Harden release source execution
This commit is contained in:
@@ -18,6 +18,29 @@ from govoplan_release.module_directory import ( # noqa: E402
|
||||
|
||||
|
||||
class ReleaseModuleDirectoryTests(unittest.TestCase):
|
||||
def test_signed_catalog_timestamp_makes_derived_files_reproducible(self) -> None:
|
||||
catalog = {
|
||||
"generated_at": "2026-07-22T12:00:00Z",
|
||||
"sequence": 7,
|
||||
"modules": [],
|
||||
}
|
||||
first = module_directory_payloads(
|
||||
catalog_payload=catalog,
|
||||
keyring_payload={},
|
||||
channel="stable",
|
||||
)
|
||||
second = module_directory_payloads(
|
||||
catalog_payload=catalog,
|
||||
keyring_payload={},
|
||||
channel="stable",
|
||||
)
|
||||
|
||||
self.assertEqual(first, second)
|
||||
self.assertEqual(
|
||||
"2026-07-22T12:00:00Z",
|
||||
first[-1][1]["generated_at"],
|
||||
)
|
||||
|
||||
def test_dot_segments_and_noncanonical_ids_never_become_paths(self) -> None:
|
||||
for value in (".", "..", "../escape", "/absolute", "module/child"):
|
||||
with self.subTest(value=value), self.assertRaises(ValueError):
|
||||
|
||||
Reference in New Issue
Block a user