release: bridge legacy installations to ForgeFlow-Public
Managed validation / full (pull_request) Successful in 27s
ChatGPT validation / quality (push) Successful in 21m36s

This commit is contained in:
NuklearRabbit committed 2026-09-30 23:02:50 +02:00
1 parent 1192d75d15
commit 8769f07539
16 files changed
+339 -222

No files matched your search

+27
View File
@@ -118,6 +118,33 @@ test("update repository parts reject path injection", async () => {
await rm(temp, { recursive: true, force: true });
});
test("packaged updates pin the published release commit despite later source-only changes", async (t) => {
const temp = await mkdtemp(path.join(os.tmpdir(), "forgeflow-release-check-"));
t.after(() => rm(temp, { recursive: true, force: true }));
const releaseCommit = "b".repeat(40);
const service = new UpdateService({
store: { data: { updates: {} }, save: async () => {} },
gitea: {
async getLatestRelease(owner, repo) {
assert.equal(repo, "ForgeFlow-Public");
return { tag_name: "v0.10.16", target_commitish: releaseCommit, draft: false, prerelease: false };
},
async getBranch() { throw new Error("Packaged updates must not follow mutable main."); },
async getRepositoryFile(input) {
assert.equal(input.ref, releaseCommit);
return { decoded: JSON.stringify({ name: "forgeflow", version: "0.10.16" }) };
},
},
appInfo: { version: "0.10.14", packaged: true },
sourcePath: temp,
userDataPath: temp,
});
const result = await service.check();
assert.equal(result.available, true);
assert.equal(result.remoteSha, releaseCommit);
assert.equal(result.releaseTag, "v0.10.16");
});
test("source updater refuses an unsigned archive before launching a helper", async () => {
const temp = await mkdtemp(
path.join(os.tmpdir(), "forgeflow-update-handshake-"),