Commit d911d94
committed
test(srt): guard srt-settings.json against drifting off the pack
Two static checks. The provenance marker check needs no pack checkout so
it always runs; the byte-for-byte drift check needs one and reports SKIP
(exit 93) without it, so a developer machine without the sibling clone
does not go red.
CI now checks out cheshirecode/srt-policy-packs into .srt-policy-packs
and passes SRT_POLICY_PACKS, so the drift check actually runs there. A
check nothing runs is not coverage.
Proved red three ways before landing:
del(._source) -> 2 fail (marker + drift)
allowedDomains += evil.example -> 1 fail (drift), marker still PASS
no pack checkout -> SKIP, 9 pass 0 fail1 parent d7a662d commit d911d94
3 files changed
Lines changed: 30 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
16 | 23 | | |
17 | 24 | | |
18 | 25 | | |
| 26 | + | |
| 27 | + | |
19 | 28 | | |
20 | 29 | | |
21 | 30 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
| 21 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
95 | 95 | | |
96 | 96 | | |
97 | 97 | | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
98 | 118 | | |
99 | 119 | | |
100 | 120 | | |
| |||
0 commit comments