Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -147,6 +147,8 @@ jobs:
gocloud.dev:443
filippo.io:443
sigs.k8s.io:443
raw.githubusercontent.com:443
dl.google.com:443

- name: Checkout code
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
Expand Down
13 changes: 13 additions & 0 deletions .github/workflows/native-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -93,6 +93,10 @@ jobs:
storage.googleapis.com:443
google.golang.org:443
modernc.org:443
raw.githubusercontent.com:443
golang.org:443
go.dev:443
dl.google.com:443

- name: Check out code
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
Expand Down Expand Up @@ -171,6 +175,9 @@ jobs:
raw.githubusercontent.com:443
tuf-repo-cdn.sigstore.dev:443
rekor.sigstore.dev:443
golang.org:443
go.dev:443
dl.google.com:443

- name: Check out code
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
Expand Down Expand Up @@ -254,6 +261,9 @@ jobs:
raw.githubusercontent.com:443
tuf-repo-cdn.sigstore.dev:443
rekor.sigstore.dev:443
golang.org:443
go.dev:443
dl.google.com:443

- name: Check out code
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
Expand Down Expand Up @@ -330,6 +340,9 @@ jobs:
raw.githubusercontent.com:443
tuf-repo-cdn.sigstore.dev:443
rekor.sigstore.dev:443
golang.org:443
go.dev:443
dl.google.com:443

- name: Check out code
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/planfile-artifacts-e2e.yml
Original file line number Diff line number Diff line change
Expand Up @@ -71,6 +71,9 @@ jobs:
tuf-repo-cdn.sigstore.dev:443
rekor.sigstore.dev:443
registry.opentofu.org:443
golang.org:443
go.dev:443
dl.google.com:443

- name: Checkout
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
Expand Down Expand Up @@ -125,6 +128,9 @@ jobs:
tuf-repo-cdn.sigstore.dev:443
rekor.sigstore.dev:443
registry.opentofu.org:443
golang.org:443
go.dev:443
dl.google.com:443

- name: Checkout
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
Expand Down
9 changes: 9 additions & 0 deletions .github/workflows/planfile-verify-e2e.yml
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,9 @@ jobs:
tuf-repo-cdn.sigstore.dev:443
rekor.sigstore.dev:443
registry.opentofu.org:443
golang.org:443
go.dev:443
dl.google.com:443
- name: Checkout
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
Expand Down Expand Up @@ -133,6 +136,9 @@ jobs:
tuf-repo-cdn.sigstore.dev:443
rekor.sigstore.dev:443
registry.opentofu.org:443
golang.org:443
go.dev:443
dl.google.com:443
- name: Checkout
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
Expand Down Expand Up @@ -183,6 +189,9 @@ jobs:
tuf-repo-cdn.sigstore.dev:443
rekor.sigstore.dev:443
registry.opentofu.org:443
golang.org:443
go.dev:443
dl.google.com:443
- name: Checkout
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/rerun-infra-failures.yml
Original file line number Diff line number Diff line change
Expand Up @@ -92,6 +92,9 @@ jobs:
storage.googleapis.com:443
google.golang.org:443
modernc.org:443
raw.githubusercontent.com:443
go.dev:443
dl.google.com:443

- name: Check out code into the Go module directory
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/setup-go-cache-warmup.yml
Original file line number Diff line number Diff line change
Expand Up @@ -126,6 +126,9 @@ jobs:
ocsp.usertrust.com:80
ocsp.digicert.com:80
*.pool.ntp.org:123
raw.githubusercontent.com:443
golang.org:443
go.dev:443

- name: Check out code into the Go module directory
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
Expand Down
22 changes: 22 additions & 0 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -177,6 +177,9 @@ jobs:
ocsp.usertrust.com:80
ocsp.digicert.com:80
*.pool.ntp.org:123
golang.org:443
go.dev:443
dl.google.com:443

- name: Announce build target
if: ${{ ! ( matrix.target == 'windows' && github.event.pull_request.draft ) }}
Expand Down Expand Up @@ -425,6 +428,9 @@ jobs:
ocsp.usertrust.com:80
ocsp.digicert.com:80
*.pool.ntp.org:123
golang.org:443
go.dev:443
dl.google.com:443

- name: Check out code into the Go module directory
if: ${{ ! ( matrix.flavor.target == 'windows' && github.event.pull_request.draft ) }}
Expand Down Expand Up @@ -659,6 +665,9 @@ jobs:
ocsp.usertrust.com:80
ocsp.digicert.com:80
*.pool.ntp.org:123
golang.org:443
go.dev:443
dl.google.com:443

- name: Check out code into the Go module directory
if: ${{ ! ( matrix.flavor.target == 'windows' && github.event.pull_request.draft ) }}
Expand Down Expand Up @@ -1068,7 +1077,10 @@ jobs:
egress-policy: block
allowed-endpoints: >
api.github.com:443
dl.google.com:443
github.com:443
go.dev:443
raw.githubusercontent.com:443
release-assets.githubusercontent.com:443
golang.org:443
proxy.golang.org:443
Expand Down Expand Up @@ -1436,6 +1448,8 @@ jobs:
storage.googleapis.com:443
tuf-repo-cdn.sigstore.dev:443
us.i.posthog.com:443
golang.org:443
go.dev:443

- name: Check out code into the Go module directory
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
Expand Down Expand Up @@ -1756,6 +1770,10 @@ jobs:
ocsp.usertrust.com:80
ocsp.digicert.com:80
*.pool.ntp.org:123
raw.githubusercontent.com:443
golang.org:443
go.dev:443
dl.google.com:443

- name: Check out code into the Go module directory
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
Expand Down Expand Up @@ -2216,6 +2234,10 @@ jobs:
release-assets.githubusercontent.com:443
storage.googleapis.com:443
us.i.posthog.com:443
raw.githubusercontent.com:443
golang.org:443
go.dev:443
dl.google.com:443

- name: Check out code into the Go module directory
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/validation-e2e.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,10 @@ jobs:
proxy.golang.org:443
sum.golang.org:443
storage.googleapis.com:443
raw.githubusercontent.com:443
golang.org:443
go.dev:443
dl.google.com:443

- name: Check out source
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/website-deploy-prod.yml
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,10 @@ jobs:
cloudfront.amazonaws.com:443
api.scorecard.dev:443
www.bestpractices.dev:443
raw.githubusercontent.com:443
golang.org:443
go.dev:443
dl.google.com:443

# https://github.com/marketplace/actions/configure-aws-credentials-action-for-github-actions
- name: Configure AWS Credentials
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/website-preview-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,10 @@ jobs:
us.i.posthog.com:443
api.scorecard.dev:443
www.bestpractices.dev:443
raw.githubusercontent.com:443
golang.org:443
go.dev:443
dl.google.com:443

- name: Checkout Repository
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/website-preview-deploy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -64,6 +64,10 @@ jobs:
storage.googleapis.com:443
cplive-plat-ue2-dev-atmos-docs-origin.s3.us-east-2.amazonaws.com:443
cloudfront.amazonaws.com:443
raw.githubusercontent.com:443
golang.org:443
go.dev:443
dl.google.com:443

- name: Start deployment
uses: bobheadxi/deployments@648679e8e4915b27893bd7dbc35cb504dc915bc8 # v1
Expand Down
7 changes: 5 additions & 2 deletions cmd/custom_command_output_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ import (
"fmt"
"testing"

"github.com/charmbracelet/x/ansi"
"github.com/spf13/viper"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
Expand Down Expand Up @@ -33,8 +34,10 @@ func TestCustomCommandShellViewport(t *testing.T) {
stdout, stderr := captureStdoutStderr(t, func() { command.Run(command, nil) })
if live {
assert.Empty(t, stdout, "successful viewport output must not leak to stdout")
assert.NotContains(t, stderr, "passing-stderr")
assert.Contains(t, stderr, "compile completed")
// Raw terminal capture can include live frames drawn before the viewport
// clears them. TestOutputViewportTailAndResize verifies that clearing;
// here verify the command finishes with its summary and no stdout replay.
assert.Regexp(t, "compile completed\\r?\\n$", ansi.Strip(stderr))
} else {
assert.Equal(t, "passing-stdout", stdout)
assert.Equal(t, "passing-stderr", stderr)
Expand Down
75 changes: 13 additions & 62 deletions cmd/terraform_generate_varfile_test.go
Original file line number Diff line number Diff line change
@@ -1,9 +1,6 @@
package cmd

import (
"bytes"
"io"
"os"
"regexp"
"runtime"
"strings"
Expand Down Expand Up @@ -38,35 +35,12 @@ func TestTerraformGenerateVarfileCmd(t *testing.T) {
t.Setenv("ATMOS_BASE_PATH", stacksPath)
t.Setenv("ATMOS_LOGS_LEVEL", "Debug")

// Capture stderr.
oldStderr := os.Stderr
r, w, err := os.Pipe()
assert.NoError(t, err, "Creating pipe should not error")

os.Stderr = w

// Execute the command.
RootCmd.SetArgs([]string{"terraform", "generate", "varfile", "component-1", "-s", "nonprod"})
err = Execute()
assert.NoError(t, err, "'TestTerraformGenerateVarfileCmd' should execute without error")

// Restore stderr immediately after command execution to prevent any goroutines from blocking.
os.Stderr = oldStderr

// Close the writer to signal end of output.
err = w.Close()
assert.NoError(t, err, "Closing pipe writer should not error")

// Read captured output from the pipe.
var output bytes.Buffer
_, err = io.Copy(&output, r)
assert.NoError(t, err, "Reading from pipe should not error")

// Close the reader.
err = r.Close()
assert.NoError(t, err, "Closing pipe reader should not error")

outputStr := output.String()
// Drain output while Execute runs; debug config logging can exceed pipe capacity.
_, outputStr := captureStdoutStderr(t, func() {
RootCmd.SetArgs([]string{"terraform", "generate", "varfile", "component-1", "-s", "nonprod"})
err := Execute()
assert.NoError(t, err, "'TestTerraformGenerateVarfileCmd' should execute without error")
})
// Strip ANSI codes for comparison.
cleanOutput := stripANSI(outputStr)

Expand Down Expand Up @@ -97,41 +71,18 @@ func TestTerraformGenerateVarfileCmdNoColor(t *testing.T) {
// SetColorProfile handles lipgloss, theme, and logger configuration.
ui.SetColorProfile(termenv.Ascii)

// Capture stderr.
oldStderr := os.Stderr
r, w, err := os.Pipe()
assert.NoError(t, err, "Creating pipe should not error")

os.Stderr = w

// Execute the command.
RootCmd.SetArgs([]string{"terraform", "generate", "varfile", "component-1", "-s", "nonprod"})
err = Execute()
assert.NoError(t, err, "'TestTerraformGenerateVarfileCmdNoColor' should execute without error")

// Restore stderr immediately after command execution to prevent any goroutines from blocking.
os.Stderr = oldStderr

// Close the writer to signal end of output.
err = w.Close()
assert.NoError(t, err, "Closing pipe writer should not error")

// Read captured output from the pipe.
var output bytes.Buffer
_, err = io.Copy(&output, r)
assert.NoError(t, err, "Reading from pipe should not error")

// Close the reader.
err = r.Close()
assert.NoError(t, err, "Closing pipe reader should not error")

outputStr := output.String()
// Drain output while Execute runs; debug config logging can exceed pipe capacity.
_, outputStr := captureStdoutStderr(t, func() {
RootCmd.SetArgs([]string{"terraform", "generate", "varfile", "component-1", "-s", "nonprod"})
err := Execute()
assert.NoError(t, err, "'TestTerraformGenerateVarfileCmdNoColor' should execute without error")
})

// A stray write from an unrelated, already-completed test's background
// goroutine (e.g. mvdan.cc/sh/v3's DefaultExecHandler kill-timeout
// goroutine, which outlives cmd.Wait() by design -- see its own "TODO:
// don't sleep in this goroutine" comment) can land in this test's pipe if
// it fires in the narrow window between os.Stderr = w above and this
// it fires in the narrow window between redirecting stderr and this
// test's own Execute() producing its first line. That race is upstream of
// this test and unrelated to NO_COLOR handling, so scope the ANSI check
// to what this invocation's own Execute() actually produced: everything
Expand Down
Loading
Loading