ("1.9.0", "1.9.1")
assert entry.version == "1.9.1" # the higher of the two
def test_combined_header_is_findable_by_either_version():
assert entry_for(SAMPLE, "1.9.1") == entry_for(SAMPLE, "v1.9.0")
def test_body_excludes_thematic_break_rules():
# The "---" rule separating eras must not bleed into the combined entry's notes.
assert "---" not in entry_for(SAMPLE, "1.9.0").body
def test_date_only_headers_carry_no_version():
titles = {e.title for e in parse_changelog(SAMPLE) if not e.versions}
assert "May 2026 — Phone-system automation" in titles
assert "April 3, 2026 — Launch 🎉" in titles
def test_version_entries_excludes_date_only():
versions = [e.version for e in version_entries(SAMPLE)]
assert versions == ["1.10.0", "1.9.2", "1.9.1"]
def test_entry_for_accepts_v_prefix():
assert entry_for(SAMPLE, "v1.10.0").version == "1.10.0"
def test_entry_for_unknown_version_is_none():
assert entry_for(SAMPLE, "2.0.0") is None
def test_empty_changelog_has_no_top_version():
assert top_version("# Changelog\n\nNothing yet.\n") is None
assert latest_entry("# Changelog\n") is None
@pytest.mark.parametrize(
"new,prev,expected",
[
("1.10.0", "1.9.2", "minor"), # minor resets patch to 0
("2.0.0", "1.9.2", "major"),
("1.9.3", "1.9.2", "patch"),
("1.11.0", "1.9.2", None), # skips a minor
("1.9.2", "1.9.2", None), # no change
("1.9.1", "1.9.2", None), # downgrade
("3.0.0", "1.9.2", None), # skips a major
],
)
def test_bump_kind(new, prev, expected):
assert bump_kind(new, prev) == expected
assert is_valid_bump(new, prev) is (expected is not None)