Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 35 additions & 0 deletions .github/workflows/test-action.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -134,3 +134,38 @@ jobs:
env:
BRANCH_NAME: ${{ github.event.repository.default_branch }}
run: ct install --chart-dirs=testdata --target-branch ${BRANCH_NAME}

test_ct_action_noverify:
runs-on: ubuntu-latest
permissions:
contents: read # Clone the repository

name: Install chart-testing without verifying blob and test presence in path
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install chart-testing
uses: $/./
with:
verify_blob: 'false'
- name: Check install!
run: |
ct version
CT_VERSION_OUTPUT=$(ct version 2>&1 /dev/null)
ACTUAL_VERSION=$(echo "$CT_VERSION_OUTPUT" | grep Version | rev | cut -d ' ' -f1 | rev)
if [[ $ACTUAL_VERSION != 'v3.14.0' ]]; then
echo 'should be v3.14.0'
exit 1
else
exit 0
fi
shell: bash
- name: Check root directory
run: |
if [[ $(git diff --stat) != '' ]]; then
echo 'should be clean'
exit 1
else
exit 0
fi
7 changes: 7 additions & 0 deletions action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ branding:
color: blue
icon: anchor
inputs:
verify_blob:
description: "determines whether the download blob should be verified (default: true)"
required: false
default: 'true'
version:
description: "The chart-testing version to install"
required: false
Expand All @@ -29,18 +33,21 @@ runs:
using: composite
steps:
- uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
if: ${{ inputs.verify_blob != 'false' }}
- uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
with:
version: ${{ inputs.uv_version }}
github-token: ${{ inputs.github_token }}
- run: |
cd "$GITHUB_ACTION_PATH" \
&& ./ct.sh \
--verify-blob "$VERIFY_BLOB" \
--version "$CHART_TESTING_VERSION" \
--yamllint-version "$YAMLLINT_VERSION" \
--yamale-version "$YAMALE_VERSION"
shell: bash
env:
VERIFY_BLOB: ${{ inputs.verify_blob }}
CHART_TESTING_VERSION: ${{ inputs.version }}
YAMLLINT_VERSION: ${{ inputs.yamllint_version }}
YAMALE_VERSION: ${{ inputs.yamale_version }}
26 changes: 21 additions & 5 deletions ct.sh
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ set -o nounset
set -o pipefail

DEFAULT_CHART_TESTING_VERSION=3.14.0
DEFAULT_VERIFY_BLOB=true
DEFAULT_YAMLLINT_VERSION=1.33.0
DEFAULT_YAMALE_VERSION=6.0.0

Expand Down Expand Up @@ -41,6 +42,7 @@ EOF

main() {
local version="${DEFAULT_CHART_TESTING_VERSION}"
local verify_blob="${DEFAULT_VERIFY_BLOB}"
local yamllint_version="${DEFAULT_YAMLLINT_VERSION}"
local yamale_version="${DEFAULT_YAMALE_VERSION}"

Expand All @@ -62,6 +64,16 @@ parse_command_line() {
show_help
exit
;;
--verify-blob)
if [[ -n "${2:-}" ]]; then
verify_blob="${2#v}"
shift
else
echo "ERROR: '--verify-blob' cannot be empty." >&2
show_help
exit 1
fi
;;
-v|--version)
if [[ -n "${2:-}" ]]; then
version="${2#v}"
Expand Down Expand Up @@ -140,11 +152,15 @@ install_chart_testing() {
exit 1
fi

if ! cosign verify-blob --certificate "${ct_cert}" --signature "${ct_sig}" \
--certificate-identity "https://github.com/helm/chart-testing/.github/workflows/release.yaml@refs/heads/main" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" "${staging_dir}/ct.tar.gz"; then
echo "ERROR: Unable to validate chart-testing version: v${version}" >&2
exit 1
if [[ "${verify_blob}" != "false" ]]; then
if ! cosign verify-blob --certificate "${ct_cert}" --signature "${ct_sig}" \
--certificate-identity "https://github.com/helm/chart-testing/.github/workflows/release.yaml@refs/heads/main" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" "${staging_dir}/ct.tar.gz"; then
echo "ERROR: Unable to validate chart-testing version: v${version}" >&2
exit 1
fi
else
echo "Skipping blob verification..."
fi

mkdir -p "${staging_dir}/extracted"
Expand Down
Loading