diff --git a/.github/workflows/test-action.yaml b/.github/workflows/test-action.yaml index 78bc09a..cf8be70 100644 --- a/.github/workflows/test-action.yaml +++ b/.github/workflows/test-action.yaml @@ -134,3 +134,38 @@ jobs: env: BRANCH_NAME: ${{ github.event.repository.default_branch }} run: ct install --chart-dirs=testdata --target-branch ${BRANCH_NAME} + + test_ct_action_noverify: + runs-on: ubuntu-latest + permissions: + contents: read # Clone the repository + + name: Install chart-testing without verifying blob and test presence in path + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - name: Install chart-testing + uses: $/./ + with: + verify_blob: 'false' + - name: Check install! + run: | + ct version + CT_VERSION_OUTPUT=$(ct version 2>&1 /dev/null) + ACTUAL_VERSION=$(echo "$CT_VERSION_OUTPUT" | grep Version | rev | cut -d ' ' -f1 | rev) + if [[ $ACTUAL_VERSION != 'v3.14.0' ]]; then + echo 'should be v3.14.0' + exit 1 + else + exit 0 + fi + shell: bash + - name: Check root directory + run: | + if [[ $(git diff --stat) != '' ]]; then + echo 'should be clean' + exit 1 + else + exit 0 + fi diff --git a/action.yml b/action.yml index 6544cdf..40e8fe1 100644 --- a/action.yml +++ b/action.yml @@ -5,6 +5,10 @@ branding: color: blue icon: anchor inputs: + verify_blob: + description: "determines whether the download blob should be verified (default: true)" + required: false + default: 'true' version: description: "The chart-testing version to install" required: false @@ -29,6 +33,7 @@ runs: using: composite steps: - uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 + if: ${{ inputs.verify_blob != 'false' }} - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: version: ${{ inputs.uv_version }} @@ -36,11 +41,13 @@ runs: - run: | cd "$GITHUB_ACTION_PATH" \ && ./ct.sh \ + --verify-blob "$VERIFY_BLOB" \ --version "$CHART_TESTING_VERSION" \ --yamllint-version "$YAMLLINT_VERSION" \ --yamale-version "$YAMALE_VERSION" shell: bash env: + VERIFY_BLOB: ${{ inputs.verify_blob }} CHART_TESTING_VERSION: ${{ inputs.version }} YAMLLINT_VERSION: ${{ inputs.yamllint_version }} YAMALE_VERSION: ${{ inputs.yamale_version }} diff --git a/ct.sh b/ct.sh index a616dcb..0d954a0 100755 --- a/ct.sh +++ b/ct.sh @@ -5,6 +5,7 @@ set -o nounset set -o pipefail DEFAULT_CHART_TESTING_VERSION=3.14.0 +DEFAULT_VERIFY_BLOB=true DEFAULT_YAMLLINT_VERSION=1.33.0 DEFAULT_YAMALE_VERSION=6.0.0 @@ -41,6 +42,7 @@ EOF main() { local version="${DEFAULT_CHART_TESTING_VERSION}" + local verify_blob="${DEFAULT_VERIFY_BLOB}" local yamllint_version="${DEFAULT_YAMLLINT_VERSION}" local yamale_version="${DEFAULT_YAMALE_VERSION}" @@ -62,6 +64,16 @@ parse_command_line() { show_help exit ;; + --verify-blob) + if [[ -n "${2:-}" ]]; then + verify_blob="${2#v}" + shift + else + echo "ERROR: '--verify-blob' cannot be empty." >&2 + show_help + exit 1 + fi + ;; -v|--version) if [[ -n "${2:-}" ]]; then version="${2#v}" @@ -140,11 +152,15 @@ install_chart_testing() { exit 1 fi - if ! cosign verify-blob --certificate "${ct_cert}" --signature "${ct_sig}" \ - --certificate-identity "https://github.com/helm/chart-testing/.github/workflows/release.yaml@refs/heads/main" \ - --certificate-oidc-issuer "https://token.actions.githubusercontent.com" "${staging_dir}/ct.tar.gz"; then - echo "ERROR: Unable to validate chart-testing version: v${version}" >&2 - exit 1 + if [[ "${verify_blob}" != "false" ]]; then + if ! cosign verify-blob --certificate "${ct_cert}" --signature "${ct_sig}" \ + --certificate-identity "https://github.com/helm/chart-testing/.github/workflows/release.yaml@refs/heads/main" \ + --certificate-oidc-issuer "https://token.actions.githubusercontent.com" "${staging_dir}/ct.tar.gz"; then + echo "ERROR: Unable to validate chart-testing version: v${version}" >&2 + exit 1 + fi + else + echo "Skipping blob verification..." fi mkdir -p "${staging_dir}/extracted"