mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-16 09:55:29 +02:00
* feat(cso): add verified audits and replayable repair bundles * fix(cso): harden qualification and setup boundaries * fix(cso): assemble security canaries at runtime * fix(cso): bound release proof and maintenance work Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): require complete evaluation reports Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): replay expired snapshots from supplied source Co-Authored-By: OpenAI Codex <noreply@openai.com> * test(cso): synchronize DNS cancellation assertion Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore(ship): exempt repository owner from liveness proof Co-Authored-By: OpenAI Codex <noreply@openai.com> * test(cso): make recheck retention overlap deterministic Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: bump version and changelog (v1.85.0.0) Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): pass native release gates Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: move release to v1.86.0.0 Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): resolve rechecks by finding Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: move release to v1.87.0.0 Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): pass macOS and Windows release gates Normalize BSD wc output, compare Windows paths by filesystem identity, preserve portable snapshot race coverage, and narrow POSIX-only Windows fixtures. Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): harden native verification gates * fix(cso): refine Windows native diagnostics * test(cso): isolate Windows Git startup failure * test(cso): stabilize Windows native diagnostics * fix(cso): support hardened Git on Windows * fix(cso): close final verification gaps * test(cso): bound cold Docker fixture setup * fix(cso): restore cross-platform free-suite gates --------- Co-authored-by: OpenAI Codex <noreply@openai.com>
25 lines
1007 B
TypeScript
25 lines
1007 B
TypeScript
import { describe, expect, test } from 'bun:test';
|
|
import * as fs from 'fs';
|
|
import * as path from 'path';
|
|
|
|
const template = fs.readFileSync(
|
|
path.join(import.meta.dir, '..', '.github', 'PULL_REQUEST_TEMPLATE.md'),
|
|
'utf8',
|
|
);
|
|
|
|
describe('gstack PR liveness policy', () => {
|
|
test('remembers the authenticated repository-owner exemption', () => {
|
|
expect(template).toContain('Repository owner @garrytan is explicitly exempt');
|
|
expect(template).toContain('gh api user --jq .login');
|
|
expect(template).toMatch(/Git author metadata\s+alone is not sufficient/);
|
|
expect(template).toContain('PR author is @garrytan (owner exemption)');
|
|
});
|
|
|
|
test('retains live GSTACK PR proof for every other contributor', () => {
|
|
expect(template).toContain('required for external contributors');
|
|
expect(template).toContain('All other contributors');
|
|
expect(template).toContain('`GSTACK PR` typed LIVE');
|
|
expect(template).toContain('not drawn,\noverlaid, or edited onto the image');
|
|
});
|
|
});
|