mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 18:23:12 +00:00
* Add changelog-driven releases and App Home tab Version the bot continuously from CHANGELOG.md (the single source of truth for both the version and the staff-readable notes) and surface changes to users in two ways: - A new afterhours-release-notifier Lambda posts a "What's New" message to the shift channel on minor/major releases (patches stay silent). - The bot gains an App Home "About" tab showing what it does, the command list, and the current version's notes. release.yaml runs on Deploy success (not release:published — GITHUB_TOKEN events don't start downstream workflows), checks out the deployed commit, and tags + publishes a GitHub Release + invokes the notifier. It assumes a dedicated, boundary-carrying OIDC role scoped to InvokeFunction on the notifier; the account's cfn role gates role creation on that boundary. The manual Version Bump workflow is retired. A CI guard enforces that a CHANGELOG edit is a clean SemVer bump and that the in-package copy matches. * Harden release workflow and regex against CodeQL findings Address three code-scanning alerts on the PR: - Critical (actions/untrusted-checkout): split release.yaml into a read-only `prepare` job that checks out and runs repo code, and a privileged `publish` job (contents:write + OIDC) that never checks out repo code — it tags, releases, and invokes purely through the GitHub and AWS APIs. Also assert head_branch == main. - High x2 (py/polynomial-redos): rewrite the italic and link regexes in markdown_to_mrkdwn with possessive quantifiers and exclusive character classes so they run in linear time on adversarial input. Adds a regression test. * Move release/announce into Deploy workflow to clear CodeQL The workflow_run-triggered release.yaml kept tripping CodeQL's privileged-context rules (untrusted-checkout, then cache-poisoning) — CodeQL distrusts any workflow_run that checks out a ref, regardless of the main-only guarantee, and there is no autofix. Fold the release job into deploy.yaml gated on `needs: deploy`. A push-to-main run is a trusted context, so checking out and running repo code with write/OIDC is safe there. This still gates on deploy success and serializes via the deploy concurrency group, and removes the separate workflow entirely.
119 lines
3.2 KiB
Python
119 lines
3.2 KiB
Python
"""Tests for the CHANGELOG parser — the single source of truth for versioning."""
|
|
|
|
import pytest
|
|
|
|
from shared.changelog import (
|
|
bump_kind,
|
|
entry_for,
|
|
is_valid_bump,
|
|
latest_entry,
|
|
parse_changelog,
|
|
top_version,
|
|
version_entries,
|
|
)
|
|
|
|
# A faithful slice of the real file: preamble prose, a plain version entry, a
|
|
# legacy combined entry, and date-only historical headers with no version.
|
|
SAMPLE = """# Changelog
|
|
|
|
What's changed in the **After-Hours Shift Manager**. Newest first.
|
|
|
|
Versions are `MAJOR.MINOR.PATCH`.
|
|
|
|
---
|
|
|
|
## v1.10.0 — June 11, 2026
|
|
|
|
**Release notes now announce themselves.** Big new feature line.
|
|
|
|
## v1.9.2 — June 1, 2026
|
|
|
|
**Setup-guide fix.** A patch.
|
|
|
|
## v1.9.0 / v1.9.1 — June 1, 2026
|
|
|
|
**Last-minute drops blocked.** Combined entry. *(v1.9.1 was a library update.)*
|
|
|
|
---
|
|
|
|
## May 2026 — Phone-system automation
|
|
|
|
- Live phone routing follows the schedule.
|
|
|
|
## April 3, 2026 — Launch 🎉
|
|
|
|
The first version.
|
|
"""
|
|
|
|
|
|
def test_preamble_is_not_an_entry():
|
|
# The "# Changelog" h1 and prose before the first "##" must not parse as entries.
|
|
entries = parse_changelog(SAMPLE)
|
|
assert all("Changelog" not in e.title for e in entries)
|
|
|
|
|
|
def test_top_version_skips_preamble():
|
|
assert top_version(SAMPLE) == "1.10.0"
|
|
|
|
|
|
def test_latest_entry_fields():
|
|
entry = latest_entry(SAMPLE)
|
|
assert entry.version == "1.10.0"
|
|
assert entry.date_label == "June 11, 2026"
|
|
assert "announce themselves" in entry.body
|
|
|
|
|
|
def test_combined_header_reports_higher_version():
|
|
entry = entry_for(SAMPLE, "1.9.0")
|
|
assert entry.versions == ("1.9.0", "1.9.1")
|
|
assert entry.version == "1.9.1" # the higher of the two
|
|
|
|
|
|
def test_combined_header_is_findable_by_either_version():
|
|
assert entry_for(SAMPLE, "1.9.1") == entry_for(SAMPLE, "v1.9.0")
|
|
|
|
|
|
def test_body_excludes_thematic_break_rules():
|
|
# The "---" rule separating eras must not bleed into the combined entry's notes.
|
|
assert "---" not in entry_for(SAMPLE, "1.9.0").body
|
|
|
|
|
|
def test_date_only_headers_carry_no_version():
|
|
titles = {e.title for e in parse_changelog(SAMPLE) if not e.versions}
|
|
assert "May 2026 — Phone-system automation" in titles
|
|
assert "April 3, 2026 — Launch 🎉" in titles
|
|
|
|
|
|
def test_version_entries_excludes_date_only():
|
|
versions = [e.version for e in version_entries(SAMPLE)]
|
|
assert versions == ["1.10.0", "1.9.2", "1.9.1"]
|
|
|
|
|
|
def test_entry_for_accepts_v_prefix():
|
|
assert entry_for(SAMPLE, "v1.10.0").version == "1.10.0"
|
|
|
|
|
|
def test_entry_for_unknown_version_is_none():
|
|
assert entry_for(SAMPLE, "2.0.0") is None
|
|
|
|
|
|
def test_empty_changelog_has_no_top_version():
|
|
assert top_version("# Changelog\n\nNothing yet.\n") is None
|
|
assert latest_entry("# Changelog\n") is None
|
|
|
|
|
|
@pytest.mark.parametrize(
|
|
"new,prev,expected",
|
|
[
|
|
("1.10.0", "1.9.2", "minor"), # minor resets patch to 0
|
|
("2.0.0", "1.9.2", "major"),
|
|
("1.9.3", "1.9.2", "patch"),
|
|
("1.11.0", "1.9.2", None), # skips a minor
|
|
("1.9.2", "1.9.2", None), # no change
|
|
("1.9.1", "1.9.2", None), # downgrade
|
|
("3.0.0", "1.9.2", None), # skips a major
|
|
],
|
|
)
|
|
def test_bump_kind(new, prev, expected):
|
|
assert bump_kind(new, prev) == expected
|
|
assert is_valid_bump(new, prev) is (expected is not None)
|