| 429 | return err |
| 430 | } |
| 431 | refspec := "+" + requirement.Ref + ":" + verifiedSourceTrackingRef |
| 432 | if _, err := runGitWithEnv(ctx, candidateGitDir, env, "config", "--replace-all", "remote.origin.fetch", refspec); err != nil { |
| 433 | return err |
| 434 | } |
| 435 | args := []string{"fetch", "--filter=blob:none", "--no-tags"} |
| 436 | if requirement.Depth > 0 { |
| 437 | args = append(args, fmt.Sprintf("--depth=%d", requirement.Depth)) |
| 438 | } |
| 439 | args = append(args, "origin", refspec) |
| 440 | if _, err := runGitWithEnv(ctx, candidateGitDir, env, args...); err != nil { |
| 441 | return err |
| 442 | } |
| 443 | observed, err := runGit(ctx, candidateGitDir, "rev-parse", "--verify", verifiedSourceTrackingRef+"^{commit}") |
| 444 | if err != nil { |
| 445 | return fmt.Errorf("source ref %s did not resolve to a commit: %w", requirement.Ref, err) |
| 446 | } |
| 447 | observed = strings.ToLower(strings.TrimSpace(observed)) |
| 448 | if observed != requirement.RequiredCommit { |
| 449 | return fmt.Errorf("source changed: %s resolved to %s, required %s", requirement.Ref, observed, requirement.RequiredCommit) |