This commit is contained in:
@@ -153,17 +153,36 @@ if grep -Eq '(^|/)(signing-private|private-key|id_rsa)' <<< "$ARCHIVE_LIST"; the
|
||||
printf 'Release archive contains private key material\n' >&2
|
||||
exit 1
|
||||
fi
|
||||
if grep -Eq '(^|/)(\.DS_Store|__MACOSX|[^/]*\._[^/]*)$' <<< "$ARCHIVE_LIST"; then
|
||||
printf 'Release archive contains macOS metadata\n' >&2
|
||||
exit 1
|
||||
fi
|
||||
if tar -tvzf "$ARTIFACT" | grep -Eq '^l'; then
|
||||
printf 'Release archive contains a symbolic link\n' >&2
|
||||
exit 1
|
||||
fi
|
||||
[ "$(tar -xOf "$ARTIFACT" ./VERSION)" = "$VERSION" ] \
|
||||
|| { printf 'Release archive version does not match the manifest\n' >&2; exit 1; }
|
||||
tar -xOf "$ARTIFACT" ./app.jar > "$WORK/app.jar"
|
||||
(cd "$WORK" && jar -xf app.jar \
|
||||
META-INF/MANIFEST.MF META-INF/maven/com.kaidi/finance-system/pom.properties)
|
||||
META-INF/MANIFEST.MF META-INF/maven/com.kaidi/finance-system/pom.properties \
|
||||
BOOT-INF/classes/application.yml BOOT-INF/classes/application-local.yml \
|
||||
BOOT-INF/classes/application-production.yml)
|
||||
JAR_POM_VERSION=$(sed -n 's/^version=//p' \
|
||||
"$WORK/META-INF/maven/com.kaidi/finance-system/pom.properties")
|
||||
JAR_IMPLEMENTATION_VERSION=$(sed -n 's/^Implementation-Version: //p' \
|
||||
"$WORK/META-INF/MANIFEST.MF" | tr -d '\r')
|
||||
[ "$JAR_POM_VERSION" = "$VERSION" ] && [ "$JAR_IMPLEMENTATION_VERSION" = "$VERSION" ] \
|
||||
|| { printf 'Release JAR metadata versions do not match the manifest\n' >&2; exit 1; }
|
||||
grep -Fq 'default: production' "$WORK/BOOT-INF/classes/application.yml" \
|
||||
|| { printf 'Release JAR does not default to the production profile\n' >&2; exit 1; }
|
||||
if grep -Eq '127\.0\.0\.1:3307|kaidi_local_2026' \
|
||||
"$WORK/BOOT-INF/classes/application.yml" \
|
||||
"$WORK/BOOT-INF/classes/application-local.yml" \
|
||||
"$WORK/BOOT-INF/classes/application-production.yml"; then
|
||||
printf 'Release JAR contains a development database fallback\n' >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
compare_archive_file() {
|
||||
archive_path=$1
|
||||
|
||||
Reference in New Issue
Block a user