mirror of https://github.com/raandree/NTFSSecurity
Browse Source
chore: update the pinned actions with Dependabot and keep pull request runs read-onlypull/112/head
committed by
GitHub
10 changed files with 262 additions and 139 deletions
@ -0,0 +1,19 @@ |
|||
# Keeps the actions of .github/workflows/ci.yml up to date. The workflow pins |
|||
# each action by commit SHA with the version in a comment; Dependabot updates |
|||
# both and opens one pull request a week for all actions. |
|||
version: 2 |
|||
updates: |
|||
- package-ecosystem: github-actions |
|||
directory: / |
|||
schedule: |
|||
interval: weekly |
|||
# Waits a week before it proposes a new release, so that a compromised |
|||
# release is more likely to be found and withdrawn first. |
|||
cooldown: |
|||
default-days: 7 |
|||
commit-message: |
|||
prefix: ci |
|||
groups: |
|||
github-actions: |
|||
patterns: |
|||
- "*" |
|||
@ -1,5 +1,5 @@ |
|||
<?xml version="1.0" encoding="utf-8"?> |
|||
<packages> |
|||
<package id="AlphaFS" version="2.2.6" targetFramework="net452" /> |
|||
<package id="AlphaFS" version="2.2.1" targetFramework="net452" /> |
|||
<package id="System.Management.Automation.dll" version="10.0.10586.0" targetFramework="net452" /> |
|||
</packages> |
|||
@ -0,0 +1,77 @@ |
|||
<# |
|||
Tests repository files that the build and GitHub use, without a build: every packages.config lists the AlphaFS |
|||
version that the projects reference and ship, and Dependabot keeps the actions of the CI workflow up to date. |
|||
#> |
|||
[Diagnostics.CodeAnalysis.SuppressMessageAttribute( |
|||
'PSUseDeclaredVarsMoreThanAssignments', '', Justification = 'Pester shares variables between blocks.' |
|||
)] |
|||
param () |
|||
|
|||
BeforeDiscovery { |
|||
$repositoryPath = Join-Path -Path $PSScriptRoot -ChildPath '..' |
|||
$packageConfigs = foreach ($project in Get-ChildItem -Path $repositoryPath -Filter '*.csproj' -Recurse -Depth 1) { |
|||
$configPath = Join-Path -Path $project.DirectoryName -ChildPath 'packages.config' |
|||
if ((Test-Path -LiteralPath $configPath) -and (Select-String -LiteralPath $configPath -Pattern 'id="AlphaFS"' -Quiet)) { |
|||
@{ Project = $project.Directory.Name; Path = $configPath } |
|||
} |
|||
} |
|||
} |
|||
|
|||
Describe 'NuGet packages of the projects' { |
|||
BeforeAll { |
|||
$repositoryPath = Join-Path -Path $PSScriptRoot -ChildPath '..' |
|||
$projects = Get-ChildItem -Path $repositoryPath -Filter '*.csproj' -Recurse -Depth 1 |
|||
$hintPathVersions = @($projects | Select-String -Pattern 'packages\\AlphaFS\.(\d+\.\d+\.\d+)\\' | |
|||
ForEach-Object -Process { $_.Matches[0].Groups[1].Value } | Sort-Object -Unique) |
|||
} |
|||
|
|||
It 'Should reference one AlphaFS version in the HintPaths of all projects' { |
|||
$hintPathVersions | Should -HaveCount 1 |
|||
} |
|||
|
|||
It 'Should find the packages.config of the three projects that reference AlphaFS' -ForEach @(@{ Configs = $packageConfigs }) { |
|||
$Configs | Should -HaveCount 3 |
|||
} |
|||
|
|||
It 'Should list the AlphaFS version of the HintPaths in <Project>\packages.config' -ForEach $packageConfigs { |
|||
$package = ([xml] (Get-Content -LiteralPath $Path -Raw)).packages.package | |
|||
Where-Object -Property id -EQ -Value 'AlphaFS' |
|||
|
|||
$package.version | Should -BeExactly $hintPathVersions[0] |
|||
} |
|||
} |
|||
|
|||
Describe 'Dependabot configuration' { |
|||
BeforeAll { |
|||
$configPath = Join-Path -Path $PSScriptRoot -ChildPath '..\.github\dependabot.yml' |
|||
$lines = if (Test-Path -LiteralPath $configPath) { Get-Content -LiteralPath $configPath } else { @() } |
|||
$raw = $lines -join "`n" |
|||
$ecosystems = @($lines | Select-String -Pattern '^\s*-\s*package-ecosystem:\s*"?([\w-]+)"?\s*$' | |
|||
ForEach-Object -Process { $_.Matches[0].Groups[1].Value }) |
|||
} |
|||
|
|||
It 'Should exist in the .github folder' { |
|||
$configPath | Should -Exist |
|||
} |
|||
|
|||
It 'Should use version 2 of the format and the root folder of the repository' { |
|||
$lines -match '^version:\s*2\s*$' | Should -HaveCount 1 |
|||
$lines -match '^\s+directory:\s*"?/"?\s*$' | Should -HaveCount 1 |
|||
} |
|||
|
|||
It 'Should update only the actions of the CI workflow' { |
|||
$ecosystems | Should -BeExactly @('github-actions') |
|||
} |
|||
|
|||
It 'Should check for updates every week' { |
|||
$lines -match '^\s+interval:\s*"?weekly"?\s*$' | Should -HaveCount 1 |
|||
} |
|||
|
|||
It 'Should wait at least a week before it proposes a new release' { |
|||
$raw | Should -Match '(?m)^\s+cooldown:\s*\n\s+default-days:\s*([7-9]|[1-9]\d+)\s*$' |
|||
} |
|||
|
|||
It 'Should group all updates into one pull request' { |
|||
$raw | Should -Match '(?m)^\s+groups:\s*\n\s+[\w-]+:\s*\n\s+patterns:\s*\n\s+-\s*["'']\*["'']\s*$' |
|||
} |
|||
} |
|||
Loading…
Reference in new issue