graduation

package
v0.72.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 1, 2026 License: MIT Imports: 15 Imported by: 0

Documentation

Overview

Package graduation composes independently produced WB and deployment evidence into one strict, reviewable graduation receipt. It never turns a hand-written status field into a green release decision.

Index

Constants

View Source
const (
	RemoteTargetProducer = "wb.verify.receipt.remote-target.v1"
	DeploymentProducer   = "external.deployment-receipt.v1"
)
View Source
const SchemaVersion = 1

Variables

This section is empty.

Functions

func Digest

func Digest(raw []byte) string

func ValidateRemoteURL added in v0.62.2

func ValidateRemoteURL(repository, raw string) error

ValidateRemoteURL binds the recorded remote URL to the repository the receipt claims to graduate. Without it remote_url is an unchecked free-text field: any string satisfies a non-blank test, so a receipt can name one repository while citing a remote that publishes another. The check is host-neutral by construction — gitremote.Parse already rejects embedded credentials, query strings, fragments, encoded paths, and option-like arguments on every supported host, so WB does not need to know which forge served the remote in order to prove its identity.

Types

type CIWaitReceipt

type CIWaitReceipt struct {
	SchemaVersion int       `json:"schema_version"`
	ObservedAt    time.Time `json:"observed_at"`
	orchestrate.PullRequestWaitResult
}

CIWaitReceipt is exactly the JSON envelope emitted by `wb ci wait --json`.

func DecodeCIWaitReceipt

func DecodeCIWaitReceipt(raw []byte) (CIWaitReceipt, error)

type Component

type Component[T any] struct {
	SHA256     string    `json:"sha256"`
	ObservedAt time.Time `json:"observed_at"`
	Evidence   T         `json:"evidence"`
}

type DeployedRevisionEvidence

type DeployedRevisionEvidence struct {
	SchemaVersion       int       `json:"schema_version"`
	Producer            string    `json:"producer"`
	Provider            string    `json:"provider"`
	Repository          string    `json:"repository"`
	RunURL              string    `json:"run_url"`
	Revision            string    `json:"revision"`
	RevisionJSONPointer string    `json:"revision_json_pointer"`
	ObservedAt          time.Time `json:"observed_at"`
	PayloadJSON         string    `json:"payload_json"`
	PayloadSHA256       string    `json:"payload_sha256"`
}

DeployedRevisionEvidence is a provider-neutral immutable deployment receipt. A deployment adapter must retain its exact structured provider payload and content digest; free-form “passed” prose is intentionally not representable here.

func DecodeDeployedRevision

func DecodeDeployedRevision(raw []byte) (DeployedRevisionEvidence, error)

type Inputs

type Inputs struct {
	LocalCheck             VerificationIndex
	LocalCheckSHA256       string
	LocalCheckObservedAt   time.Time
	CIWait                 CIWaitReceipt
	CIWaitSHA256           string
	CIWaitObservedAt       time.Time
	RemoteTarget           RemoteTargetEvidence
	RemoteTargetSHA256     string
	RemoteTargetObservedAt time.Time
	DeployedRevision       DeployedRevisionEvidence
	DeployedSHA256         string
	DeployedObservedAt     time.Time
	TerminalCleanup        TerminalCleanupEvidence
	CleanupSHA256          string
	CleanupObservedAt      time.Time
}

type LocalCIComponent

type LocalCIComponent struct {
	LocalCheck Component[VerificationIndex] `json:"local_check"`
	CIWait     Component[CIWaitReceipt]     `json:"ci_wait"`
}

type Receipt

type Receipt struct {
	SchemaVersion    int                                 `json:"schema_version"`
	Repository       string                              `json:"repository"`
	Revision         string                              `json:"revision"`
	CreatedAt        time.Time                           `json:"created_at"`
	LocalCI          LocalCIComponent                    `json:"local_ci"`
	RemoteTarget     Component[RemoteTargetEvidence]     `json:"remote_target"`
	DeployedRevision Component[DeployedRevisionEvidence] `json:"deployed_revision"`
	TerminalCleanup  Component[TerminalCleanupEvidence]  `json:"terminal_cleanup"`
}

Receipt retains the immutable source digest and observation time for every supplied producer document, so review can independently retrieve and hash each component.

func Compose

func Compose(inputs Inputs, now time.Time) (Receipt, error)

type RemoteTargetEvidence

type RemoteTargetEvidence struct {
	SchemaVersion        int       `json:"schema_version"`
	Producer             string    `json:"producer"`
	Repository           string    `json:"repository"`
	Remote               string    `json:"remote"`
	RemoteURL            string    `json:"remote_url"`
	TargetRef            string    `json:"target_ref"`
	Revision             string    `json:"revision"`
	ObservedAt           time.Time `json:"observed_at"`
	ObservedOutput       string    `json:"observed_output"`
	ObservedOutputSHA256 string    `json:"observed_output_sha256"`
}

RemoteTargetEvidence can only be emitted by `wb verify receipt remote-target`. The captured git-ls-remote payload and digest make the observed remote ref independently inspectable rather than an assertion.

func DecodeRemoteTarget

func DecodeRemoteTarget(raw []byte) (RemoteTargetEvidence, error)

type TerminalCleanupEvidence

type TerminalCleanupEvidence struct {
	GeneratedAt  time.Time                          `json:"generated_at"`
	Phase        string                             `json:"phase"`
	Task         string                             `json:"task,omitempty"`
	Filter       string                             `json:"filter,omitempty"`
	AllMerged    bool                               `json:"all_merged"`
	Apply        bool                               `json:"apply"`
	DeleteRemote bool                               `json:"delete_remote"`
	OlderThan    string                             `json:"older_than"`
	Results      []worktrees.CleanupResult          `json:"results"`
	Diagnostics  []worktrees.ListDiagnostic         `json:"diagnostics,omitempty"`
	Artifacts    []worktrees.LifecycleArtifact      `json:"artifacts,omitempty"`
	Recovery     *worktrees.InterruptedLockRecovery `json:"recovery,omitempty"`
}

TerminalCleanupEvidence is the persistent JSON report written by `wb worktree cleanup <task> --apply --remote`. It names only feature/integration worktrees; a canonical target checkout is intentionally not deleted.

func DecodeTerminalCleanup

func DecodeTerminalCleanup(raw []byte) (TerminalCleanupEvidence, error)

type VerificationIndex

type VerificationIndex struct {
	SchemaVersion int                          `json:"schema_version"`
	GeneratedAt   time.Time                    `json:"generated_at"`
	Profile       string                       `json:"profile,omitempty"`
	Checks        []quality.Check              `json:"checks"`
	Repositories  []quality.VerificationReport `json:"repositories"`
}

VerificationIndex is exactly the JSON envelope emitted by `wb check --profile ci --format json`, copied here because the command package owns its renderer. It deliberately preserves the public quality report types.

func DecodeVerificationIndex

func DecodeVerificationIndex(raw []byte) (VerificationIndex, error)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL