Files
msd-core/tests/policy-lint-shallow-checkout.test.cjs
Colin cd5db1f8db test(suites): seed security/slow/integration suites via measured retags
Renames (git mv) with all references updated (ci-test-scope RULES,
windows-parity allowlist, test-file-count allowlist, docs in 6 locales):

- 5 scanner tests -> *.security.test.cjs — the 'Run security tests' CI step
  ran zero files since the suite taxonomy landed; it is now honest.
- graphify-auto-update -> *.slow.test.cjs (36s, slowest file in the suite;
  e2e gsd-tools spawns) — runs on full-matrix lanes and push to next.
- installer-migration-install-integration -> *.integration.test.cjs
  (13s; an integration test by its own name).

Coverage gate measured after retags: 88.55% lines (gate 70%).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-09 23:50:41 -04:00

65 lines
2.3 KiB
JavaScript

'use strict';
/**
* Policy test: docs-required.yml and changeset-required.yml must use
* fetch-depth: 50 (NOT fetch-depth: 0) in their checkout steps.
*
* Rationale: both workflows run a lint script that performs a three-dot git diff
* (`git diff --name-only origin/${base}...HEAD`). A full-history clone
* (fetch-depth: 0) is wasteful — depth 50 covers >99% of PRs and is far faster.
* The explicit base-ref fetch step ensures the merge-base is present for the
* three-dot diff. The workflow FAILS CLOSED (lint errors) if the merge-base is
* deeper than 50, which is intentional.
*
* Note: security-scan.yml legitimately uses fetch-depth: 0 and is NOT covered
* by this test (see tests/security-scan.security.test.cjs).
*/
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const PROJECT_ROOT = path.join(__dirname, '..');
const WORKFLOWS = {
'docs-required.yml': path.join(PROJECT_ROOT, '.github', 'workflows', 'docs-required.yml'),
'changeset-required.yml': path.join(
PROJECT_ROOT,
'.github',
'workflows',
'changeset-required.yml',
),
};
for (const [name, workflowPath] of Object.entries(WORKFLOWS)) {
describe(`${name} shallow-checkout policy`, () => {
let content;
test('workflow file exists', () => {
assert.ok(fs.existsSync(workflowPath), `Missing workflow: ${workflowPath}`);
content = fs.readFileSync(workflowPath, 'utf-8');
});
test('checkout uses fetch-depth: 50 (not 0)', () => {
if (!content) content = fs.readFileSync(workflowPath, 'utf-8');
assert.ok(
content.includes('fetch-depth: 50'),
`${name}: checkout must use fetch-depth: 50 (got full-history clone with fetch-depth: 0 or missing)`,
);
assert.ok(
!content.includes('fetch-depth: 0'),
`${name}: fetch-depth: 0 (full-history clone) must be replaced with fetch-depth: 50`,
);
});
test('has explicit base-ref fetch step for three-dot diff merge-base', () => {
if (!content) content = fs.readFileSync(workflowPath, 'utf-8');
assert.ok(
content.includes('Fetch base ref for diff'),
`${name}: must have an explicit "Fetch base ref for diff" step so the three-dot diff has its merge-base`,
);
});
});
}