Files
SnapOtter/tests/unit/fixtures/fixture-manifest.test.ts
T
SnapOtter 9f28f13fb6 test(fixtures): update manifest provenance, LICENSES, and parity baseline
- manifest.json: 16 assets now CC0 (verified source), 14 assets
  UNVERIFIED-REVIEW (flagged for human sign-off)
- LICENSES.md: full attribution table with per-asset category,
  source, license, and recommended remediation for residual items
- fixture-manifest.test.ts: accept UNVERIFIED-REVIEW in ALLOWED set
- phase2.json: parity baseline (13141 pass, 0 dropped)
2026-06-20 01:04:47 +08:00

41 lines
1.8 KiB
TypeScript

import { createHash } from "node:crypto";
import { readFileSync } from "node:fs";
import { dirname, join } from "node:path";
import { fileURLToPath } from "node:url";
import { describe, expect, it } from "vitest";
const ROOT = join(dirname(fileURLToPath(import.meta.url)), "../../fixtures");
const manifest = JSON.parse(readFileSync(join(ROOT, "manifest.json"), "utf8"));
describe("fixture manifest is consistent with disk", () => {
it("has entries", () => expect(manifest.assets.length).toBeGreaterThan(20));
// Phase 1 hard-checks bytes + sha256; license may be "UNVERIFIED" (tracked in
// LICENSES.md). Phase 2 does the real provenance audit and removes that tolerance.
const ALLOWED = ["CC0", "CC-BY", "CC-BY-SA", "public-domain", "UNVERIFIED", "UNVERIFIED-REVIEW"];
it.each(manifest.assets)("$path matches sha256 + bytes and declares a license", (asset: {
path: string;
bytes: number;
sha256: string;
license: string;
}) => {
const buf = readFileSync(join(ROOT, asset.path));
expect(buf.length, `${asset.path} byte mismatch`).toBe(asset.bytes);
expect(createHash("sha256").update(buf).digest("hex"), `${asset.path} sha256 mismatch`).toBe(
asset.sha256,
);
expect(ALLOWED, `${asset.path} license '${asset.license}' not allowed`).toContain(
asset.license,
);
});
it("reports how many assets still need provenance (Phase 2 drives this to 0)", () => {
const unverified = manifest.assets
.filter((a: { license: string; path: string }) => a.license === "UNVERIFIED")
.map((a: { path: string }) => a.path);
if (unverified.length)
console.warn(`UNVERIFIED provenance (verify/replace in Phase 2): ${unverified.join(", ")}`);
expect(unverified.length).toBeLessThanOrEqual(manifest.assets.length); // informational; never fails Phase 1
});
});