@@ -394,6 +394,15 @@ t.test('verifyAttestations valid attestations', async t => {
394394
395395 const mani = await f . manifest ( )
396396 t . ok ( mani . _attestations )
397+ t . ok ( mani . _attestationBundles , 'should include fetched attestation bundles' )
398+ t . equal ( mani . _attestationBundles . length , 2 , 'should have two attestation bundles' )
399+ t . equal ( mani . _attestationBundles [ 0 ] . predicateType , 'https://slsa.dev/provenance/v0.2' )
400+ t . equal (
401+ mani . _attestationBundles [ 1 ] . predicateType ,
402+ 'https://github.com/npm/attestation/tree/main/specs/publish/v0.1'
403+ )
404+ t . ok ( mani . _attestations . url , 'should preserve original attestation url' )
405+ t . ok ( mani . _attestations . provenance , 'should preserve original provenance metadata' )
397406 t . ok ( mani . _integrity )
398407} )
399408
@@ -450,6 +459,8 @@ t.test('verifyAttestations with registry path does not duplicate path', async t
450459
451460 const mani = await f . manifest ( )
452461 t . ok ( mani . _attestations )
462+ t . ok ( mani . _attestationBundles , 'should include fetched attestation bundles' )
463+ t . equal ( mani . _attestationBundles . length , 2 )
453464 t . ok ( mani . _integrity )
454465} )
455466
@@ -554,6 +565,7 @@ t.test('disable verifyAttestations when package has attestations', async t => {
554565
555566 const mani = await f . manifest ( )
556567 t . ok ( mani . _attestations )
568+ t . notOk ( mani . _attestationBundles , 'should not include bundles when verification is disabled' )
557569 t . ok ( mani . _integrity )
558570} )
559571
@@ -720,6 +732,7 @@ t.test('verifyAttestations no attestation with keyid', async t => {
720732 // Keyless attestations (no keyid) should not require registry keys
721733 const mani = await f . manifest ( )
722734 t . ok ( mani . _attestations )
735+ t . ok ( mani . _attestationBundles , 'should include bundles for keyless attestations' )
723736 t . ok ( mani . _integrity )
724737} )
725738
@@ -764,6 +777,7 @@ t.test('verifyAttestations keyless without registry keys', async t => {
764777
765778 const mani = await f . manifest ( )
766779 t . ok ( mani . _attestations )
780+ t . ok ( mani . _attestationBundles , 'should include bundles for keyless attestations without registry keys' )
767781 t . ok ( mani . _integrity )
768782} )
769783
@@ -945,6 +959,7 @@ t.test('verifyAttestations rotated key', async t => {
945959
946960 const mani = await f . manifest ( )
947961 t . ok ( mani . _attestations )
962+ t . ok ( mani . _attestationBundles , 'should include bundles with rotated key' )
948963 t . ok ( mani . _integrity )
949964} )
950965
0 commit comments