Dashboard › publish › Distillation
9279afcd-16fd-483f-9f3c-c484066002be["lore_tm_v1_a1-kI_izOZqOavMlXCMncLgI87uSmTxhAyCvcvHPcVA","lore_tm_v1_6unlwGca8_ALJBmLL7OBAyMSqDfh1gN9cWQuZMLcX9Y","lore_tm_v1_oJ2ki6bVAktx4pHfo-gcFVyJn_mOIXp79RrG3f09e7M","lore_tm_v1_ZJywn7FVTVM0CibRiDEHoNXSnLOIPm1MEXAI7kSlZp4","lore_tm_v1_ObTI8ZYk8By--K7EiOIZrK0ui-5-L3HIVmz7uar1wus","lore_tm_v1_VfyTsPUOiFs8RRb41ffi5xDFVMzzfzxY4tV1fQ9mm7Q"]
Date: Sep 9, 2026
/home/byk/Code/getsentry/publish/src/publish/__tests__/validate-approval-attestation.js is a 420-line Vitest suite importing validateApprovalAttestation, createApprovalAttestation, and createCiReadyAttestation; afterEach() calls vi.restoreAllMocks(), jsonResponse(json) creates an OK mocked response, and issue(title, { body = "", labels = [{ name: "accepted" }], state = "open" } = {}) creates test issues.validate-approval-attestation.js has 9 shown tests in describe("validateApprovalAttestation"): 1. accepts current accepted event "100" by actor contractor with an attestation authored by github-actions[bot]; 2. rejects after title changes from publish: getsentry/sentry-javascript@10.0.0 to publish: getsentry/sentry-python@10.0.0; 3. rejects after body changes to Merge target: main\n\n- [ ] npm; 4. rejects when accepted is removed; 5. rejects after issue state becomes closed; 6. rejects when accepted is re-added with newer event ID "200"; 7. rejects an attestation for event "200" when expectedAcceptedEvent is { actor: "contractor", eventId: "100" }; 8. accepts required CI-ready proof tied to approval event "100" and a current ci-ready event "200" added by sentry-internal-app[bot]; 9. rejects when the current ci-ready event was manually added by contractor despite an attestation naming sentry-internal-app[bot].2c4c77d1cafa8d792ab4a9d449799221baf95176a47692ad9a0b350b0a2618ed.bcd2ba49218906704ab6c1aa796996da409d3eb1 for actions/create-github-app-token was reported cryptographically verified (reason: "valid"), dated 2026-05-12T23:31:18Z, with message chore(main): release 3.2.0 (#370). Release 3.2.0 added enterprise-level GitHub App support and full repository names in the repositories input; fixes included upgrading @actions/core from 3.0.0 to 3.0.1 and validating private-key input.actions/create-github-app-token commit bcd2ba49218906704ab6c1aa796996da409d3eb1, file object hashes were: action.yml → 9f45ab3e2605ffeb987d3e029f27ee4d96bca6a0; dist/main.cjs → 20b90dce8c14c24222d6552fac6a4d5e2866a7d6; lib/main.js → 7108c3e584b8584b76d6dfa346b01706ca5fa5b4.d23441a48e516b6c34aea4fa41551a30e30af803 was reported cryptographically verified (reason: "valid"), dated 2026-07-16T19:43:33Z, with message backport fixes to releases-v6 (#2527).249970729cb0ef3589644e2896645e5dc5ba9c38 was reported cryptographically verified (reason: "valid"), dated 2026-07-14T02:48:03Z, with message Update @actions/cache to 5.1.0 and add security overrides for undici and fast-xml-parser (#1579); the change also updated licenses, fixed cache-validation test debug output and formatting, and bumped the version to 6.5.0.0057852bfaa89a56745cba8c7296529d2fc39830 was reported cryptographically verified (reason: "valid"), dated 2025-09-24T13:47:33Z, with message Merge pull request #1655 from actions/Link-/prepare-4.3.0 / Prepare \v4.3.0` release`.11d5960a326750d5838078e36cf38b85af677262 was reported cryptographically verified (reason: "valid"), dated 2026-07-16T19:43:47Z, with message backport fixes to releases-v4 (#2524).