sha256sum -c resolves filenames relative to cwd; downloading directly to /usr/local/bin/cosign caused 'No such file or directory'. Fix: download to /tmp/cosign-linux-amd64, cd /tmp, verify, then mv to /usr/local/bin/cosign. Applies to Containerfile, cosign-sign-image-by-digest task, and cosign-attach-sbom task. Also: update build.sh with HI_GO_DIGEST + GOVULNCHECK_VERSION args; add govulncheck + openspec checks to verify.sh. Image built and pushed: codeberg.org/operate-first/release-tools:latest Digest: sha256:b0387a762c54c035fc484d161115e79703d76ac90d2a91d1931077024a674cdd All 11 verify.sh checks pass (including offline mcpb).
59 lines
1.8 KiB
Bash
Executable file
59 lines
1.8 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# Verify that the locally built release-tools image contains all expected tools.
|
|
# Used both locally and by the PR build pipeline.
|
|
# Requires: podman
|
|
set -euo pipefail
|
|
|
|
RELEASE_TOOLS_IMAGE="${RELEASE_TOOLS_IMAGE:-localhost/release-tools:dev}"
|
|
|
|
echo "Verifying tools in ${RELEASE_TOOLS_IMAGE}"
|
|
|
|
FAIL=0
|
|
|
|
run_check() {
|
|
local label="$1"
|
|
shift
|
|
echo -n " ${label}: "
|
|
if output=$(podman run --rm "${RELEASE_TOOLS_IMAGE}" sh -c "$*" 2>&1); then
|
|
echo "OK — $(echo "${output}" | head -1)"
|
|
else
|
|
echo "FAIL"
|
|
echo " output: ${output}"
|
|
FAIL=1
|
|
fi
|
|
}
|
|
|
|
# Each bundled tool must report a version
|
|
run_check "go" "go version"
|
|
run_check "syft" "syft version"
|
|
run_check "goreleaser" "goreleaser --version"
|
|
run_check "cosign" "cosign version"
|
|
run_check "govulncheck" "govulncheck -version"
|
|
run_check "jq" "jq --version"
|
|
run_check "curl" "curl --version"
|
|
run_check "node" "node --version"
|
|
run_check "npm" "npm --version"
|
|
run_check "openspec" "openspec --version"
|
|
|
|
# Shell must work (Tekton script: blocks require /bin/sh)
|
|
run_check "shell" "/bin/sh -c 'echo ok'"
|
|
|
|
# mcpb must resolve without network (npm cache prewarmed in build stage)
|
|
echo -n " mcpb (offline npx): "
|
|
if output=$(podman run --rm --network=none "${RELEASE_TOOLS_IMAGE}" \
|
|
sh -c 'npx -y @anthropic-ai/mcpb --version 2>&1 || mcpb --version 2>&1' 2>&1); then
|
|
echo "OK — $(echo "${output}" | head -1)"
|
|
else
|
|
echo "FAIL (offline mcpb resolution failed)"
|
|
echo " output: ${output}"
|
|
FAIL=1
|
|
fi
|
|
|
|
if [[ ${FAIL} -ne 0 ]]; then
|
|
echo ""
|
|
echo "VERIFICATION FAILED — one or more tool checks failed. See output above."
|
|
exit 1
|
|
fi
|
|
|
|
echo ""
|
|
echo "All tool checks passed for ${RELEASE_TOOLS_IMAGE}"
|