返回 DeepSeek-Reasonix
validate-release-control-plane.sh
根目录 / scripts / validate-release-control-plane.sh
1 #!/usr/bin/env bash
2 set -euo pipefail
3
4 root="${1:-$(git rev-parse --show-toplevel)}"
5 required=(
6 .github/actions/setup-certum/action.yml
7 .github/workflows/release-candidate.yml
8 .github/workflows/release-candidate-verify.yml
9 .github/workflows/release-promote.yml
10 .github/workflows/release-desktop.yml
11 .signpath/contracts/release-signing.yml
12 npm/publish-candidate.mjs
13 scripts/build-release-cli-candidate.mjs
14 scripts/desktop-release-artifacts.mjs
15 scripts/finalize-windows-signed-candidate.sh
16 scripts/install-nsis.ps1
17 scripts/package-windows-desktop.sh
18 scripts/release-candidate.mjs
19 scripts/release-candidate-tags.sh
20 scripts/test-release-control-contracts.sh
21 scripts/reconcile-release-publication.sh
22 scripts/release-publication-ledger.mjs
23 scripts/check-release-public-access.sh
24 scripts/fetch-stable-release-manifest.sh
25 scripts/release-manifest-fetch/main.go
26 scripts/resolve-release-candidate.mjs
27 scripts/sign-certum.ps1
28 scripts/test-windows-installer-startup.ps1
29 scripts/test-windows-startup-recovery.ps1
30 scripts/test-windows-upgrade-startup.ps1
31 scripts/verify-windows-authenticode.ps1
32 scripts/verify-release-authorization.sh
33 scripts/verify-release-artifact-archive.mjs
34 scripts/windows-acceptance-environment.ps1
35 scripts/windows-upgrade-ui-evidence.ps1
36 )
37
38 for file in "${required[@]}"; do
39 if [ ! -s "$root/$file" ]; then
40 echo "missing release control file: $file" >&2
41 exit 1
42 fi
43 done
44
45 for file in \
46 scripts/finalize-windows-signed-candidate.sh \
47 scripts/package-windows-desktop.sh; do
48 if [ ! -x "$root/$file" ]; then
49 echo "release control helper is not executable: $file" >&2
50 exit 1
51 fi
52 done
53
54 node --check "$root/scripts/release-candidate.mjs"
55 node --check "$root/scripts/verify-release-artifact-archive.mjs"
56 node --check "$root/scripts/resolve-release-candidate.mjs"
57 node --check "$root/scripts/build-release-cli-candidate.mjs"
58 node --check "$root/npm/publish-candidate.mjs"
59 bash -n "$root/scripts/finalize-windows-signed-candidate.sh"
60 bash -n "$root/scripts/release-candidate-tags.sh"
61 bash -n "$root/scripts/package-windows-desktop.sh"
62
63 bash "$root/scripts/test-release-control-contracts.sh" "$root"
64 echo "release control preflight: PASS"
65
65 lines BASH