fix(release): verify frozen backend artifacts

This commit is contained in:
key
2026-07-29 03:14:26 +08:00
parent 771d8552fa
commit feece9bb74
3 changed files with 14 additions and 3 deletions
+8 -2
View File
@@ -56,7 +56,12 @@ fi
frontend_index="frontend/dist/index.html"
mobile_index="mobile-uni/dist/build/h5/index.html"
backend_jar="backend/ruoyi-admin/target/ruoyi-admin.jar"
backend_jar="${RELEASE_LOCAL_BACKEND_PATH:-backend/ruoyi-admin/target/ruoyi-admin.jar}"
artifact_commit="${RELEASE_ARTIFACT_COMMIT:-HEAD}"
artifact_commit_sha="$(git rev-parse --verify "${artifact_commit}^{commit}" 2>/dev/null)" \
|| fail "RELEASE_ARTIFACT_COMMIT is not a valid commit: $artifact_commit"
git merge-base --is-ancestor "$artifact_commit_sha" HEAD \
|| fail "RELEASE_ARTIFACT_COMMIT must be an ancestor of HEAD: $artifact_commit_sha"
require_static_artifacts="true"
require_backend_artifact="true"
if [[ "$remote_verification_requested" == "true" ]]; then
@@ -91,7 +96,7 @@ if [[ "${AIHR_PRACTICE_RUNTIME_SCHEMA_BOOTSTRAP:-false}" == "true" ]]; then
fail "AIHR_PRACTICE_RUNTIME_SCHEMA_BOOTSTRAP must stay false for a release; apply the formal SQL migration instead"
fi
head_epoch="$(git show -s --format=%ct HEAD)"
head_epoch="$(git show -s --format=%ct "$artifact_commit_sha")"
file_epoch() {
if stat -f %m "$1" >/dev/null 2>&1; then
@@ -839,6 +844,7 @@ changed_files="$(git status --porcelain)"
[[ -z "$changed_files" ]] || fail "worktree has uncommitted changes; commit the release batch before publishing"
echo "commit=$(git rev-parse HEAD)"
echo "artifact_commit=$artifact_commit_sha"
echo "head_epoch=$head_epoch"
echo "worktree=clean"
if [[ "$require_static_artifacts" == "true" ]]; then