Visitar URL original
test: vendor the Prism mock server used by make test-docker by kridai · Pull Request #786 · sendgrid/sendgrid-java · GitHub
Skip to content

test: vendor the Prism mock server used by make test-docker - #786

Merged
kridai merged 1 commit into
chore/harden-github-actionsfrom
chore/vendor-prism-mock
Oct 7, 2026
Merged

kridai merged 1 commit into
chore/harden-github-actionsfrom
chore/vendor-prism-mock

Conversation

@kridai

@kridai kridai commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Stacked on #785. Restores the API tests, which haven't been able to run.
Ticket: https://twilio-engineering.atlassian.net/browse/DII-2643

make test-docker downloaded prism-java.sh from sendgrid/sendgrid-oai@HEAD and ran it. That repo is no longer publicly readable, so the download returns 404 and 231 of the 255 SendGridTest tests (everything that calls the API) couldn't run. Downloading a script from another repo's HEAD and running it is also the kind of unpinned step the platform requirements are meant to remove.

Changes

  • New mock-server/ directory with the setup the remote script used to provide (sendgrid-oai/prism/), now committed and pinned:
    • Prism v2.0.17, with the binary checked by sha256.
    • oai_stoplight.json vendored from sendgrid-oai commit eb7a825b, the same commit the old script pinned. That URL is now 404 as well.
    • nginx answering as api.sendgrid.com with the same self-signed test cert/key the old setup used. These are test-only credentials and were already public in sendgrid-oai, but secret scanners may flag them.
    • nginx and debian base images pinned by digest. The nginx healthcheck replaces the old sleep 10.
  • Dockerfile: openjdk:$version replaced with maven:3.9-eclipse-temurin-$version. The openjdk images have been removed from Docker Hub, so the old Dockerfile can't build any more.
  • Makefile: test-docker runs the local compose file with --exit-code-from helper-runner. The old script used --abort-on-container-exit alone, which doesn't guarantee the exit code reflects the test result. It uses docker compose, falling back to docker-compose.

Testing

  • CI on ubuntu-x64 (run 37435921680): JDK 8 and JDK 11 both pass 289 tests, 0 failures, including all 255 in SendGridTest.
  • Locally on JDK 8: same result, and spotbugs and checkstyle pass.
  • The workflow's push filter branches: [ '*' ] doesn't match branch names that contain /, so this run was started with workflow_dispatch. Pull requests into main trigger it normally.
  • Failure propagation: with LicenseTest deliberately broken, make test-docker ends in BUILD FAILURE and exits 2. Before this change a failing run could still exit 0.

Draft until the CI matrix is green.

🤖 Generated with Claude Code

make test-docker downloaded and ran a script from sendgrid/sendgrid-oai@HEAD,
which is no longer publicly readable, so 231 of 255 SendGridTest tests could
not run. The setup now lives in mock-server/ with everything pinned:

- Prism v2.0.17 binary verified by sha256; spec vendored from sendgrid-oai
  commit eb7a825b (the commit the old script pinned)
- nginx and debian base images pinned by digest
- Dockerfile moved from the removed openjdk images to maven:3.9-eclipse-temurin
- --exit-code-from helper-runner so a failing test fails the make target

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kridai
kridai added this pull request to stack #787 October 6, 2026 08:31
@kridai
kridai marked this pull request as ready for review October 6, 2026 08:52
@kridai
kridai removed this pull request from stack #787 October 7, 2026 07:40
@kridai
kridai merged commit 38ba143 into chore/harden-github-actions Oct 7, 2026
13 checks passed
@kridai
kridai deleted the chore/vendor-prism-mock branch October 7, 2026 07:40
kridai added a commit that referenced this pull request Oct 7, 2026
* chore: harden GitHub Actions for platform compliance

- Pin all actions to commit SHAs and add per-job permissions
- Run jobs on ubuntu-x64 with a repository_owner guard
- Replace amannn/action-semantic-pull-request with twilio/sdk-actions/semantic-pr-title
- Replace sendgrid/dx-automator release action with twilio/sdk-actions/github-release
- Comment out Slack failure notifications and the Datadog release metric
- Remove update-dependencies workflow in favour of Dependabot (maven + github-actions)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore: update LICENSE year so LicenseTest passes

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix: replace docker/login-action with CLI login

The sendgrid org allowlist only permits GitHub-owned actions, so
docker/login-action caused a startup_failure for the whole workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test: vendor the Prism mock server used by make test-docker (#786)

make test-docker downloaded and ran a script from sendgrid/sendgrid-oai@HEAD,
which is no longer publicly readable, so 231 of 255 SendGridTest tests could
not run. The setup now lives in mock-server/ with everything pinned:

- Prism v2.0.17 binary verified by sha256; spec vendored from sendgrid-oai
  commit eb7a825b (the commit the old script pinned)
- nginx and debian base images pinned by digest
- Dockerfile moved from the removed openjdk images to maven:3.9-eclipse-temurin
- --exit-code-from helper-runner so a failing test fails the make target

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants