Compare commits

...

93 Commits

Author SHA1 Message Date
Michael B. Gale 97837dd278 Check code coverage in pr-checks.yml 2026-03-27 18:52:16 +00:00
Michael B. Gale 8b92d05ba7 Add code coverage analysis using c8, with currently met thresholds 2026-03-27 18:51:01 +00:00
Henry Mercer a899987af2 Merge pull request #3786 from github/henrymercer/faster-interactive-jobs
Move time-sensitive Actions workflows to `ubuntu-latest`
2026-03-27 18:08:16 +00:00
Henry Mercer 191d7c6f13 Merge pull request #3783 from github/mergeback/v4.35.1-to-main-c10b8064
Mergeback v4.35.1 refs/heads/releases/v4 into main
2026-03-27 17:11:42 +00:00
Henry Mercer aa69c483cd Merge pull request #3779 from github/henrymercer/remove-unused-dependency
Remove unused `@schemastore/package` dependency
2026-03-27 17:11:32 +00:00
Henry Mercer fe775da508 Merge pull request #3780 from github/dependabot/npm_and_yarn/brace-expansion-1.1.13
Bump brace-expansion from 1.1.12 to 1.1.13
2026-03-27 17:11:18 +00:00
Henry Mercer 353802f9f2 Move time-sensitive Actions workflows to ubuntu-latest
We originally moved these to `ubuntu-slim`, but there is a significant performance difference.  Since we often find ourselves waiting on these jobs, let's use the faster runners.
2026-03-27 16:22:19 +00:00
github-actions[bot] cc7db4a1f9 Rebuild 2026-03-27 16:20:01 +00:00
github-actions[bot] 6010f9d8e2 Update changelog and version after v4.35.1 2026-03-27 16:10:47 +00:00
Henry Mercer c10b8064de Merge pull request #3782 from github/update-v4.35.1-d6d1743b8
Merge main into releases/v4
2026-03-27 16:07:37 +00:00
github-actions[bot] c5ffd06837 Update changelog for v4.35.1 2026-03-27 15:39:16 +00:00
Henry Mercer d6d1743b8e Merge pull request #3781 from github/henrymercer/update-git-minimum-version
Update minimum Git version for overlay to 2.36.0
2026-03-27 14:59:36 +00:00
github-actions[bot] 999119ba45 Rebuild 2026-03-27 14:00:54 +00:00
Henry Mercer 65d2efa733 Add changelog note 2026-03-27 14:00:27 +00:00
Henry Mercer 2437b20ab3 Update minimum git version for overlay to 2.36.0 2026-03-27 14:00:17 +00:00
dependabot[bot] f13c600724 Bump brace-expansion from 1.1.12 to 1.1.13
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.12 to 1.1.13.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.13)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.13
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-03-27 13:58:43 +00:00
Henry Mercer 7dcea06663 Remove unused @schemastore/package dependency 2026-03-27 13:57:52 +00:00
Michael B. Gale ea5f71947c Merge pull request #3775 from github/dependabot/npm_and_yarn/node-forge-1.4.0
Bump node-forge from 1.3.3 to 1.4.0
2026-03-27 13:47:55 +00:00
Henry Mercer 45ceeea896 Merge pull request #3777 from github/mergeback/v4.35.0-to-main-b8bb9f28
Mergeback v4.35.0 refs/heads/releases/v4 into main
2026-03-27 13:36:14 +00:00
github-actions[bot] 24448c9843 Rebuild 2026-03-27 12:23:25 +00:00
github-actions[bot] 7c51060631 Update changelog and version after v4.35.0 2026-03-27 12:14:07 +00:00
Óscar San José b8bb9f28b8 Merge pull request #3776 from github/update-v4.35.0-0078ad667
Merge main into releases/v4
2026-03-27 13:11:18 +01:00
github-actions[bot] e9cf68bb33 Update changelog for v4.35.0 2026-03-27 11:44:34 +00:00
github-actions[bot] 36791d8d66 Rebuild 2026-03-27 10:27:12 +00:00
dependabot[bot] 22eba96a28 Bump node-forge from 1.3.3 to 1.4.0
Bumps [node-forge](https://github.com/digitalbazaar/forge) from 1.3.3 to 1.4.0.
- [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md)
- [Commits](https://github.com/digitalbazaar/forge/compare/v1.3.3...v1.4.0)

---
updated-dependencies:
- dependency-name: node-forge
  dependency-version: 1.4.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-03-27 10:25:06 +00:00
Óscar San José 0078ad667e Merge pull request #3773 from github/update-bundle/codeql-bundle-v2.25.1
Update default bundle to 2.25.1
2026-03-27 10:02:52 +00:00
github-actions[bot] fa7a15b909 Add changelog note 2026-03-27 09:43:23 +00:00
github-actions[bot] 8c29faa7ab Update default bundle to codeql-bundle-v2.25.1 2026-03-27 09:43:12 +00:00
Henry Mercer f94817b9f0 Merge pull request #3772 from github/dependabot/npm_and_yarn/yaml-2.8.3
Bump yaml from 2.8.2 to 2.8.3
2026-03-26 19:43:58 +00:00
dependabot[bot] dd060970a5 Bump yaml from 2.8.2 to 2.8.3
Bumps [yaml](https://github.com/eemeli/yaml) from 2.8.2 to 2.8.3.
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](https://github.com/eemeli/yaml/compare/v2.8.2...v2.8.3)

---
updated-dependencies:
- dependency-name: yaml
  dependency-version: 2.8.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-03-26 18:26:45 +00:00
Michael B. Gale 5cc552f43e Merge pull request #3768 from github/dependabot/npm_and_yarn/npm-minor-3536e7c6f0
Bump the npm-minor group with 5 updates
2026-03-26 17:46:04 +00:00
Michael B. Gale 6b1a9f2131 Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-3536e7c6f0 2026-03-26 16:36:54 +00:00
Michael B. Gale 9d3ec5727a Merge pull request #3770 from github/dependabot/github_actions/dot-github/workflows/actions-minor-266139ee1d
Bump ruby/setup-ruby from 1.288.0 to 1.295.0 in /.github/workflows in the actions-minor group across 1 directory
2026-03-26 16:32:19 +00:00
Michael B. Gale 3ff82aacd0 Merge pull request #3575 from github/mbg/ts/sync-checks
Convert `release-branches.py` and `update-required-checks.sh` to TypeScript
2026-03-26 15:47:43 +00:00
Sam Robson 4bdd4e7526 Merge pull request #3554 from github/sam-robson/overlay-include-diff
feat: always include files from diff in overlay changed files
2026-03-26 10:57:24 +00:00
Sam Robson 23a0098b57 fix: improve error handling and logging for diff range path resolution 2026-03-25 19:53:21 +00:00
github-actions[bot] ea7b090925 Rebuild 2026-03-25 18:01:40 +00:00
dependabot[bot] a663d0174a Bump ruby/setup-ruby
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby).


Updates `ruby/setup-ruby` from 1.288.0 to 1.295.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](https://github.com/ruby/setup-ruby/compare/09a7688d3b55cf0e976497ff046b70949eeaccfd...319994f95fa847cf3fb3cd3dbe89f6dcde9f178f)

---
updated-dependencies:
- dependency-name: ruby/setup-ruby
  dependency-version: 1.295.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-03-25 17:59:44 +00:00
dependabot[bot] b659882aae Bump the npm-minor group with 5 updates
Bumps the npm-minor group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [esbuild](https://github.com/evanw/esbuild) | `0.27.3` | `0.27.4` |
| [eslint-plugin-import-x](https://github.com/un-ts/eslint-plugin-import-x) | `4.16.1` | `4.16.2` |
| [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc) | `62.7.1` | `62.8.0` |
| [sinon](https://github.com/sinonjs/sinon) | `21.0.2` | `21.0.3` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.57.0` | `8.57.1` |


Updates `esbuild` from 0.27.3 to 0.27.4
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md)
- [Commits](https://github.com/evanw/esbuild/compare/v0.27.3...v0.27.4)

Updates `eslint-plugin-import-x` from 4.16.1 to 4.16.2
- [Release notes](https://github.com/un-ts/eslint-plugin-import-x/releases)
- [Changelog](https://github.com/un-ts/eslint-plugin-import-x/blob/master/CHANGELOG.md)
- [Commits](https://github.com/un-ts/eslint-plugin-import-x/compare/v4.16.1...v4.16.2)

Updates `eslint-plugin-jsdoc` from 62.7.1 to 62.8.0
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases)
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.7.1...v62.8.0)

Updates `sinon` from 21.0.2 to 21.0.3
- [Release notes](https://github.com/sinonjs/sinon/releases)
- [Changelog](https://github.com/sinonjs/sinon/blob/main/docs/changelog.md)
- [Commits](https://github.com/sinonjs/sinon/compare/v21.0.2...v21.0.3)

Updates `typescript-eslint` from 8.57.0 to 8.57.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.57.1/packages/typescript-eslint)

---
updated-dependencies:
- dependency-name: esbuild
  dependency-version: 0.27.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor
- dependency-name: eslint-plugin-import-x
  dependency-version: 4.16.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
  dependency-version: 62.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor
- dependency-name: sinon
  dependency-version: 21.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor
- dependency-name: typescript-eslint
  dependency-version: 8.57.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-03-25 17:53:49 +00:00
Sam Robson d5bb39fa0b refactor: single source of truth for getDiffRangesJsonFilePath and simplified getDiffRangeFilePaths 2026-03-25 15:51:51 +00:00
Sam Robson 521c3536d3 feat: always include files from diff in overlay changed files 2026-03-25 15:51:51 +00:00
Michael B. Gale 972365e142 Fix comment 2026-03-25 14:15:39 +00:00
Michael B. Gale 8a0b4f2746 fixup! Update CONTRIBUTING.md 2026-03-25 14:14:49 +00:00
Michael B. Gale a5418e172c Delete releases.ini 2026-03-25 13:49:47 +00:00
Michael B. Gale fae4c28b51 Update CONTRIBUTING.md 2026-03-25 13:48:55 +00:00
Michael B. Gale 661a8fbbe3 Default ref to main 2026-03-25 13:40:05 +00:00
Michael B. Gale e7c7b68c5f Remove update-required-checks.sh 2026-03-25 13:38:28 +00:00
Michael B. Gale fa568ebc69 Delete release-branches.py 2026-03-25 13:37:41 +00:00
Michael B. Gale 0da3139813 Rename to branchName 2026-03-25 13:35:02 +00:00
Michael B. Gale 0abe92ed20 Configure ESLint import/no-extraneous-dependencies rule for pr-checks 2026-03-25 13:17:37 +00:00
Michael B. Gale 07f235e5f2 Add --verbose option 2026-03-25 13:17:37 +00:00
Michael B. Gale 9fd40ff508 Tidy up pr-checks/package.json 2026-03-25 13:17:37 +00:00
Michael B. Gale 75ed461aaa Add excluded.yml path to config.ts 2026-03-25 13:16:35 +00:00
Michael B. Gale cfc18781e0 Rebuild 2026-03-25 13:16:34 +00:00
Michael B. Gale 9fe42f69b7 Add some unit tests for sync-checks.ts 2026-03-25 13:16:33 +00:00
Michael B. Gale c5a984e1aa Update CONTRIBUTING.md 2026-03-25 13:16:33 +00:00
Michael B. Gale 0543156694 Actually perform the update when necessary and requested 2026-03-25 13:16:33 +00:00
Michael B. Gale 4cec5d2830 Call updateBranch for main 2026-03-25 13:16:32 +00:00
Michael B. Gale 74dd691a45 Identify changes before applying them 2026-03-25 13:16:32 +00:00
Michael B. Gale a5244bf7dd Fetch release branches and identify major versions 2026-03-25 13:16:32 +00:00
Michael B. Gale 1bc611ed0c Fetch and filter check runs for ref 2026-03-25 13:16:32 +00:00
Michael B. Gale d2008eee7c Add type to represent exclusions.yml and loading helper 2026-03-25 13:16:32 +00:00
Michael B. Gale 9481177f3d Initialise API client 2026-03-25 13:16:31 +00:00
Michael B. Gale 9813849e61 Add initial TS implementation of update-required-checks.sh 2026-03-25 13:16:31 +00:00
Michael B. Gale 4867f5927a Add config file for excluded checks from update-required-checks.sh 2026-03-25 13:16:31 +00:00
Michael B. Gale 49af37b7ab Add tests for release-branches.ts 2026-03-25 13:16:31 +00:00
Michael B. Gale b72f4fec40 Validate inputs 2026-03-25 13:16:30 +00:00
Michael B. Gale 0d87a75829 Refactor backport computation into computeReleaseBranches 2026-03-25 13:16:30 +00:00
Michael B. Gale 3db9a05c73 Replace release-branches.py with TS version in release-branches action 2026-03-25 13:16:30 +00:00
Michael B. Gale aa2773169b Install node in release-initialise action 2026-03-25 13:16:30 +00:00
Michael B. Gale 054745baee Convert release-branches.py to TypeScript 2026-03-25 13:16:30 +00:00
Michael B. Gale 3d564d9359 Merge pull request #3579 from github/mbg/start-proxy/token-check-fixes
Fix warning for PAT-like token with username
2026-03-25 13:02:47 +00:00
Michael B. Gale 137e0dec2b Merge remote-tracking branch 'origin/main' into mbg/start-proxy/token-check-fixes 2026-03-25 12:39:48 +00:00
Michael B. Gale d128e5daa8 Fix test names 2026-03-25 12:39:42 +00:00
Henry Mercer eedab83377 Merge pull request #3767 from github/henrymercer/overlay-reduce-minimum-git-version
Reduce the minimum Git version required for overlay
2026-03-24 11:26:07 +00:00
Henry Mercer 8c023a6b07 Add changelog note 2026-03-23 18:40:55 +00:00
Henry Mercer 28f56f2bed Update minimum Git version required for overlay 2026-03-23 18:36:25 +00:00
Henry Mercer d48d054533 Use --stage instead of --format in git ls-files 2026-03-23 18:33:59 +00:00
Henry Mercer 72c0b0efb7 Merge pull request #3587 from github/dependabot/npm_and_yarn/fast-xml-parser-5.5.7
Bump fast-xml-parser from 5.5.6 to 5.5.7
2026-03-23 14:22:53 +00:00
Henry Mercer 05b1a5d28f Merge pull request #3764 from github/mergeback/v4.34.1-to-main-38697555
Mergeback v4.34.1 refs/heads/releases/v4 into main
2026-03-20 18:38:55 +00:00
github-actions[bot] 8dc2e5d9d2 Rebuild 2026-03-20 18:19:40 +00:00
github-actions[bot] 8fd6c0e573 Update changelog and version after v4.34.1 2026-03-20 18:14:55 +00:00
github-actions[bot] 64507ed148 Rebuild 2026-03-20 01:40:06 +00:00
dependabot[bot] 1a45a9b9d0 Bump fast-xml-parser from 5.5.6 to 5.5.7
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) from 5.5.6 to 5.5.7.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.6...v5.5.7)

---
updated-dependencies:
- dependency-name: fast-xml-parser
  dependency-version: 5.5.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-03-20 01:38:13 +00:00
Michael B. Gale f88d49ee5d Fix warning for PAT-like token with username 2026-03-16 19:34:33 +00:00
Michael B. Gale 28f515d9ad Add tests for the absence of the warning 2026-03-16 19:34:33 +00:00
Michael B. Gale de06821112 Add hasMessage to RecordingLogger 2026-03-16 19:34:33 +00:00
Michael B. Gale ddafddb826 Replace getRecordingLogger implementation with RecordingLogger 2026-03-16 19:34:32 +00:00
Michael B. Gale 740f177889 Add assertNotLogged test helper 2026-03-16 19:34:32 +00:00
Michael B. Gale 0393130759 Add "token without a username" test 2026-03-16 19:34:32 +00:00
Michael B. Gale f86097dfdb Add params for credentials and checkAccepted to testPATWarning 2026-03-16 19:34:32 +00:00
Michael B. Gale 6e67ef61f2 Refactor PAT test into a test.macro 2026-03-16 19:34:32 +00:00
Michael B. Gale 193dd19c2d Add snippet to scaffold test.macros 2026-03-16 19:34:32 +00:00
54 changed files with 7741 additions and 5548 deletions
+2 -1
View File
@@ -22,7 +22,8 @@ runs:
MAJOR_VERSION: ${{ inputs.major_version }} MAJOR_VERSION: ${{ inputs.major_version }}
LATEST_TAG: ${{ inputs.latest_tag }} LATEST_TAG: ${{ inputs.latest_tag }}
run: | run: |
python ${{ github.action_path }}/release-branches.py \ npm ci
npx tsx ./pr-checks/release-branches.ts \
--major-version "$MAJOR_VERSION" \ --major-version "$MAJOR_VERSION" \
--latest-tag "$LATEST_TAG" --latest-tag "$LATEST_TAG"
shell: bash shell: bash
@@ -1,55 +0,0 @@
import argparse
import json
import os
import configparser
# Name of the remote
ORIGIN = 'origin'
script_dir = os.path.dirname(os.path.realpath(__file__))
grandparent_dir = os.path.dirname(os.path.dirname(script_dir))
config = configparser.ConfigParser()
with open(os.path.join(grandparent_dir, 'releases.ini')) as stream:
config.read_string('[default]\n' + stream.read())
OLDEST_SUPPORTED_MAJOR_VERSION = int(config['default']['OLDEST_SUPPORTED_MAJOR_VERSION'])
def main():
parser = argparse.ArgumentParser()
parser.add_argument("--major-version", required=True, type=str, help="The major version of the release")
parser.add_argument("--latest-tag", required=True, type=str, help="The most recent tag published to the repository")
args = parser.parse_args()
major_version = args.major_version
latest_tag = args.latest_tag
print("major_version: " + major_version)
print("latest_tag: " + latest_tag)
# If this is a primary release, we backport to all supported branches,
# so we check whether the major_version taken from the package.json
# is greater than or equal to the latest tag pulled from the repo.
# For example...
# 'v1' >= 'v2' is False # we're operating from an older release branch and should not backport
# 'v2' >= 'v2' is True # the normal case where we're updating the current version
# 'v3' >= 'v2' is True # in this case we are making the first release of a new major version
consider_backports = ( major_version >= latest_tag.split(".")[0] )
with open(os.environ["GITHUB_OUTPUT"], "a") as f:
f.write(f"backport_source_branch=releases/{major_version}\n")
backport_target_branches = []
if consider_backports:
for i in range(int(major_version.strip("v"))-1, 0, -1):
branch_name = f"releases/v{i}"
if i >= OLDEST_SUPPORTED_MAJOR_VERSION:
backport_target_branches.append(branch_name)
f.write("backport_target_branches="+json.dumps(backport_target_branches)+"\n")
if __name__ == "__main__":
main()
@@ -15,6 +15,12 @@ runs:
run: echo "$GITHUB_CONTEXT" run: echo "$GITHUB_CONTEXT"
shell: bash shell: bash
- name: Set up Node
uses: actions/setup-node@v6
with:
node-version: 20
cache: 'npm'
- name: Set up Python - name: Set up Python
uses: actions/setup-python@v6 uses: actions/setup-python@v6
with: with:
-1
View File
@@ -1 +0,0 @@
OLDEST_SUPPORTED_MAJOR_VERSION=3
+1 -1
View File
@@ -59,7 +59,7 @@ jobs:
use-all-platform-bundle: 'false' use-all-platform-bundle: 'false'
setup-kotlin: 'true' setup-kotlin: 'true'
- name: Set up Ruby - name: Set up Ruby
uses: ruby/setup-ruby@09a7688d3b55cf0e976497ff046b70949eeaccfd # v1.288.0 uses: ruby/setup-ruby@319994f95fa847cf3fb3cd3dbe89f6dcde9f178f # v1.295.0
with: with:
ruby-version: 2.6 ruby-version: 2.6
- name: Install Code Scanning integration - name: Install Code Scanning integration
+1 -1
View File
@@ -24,7 +24,7 @@ defaults:
jobs: jobs:
merge-back: merge-back:
runs-on: ubuntu-slim runs-on: ubuntu-latest
environment: Automation environment: Automation
if: github.repository == 'github/codeql-action' if: github.repository == 'github/codeql-action'
env: env:
+5 -1
View File
@@ -54,7 +54,11 @@ jobs:
- name: Run unit tests - name: Run unit tests
if: always() if: always()
run: npm test run: npm run test-coverage
- name: Check code coverage
if: always()
run: npm run coverage
- name: Lint - name: Lint
if: always() && matrix.os != 'windows-latest' if: always() && matrix.os != 'windows-latest'
+1 -1
View File
@@ -29,7 +29,7 @@ defaults:
jobs: jobs:
prepare: prepare:
name: "Prepare release" name: "Prepare release"
runs-on: ubuntu-slim runs-on: ubuntu-latest
if: github.repository == 'github/codeql-action' if: github.repository == 'github/codeql-action'
permissions: permissions:
@@ -1,64 +0,0 @@
#!/usr/bin/env bash
# Update the required checks based on the current branch.
set -euo pipefail
SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" >/dev/null 2>&1 && pwd )"
REPO_DIR="$(dirname "$SCRIPT_DIR")"
GRANDPARENT_DIR="$(dirname "$REPO_DIR")"
source "$GRANDPARENT_DIR/releases.ini"
if ! gh auth status 2>/dev/null; then
gh auth status
echo "Failed: Not authorized. This script requires admin access to github/codeql-action through the gh CLI."
exit 1
fi
if [ "$#" -eq 1 ]; then
# If we were passed an argument, use that as the SHA
GITHUB_SHA="$1"
elif [ "$#" -gt 1 ]; then
echo "Usage: $0 [SHA]"
echo "Update the required checks based on the SHA, or main."
exit 1
elif [ -z "$GITHUB_SHA" ]; then
# If we don't have a SHA, use main
GITHUB_SHA="$(git rev-parse main)"
fi
echo "Getting checks for $GITHUB_SHA"
# Ignore any checks with "https://", CodeQL, LGTM, Update, and ESLint checks.
CHECKS="$(gh api repos/github/codeql-action/commits/"${GITHUB_SHA}"/check-runs --paginate | jq --slurp --compact-output --raw-output '[.[].check_runs.[] | select(.conclusion != "skipped") | .name | select(contains("https://") or . == "CodeQL" or . == "Dependabot" or . == "check-expected-release-files" or contains("Update") or contains("ESLint") or contains("update") or contains("test-setup-python-scripts") or . == "Agent" or . == "Cleanup artifacts" or . == "Prepare" or . == "Upload results" or . == "Label PR with size" | not)] | unique | sort')"
echo "$CHECKS" | jq
# Fail if there are no checks
if [ -z "$CHECKS" ] || [ "$(echo "$CHECKS" | jq '. | length')" -eq 0 ]; then
echo "No checks found for $GITHUB_SHA"
exit 1
fi
echo "{\"contexts\": ${CHECKS}}" > checks.json
echo "Updating main"
gh api --silent -X "PATCH" "repos/github/codeql-action/branches/main/protection/required_status_checks" --input checks.json
# list all branchs on origin remote matching releases/v*
BRANCHES="$(git ls-remote --heads origin 'releases/v*' | sed 's?.*refs/heads/??' | sort -V)"
for BRANCH in $BRANCHES; do
# strip exact 'releases/v' prefix from $BRANCH using count of characters
VERSION="${BRANCH:10}"
if [ "$VERSION" -lt "$OLDEST_SUPPORTED_MAJOR_VERSION" ]; then
echo "Skipping $BRANCH"
continue
fi
echo "Updating $BRANCH"
gh api --silent -X "PATCH" "repos/github/codeql-action/branches/$BRANCH/protection/required_status_checks" --input checks.json
done
rm checks.json
+1 -1
View File
@@ -20,7 +20,7 @@ defaults:
jobs: jobs:
update-bundle: update-bundle:
if: github.event.release.prerelease && startsWith(github.event.release.tag_name, 'codeql-bundle-') if: github.event.release.prerelease && startsWith(github.event.release.tag_name, 'codeql-bundle-')
runs-on: ubuntu-slim runs-on: ubuntu-latest
permissions: permissions:
contents: write # needed to push commits contents: write # needed to push commits
pull-requests: write # needed to create pull requests pull-requests: write # needed to create pull requests
+2 -2
View File
@@ -26,7 +26,7 @@ jobs:
update: update:
timeout-minutes: 45 timeout-minutes: 45
runs-on: ubuntu-slim runs-on: ubuntu-latest
if: github.event_name == 'workflow_dispatch' if: github.event_name == 'workflow_dispatch'
needs: [prepare] needs: [prepare]
env: env:
@@ -77,7 +77,7 @@ jobs:
backport: backport:
timeout-minutes: 45 timeout-minutes: 45
runs-on: ubuntu-slim runs-on: ubuntu-latest
environment: Automation environment: Automation
needs: [prepare] needs: [prepare]
if: ${{ (github.event_name == 'push') && needs.prepare.outputs.backport_target_branches != '[]' }} if: ${{ (github.event_name == 'push') && needs.prepare.outputs.backport_target_branches != '[]' }}
+2
View File
@@ -2,6 +2,8 @@
node_modules/ node_modules/
# Build output for tests # Build output for tests
build/ build/
# Code coverage information
coverage/
# Java build files # Java build files
.gradle/ .gradle/
*.class *.class
+30
View File
@@ -0,0 +1,30 @@
{
// Place your codeql-action workspace snippets here. Each snippet is defined under a snippet name and has a scope, prefix, body and
// description. Add comma separated ids of the languages where the snippet is applicable in the scope field. If scope
// is left empty or omitted, the snippet gets applied to all languages. The prefix is what is
// used to trigger the snippet and the body will be expanded and inserted. Possible variables are:
// $1, $2 for tab stops, $0 for the final cursor position, and ${1:label}, ${2:another} for placeholders.
// Placeholders with the same ids are connected.
// Example:
// "Print to console": {
// "scope": "javascript,typescript",
// "prefix": "log",
// "body": [
// "console.log('$1');",
// "$2"
// ],
// "description": "Log output to console"
// }
"Test Macro": {
"scope": "javascript, typescript",
"prefix": "testMacro",
"body": [
"const ${1:nameMacro} = test.macro({",
" exec: async (t: ExecutionContext<unknown>) => {},",
"",
" title: (providedTitle = \"\") => `${2:common title} - \\${providedTitle}`,",
"});",
],
"description": "An Ava test macro",
},
}
+13
View File
@@ -2,6 +2,19 @@
See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs. See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
## [UNRELEASED]
No user facing changes.
## 4.35.1 - 27 Mar 2026
- Fix incorrect minimum required Git version for [improved incremental analysis](https://github.com/github/roadmap/issues/1158): it should have been 2.36.0, not 2.11.0. [#3781](https://github.com/github/codeql-action/pull/3781)
## 4.35.0 - 27 Mar 2026
- Reduced the minimum Git version required for [improved incremental analysis](https://github.com/github/roadmap/issues/1158) from 2.38.0 to 2.11.0. [#3767](https://github.com/github/codeql-action/pull/3767)
- Update default CodeQL bundle version to [2.25.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.1). [#3773](https://github.com/github/codeql-action/pull/3773)
## 4.34.1 - 20 Mar 2026 ## 4.34.1 - 20 Mar 2026
- Downgrade default CodeQL bundle version to [2.24.3](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3) due to issues with a small percentage of Actions and JavaScript analyses. [#3762](https://github.com/github/codeql-action/pull/3762) - Downgrade default CodeQL bundle version to [2.24.3](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3) due to issues with a small percentage of Actions and JavaScript analyses. [#3762](https://github.com/github/codeql-action/pull/3762)
+7 -5
View File
@@ -69,12 +69,14 @@ Once the mergeback and backport pull request have been merged, the release is co
## Keeping the PR checks up to date (admin access required) ## Keeping the PR checks up to date (admin access required)
Since the `codeql-action` runs most of its testing through individual Actions workflows, there are over two hundred required jobs that need to pass in order for a PR to turn green. It would be too tedious to maintain that list manually. You can regenerate the set of required checks automatically by running the [update-required-checks.sh](.github/workflows/script/update-required-checks.sh) script: Since the `codeql-action` runs most of its testing through individual Actions workflows, there are over two hundred required jobs that need to pass in order for a PR to turn green. It would be too tedious to maintain that list manually. You can regenerate the set of required checks automatically by running the [sync-checks.ts](pr-checks/sync-checks.ts) script:
- If you run the script without an argument, it will retrieve the set of workflows that ran for the latest commit on `main`. Make sure that your local `main` branch is up to date before running the script. - At a minimum, you must provide an argument for the `--token` input. For example, `--token "$(gh auth token)"` to use the same token that `gh` uses. If no token is provided or the token has insufficient permissions, the script will fail.
- You can specify a commit SHA as argument to retrieve the set of workflows for that commit instead. You will likely want to use this if you have a PR that removes or adds PR checks. - By default, the script performs a dry run and outputs information about the changes it would make to the branch protection rules. To actually apply the changes, specify the `--apply` flag.
- If you run the script without any other arguments, it will retrieve the set of workflows that ran for the latest commit on `main`.
- You can specify a different git ref with the `--ref` input. You will likely want to use this if you have a PR that removes or adds PR checks. For example, `--ref "some/branch/name"` to use the HEAD of the `some/branch/name` branch.
After running, go to the [branch protection rules settings page](https://github.com/github/codeql-action/settings/branches) and validate that the rules for `main`, `v3`, and any other currently supported major versions have been updated. After running, go to the [branch protection rules settings page](https://github.com/github/codeql-action/settings/branches) and validate that the rules for `main`, `v4`, and any other currently supported major versions have been updated.
Note that any updates to checks on `main` need to be backported to all currently supported major version branches, in order to maintain the same set of names for required checks. Note that any updates to checks on `main` need to be backported to all currently supported major version branches, in order to maintain the same set of names for required checks.
@@ -122,7 +124,7 @@ To deprecate an older version of the Action:
- Implement an Actions warning for customers using the deprecated version. - Implement an Actions warning for customers using the deprecated version.
1. Wait for the deprecation period to pass. 1. Wait for the deprecation period to pass.
1. Upgrade the Actions warning for customers using the deprecated version to a non-fatal error, and mention that this version of the Action is no longer supported. 1. Upgrade the Actions warning for customers using the deprecated version to a non-fatal error, and mention that this version of the Action is no longer supported.
1. Make a PR to bump the `OLDEST_SUPPORTED_MAJOR_VERSION` in [releases.ini](.github/releases.ini). Once this PR is merged, the release process will no longer backport changes to the deprecated release version. 1. Make a PR to bump the `OLDEST_SUPPORTED_MAJOR_VERSION` in [config.ts](pr-checks/config.ts). Once this PR is merged, the release process will no longer backport changes to the deprecated release version.
## Resources ## Resources
+21 -6
View File
@@ -7,7 +7,11 @@ import noAsyncForeach from "eslint-plugin-no-async-foreach";
import jsdoc from "eslint-plugin-jsdoc"; import jsdoc from "eslint-plugin-jsdoc";
import tseslint from "typescript-eslint"; import tseslint from "typescript-eslint";
import globals from "globals"; import globals from "globals";
import path from "path";
import { fileURLToPath } from "url";
const __filename = fileURLToPath(import.meta.url);
const __dirname = path.dirname(__filename);
const githubFlatConfigs = github.getFlatConfigs(); const githubFlatConfigs = github.getFlatConfigs();
export default [ export default [
@@ -43,7 +47,7 @@ export default [
plugins: { plugins: {
"import-x": importX, "import-x": importX,
"no-async-foreach": fixupPluginRules(noAsyncForeach), "no-async-foreach": fixupPluginRules(noAsyncForeach),
"jsdoc": jsdoc, jsdoc: jsdoc,
}, },
languageOptions: { languageOptions: {
@@ -67,7 +71,13 @@ export default [
typescript: {}, typescript: {},
}, },
"import/ignore": ["sinon", "uuid", "@octokit/plugin-retry", "del", "get-folder-size"], "import/ignore": [
"sinon",
"uuid",
"@octokit/plugin-retry",
"del",
"get-folder-size",
],
"import-x/resolver-next": [ "import-x/resolver-next": [
createTypeScriptImportResolver(), createTypeScriptImportResolver(),
createNodeResolver({ createNodeResolver({
@@ -143,7 +153,7 @@ export default [
// We don't currently require full JSDoc coverage, so this rule // We don't currently require full JSDoc coverage, so this rule
// should not error on missing @param annotations. // should not error on missing @param annotations.
disableMissingParamChecks: true, disableMissingParamChecks: true,
} },
], ],
}, },
}, },
@@ -162,9 +172,9 @@ export default [
"@typescript-eslint/no-unused-vars": [ "@typescript-eslint/no-unused-vars": [
"error", "error",
{ {
"args": "all", args: "all",
"argsIgnorePattern": "^_", argsIgnorePattern: "^_",
} },
], ],
"func-style": "off", "func-style": "off",
}, },
@@ -183,6 +193,11 @@ export default [
// The scripts in `pr-checks` are expected to output to the console. // The scripts in `pr-checks` are expected to output to the console.
"no-console": "off", "no-console": "off",
"import/no-extraneous-dependencies": [
"error",
{ packageDir: [__dirname, path.resolve(__dirname, "pr-checks")] },
],
"@typescript-eslint/no-floating-promises": [ "@typescript-eslint/no-floating-promises": [
"error", "error",
{ {
+1283 -1199
View File
File diff suppressed because it is too large Load Diff
+456 -531
View File
File diff suppressed because it is too large Load Diff
+740 -656
View File
File diff suppressed because it is too large Load Diff
+4 -4
View File
@@ -1,6 +1,6 @@
{ {
"bundleVersion": "codeql-bundle-v2.24.3", "bundleVersion": "codeql-bundle-v2.25.1",
"cliVersion": "2.24.3", "cliVersion": "2.25.1",
"priorBundleVersion": "codeql-bundle-v2.24.2", "priorBundleVersion": "codeql-bundle-v2.24.3",
"priorCliVersion": "2.24.2" "priorCliVersion": "2.24.3"
} }
+735 -649
View File
File diff suppressed because it is too large Load Diff
+416 -195
View File
File diff suppressed because it is too large Load Diff
+736 -652
View File
File diff suppressed because it is too large Load Diff
+185 -102
View File
@@ -41057,18 +41057,18 @@ var init_dist_src2 = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js
var VERSION5; var VERSION5;
var init_version2 = __esm({ var init_version2 = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js"() {
VERSION5 = "17.0.0"; VERSION5 = "17.0.0";
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js
var Endpoints, endpoints_default; var Endpoints, endpoints_default;
var init_endpoints = __esm({ var init_endpoints = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js"() {
Endpoints = { Endpoints = {
actions: { actions: {
addCustomLabelsToSelfHostedRunnerForOrg: [ addCustomLabelsToSelfHostedRunnerForOrg: [
@@ -43362,7 +43362,7 @@ var init_endpoints = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js
function endpointsToMethods(octokit) { function endpointsToMethods(octokit) {
const newMethods = {}; const newMethods = {};
for (const scope of endpointMethodsMap.keys()) { for (const scope of endpointMethodsMap.keys()) {
@@ -43413,7 +43413,7 @@ function decorate(octokit, scope, methodName, defaults, decorations) {
} }
var endpointMethodsMap, handler; var endpointMethodsMap, handler;
var init_endpoints_to_methods = __esm({ var init_endpoints_to_methods = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js"() {
init_endpoints(); init_endpoints();
endpointMethodsMap = /* @__PURE__ */ new Map(); endpointMethodsMap = /* @__PURE__ */ new Map();
for (const [scope, endpoints] of Object.entries(endpoints_default)) { for (const [scope, endpoints] of Object.entries(endpoints_default)) {
@@ -43491,7 +43491,7 @@ var init_endpoints_to_methods = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js
var dist_src_exports2 = {}; var dist_src_exports2 = {};
__export(dist_src_exports2, { __export(dist_src_exports2, {
legacyRestEndpointMethods: () => legacyRestEndpointMethods, legacyRestEndpointMethods: () => legacyRestEndpointMethods,
@@ -43511,7 +43511,7 @@ function legacyRestEndpointMethods(octokit) {
}; };
} }
var init_dist_src3 = __esm({ var init_dist_src3 = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js"() {
init_version2(); init_version2();
init_endpoints_to_methods(); init_endpoints_to_methods();
restEndpointMethods.VERSION = VERSION5; restEndpointMethods.VERSION = VERSION5;
@@ -43519,7 +43519,7 @@ var init_dist_src3 = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js // node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js
var dist_bundle_exports = {}; var dist_bundle_exports = {};
__export(dist_bundle_exports, { __export(dist_bundle_exports, {
composePaginateRest: () => composePaginateRest, composePaginateRest: () => composePaginateRest,
@@ -43645,7 +43645,7 @@ function paginateRest(octokit) {
} }
var VERSION6, composePaginateRest, paginatingEndpoints; var VERSION6, composePaginateRest, paginatingEndpoints;
var init_dist_bundle5 = __esm({ var init_dist_bundle5 = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js"() { "node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js"() {
VERSION6 = "0.0.0-development"; VERSION6 = "0.0.0-development";
composePaginateRest = Object.assign(paginate, { composePaginateRest = Object.assign(paginate, {
iterator iterator
@@ -47805,7 +47805,7 @@ var require_brace_expansion = __commonJS({
var x = numeric(n[0]); var x = numeric(n[0]);
var y = numeric(n[1]); var y = numeric(n[1]);
var width = Math.max(n[0].length, n[1].length); var width = Math.max(n[0].length, n[1].length);
var incr = n.length == 3 ? Math.abs(numeric(n[2])) : 1; var incr = n.length == 3 ? Math.max(Math.abs(numeric(n[2])), 1) : 1;
var test = lte; var test = lte;
var reverse = y < x; var reverse = y < x;
if (reverse) { if (reverse) {
@@ -60732,7 +60732,7 @@ var require_fxp = __commonJS({
if (a.some((t3) => i2 === t3.toLowerCase())) throw new Error(`[SECURITY] Invalid ${e2}: "${t2}" is a reserved JavaScript keyword that could cause prototype pollution`); if (a.some((t3) => i2 === t3.toLowerCase())) throw new Error(`[SECURITY] Invalid ${e2}: "${t2}" is a reserved JavaScript keyword that could cause prototype pollution`);
} }
function A(t2) { function A(t2) {
return "boolean" == typeof t2 ? { enabled: t2, maxEntitySize: 1e4, maxExpansionDepth: 10, maxTotalExpansions: 1e3, maxExpandedLength: 1e5, maxEntityCount: 100, allowedTags: null, tagFilter: null } : "object" == typeof t2 && null !== t2 ? { enabled: false !== t2.enabled, maxEntitySize: t2.maxEntitySize ?? 1e4, maxExpansionDepth: t2.maxExpansionDepth ?? 10, maxTotalExpansions: t2.maxTotalExpansions ?? 1e3, maxExpandedLength: t2.maxExpandedLength ?? 1e5, maxEntityCount: t2.maxEntityCount ?? 100, allowedTags: t2.allowedTags ?? null, tagFilter: t2.tagFilter ?? null } : A(true); return "boolean" == typeof t2 ? { enabled: t2, maxEntitySize: 1e4, maxExpansionDepth: 10, maxTotalExpansions: 1e3, maxExpandedLength: 1e5, maxEntityCount: 100, allowedTags: null, tagFilter: null } : "object" == typeof t2 && null !== t2 ? { enabled: false !== t2.enabled, maxEntitySize: Math.max(1, t2.maxEntitySize ?? 1e4), maxExpansionDepth: Math.max(1, t2.maxExpansionDepth ?? 10), maxTotalExpansions: Math.max(1, t2.maxTotalExpansions ?? 1e3), maxExpandedLength: Math.max(1, t2.maxExpandedLength ?? 1e5), maxEntityCount: Math.max(1, t2.maxEntityCount ?? 100), allowedTags: t2.allowedTags ?? null, tagFilter: t2.tagFilter ?? null } : A(true);
} }
const C = function(t2) { const C = function(t2) {
const e2 = Object.assign({}, P, t2), i2 = [{ value: e2.attributeNamePrefix, name: "attributeNamePrefix" }, { value: e2.attributesGroupName, name: "attributesGroupName" }, { value: e2.textNodeName, name: "textNodeName" }, { value: e2.cdataPropName, name: "cdataPropName" }, { value: e2.commentPropName, name: "commentPropName" }]; const e2 = Object.assign({}, P, t2), i2 = [{ value: e2.attributeNamePrefix, name: "attributeNamePrefix" }, { value: e2.attributesGroupName, name: "attributesGroupName" }, { value: e2.textNodeName, name: "textNodeName" }, { value: e2.cdataPropName, name: "cdataPropName" }, { value: e2.commentPropName, name: "commentPropName" }];
@@ -60773,7 +60773,7 @@ var require_fxp = __commonJS({
if (r2 && _(t2, "!ENTITY", e2)) { if (r2 && _(t2, "!ENTITY", e2)) {
let s3, r3; let s3, r3;
if (e2 += 7, [s3, r3, e2] = this.readEntityExp(t2, e2 + 1, this.suppressValidationErr), -1 === r3.indexOf("&")) { if (e2 += 7, [s3, r3, e2] = this.readEntityExp(t2, e2 + 1, this.suppressValidationErr), -1 === r3.indexOf("&")) {
if (false !== this.options.enabled && this.options.maxEntityCount && n2 >= this.options.maxEntityCount) throw new Error(`Entity count (${n2 + 1}) exceeds maximum allowed (${this.options.maxEntityCount})`); if (false !== this.options.enabled && null != this.options.maxEntityCount && n2 >= this.options.maxEntityCount) throw new Error(`Entity count (${n2 + 1}) exceeds maximum allowed (${this.options.maxEntityCount})`);
const t3 = s3.replace(/[.*+?^${}()|[\]\\]/g, "\\$&"); const t3 = s3.replace(/[.*+?^${}()|[\]\\]/g, "\\$&");
i2[s3] = { regx: RegExp(`&${t3};`, "g"), val: r3 }, n2++; i2[s3] = { regx: RegExp(`&${t3};`, "g"), val: r3 }, n2++;
} }
@@ -60797,82 +60797,86 @@ var require_fxp = __commonJS({
return { entities: i2, i: e2 }; return { entities: i2, i: e2 };
} }
readEntityExp(t2, e2) { readEntityExp(t2, e2) {
e2 = j(t2, e2); const i2 = e2 = j(t2, e2);
let i2 = ""; for (; e2 < t2.length && !/\s/.test(t2[e2]) && '"' !== t2[e2] && "'" !== t2[e2]; ) e2++;
for (; e2 < t2.length && !/\s/.test(t2[e2]) && '"' !== t2[e2] && "'" !== t2[e2]; ) i2 += t2[e2], e2++; let n2 = t2.substring(i2, e2);
if (D(i2), e2 = j(t2, e2), !this.suppressValidationErr) { if (D(n2), e2 = j(t2, e2), !this.suppressValidationErr) {
if ("SYSTEM" === t2.substring(e2, e2 + 6).toUpperCase()) throw new Error("External entities are not supported"); if ("SYSTEM" === t2.substring(e2, e2 + 6).toUpperCase()) throw new Error("External entities are not supported");
if ("%" === t2[e2]) throw new Error("Parameter entities are not supported"); if ("%" === t2[e2]) throw new Error("Parameter entities are not supported");
} }
let n2 = ""; let s2 = "";
if ([e2, n2] = this.readIdentifierVal(t2, e2, "entity"), false !== this.options.enabled && this.options.maxEntitySize && n2.length > this.options.maxEntitySize) throw new Error(`Entity "${i2}" size (${n2.length}) exceeds maximum allowed size (${this.options.maxEntitySize})`); if ([e2, s2] = this.readIdentifierVal(t2, e2, "entity"), false !== this.options.enabled && null != this.options.maxEntitySize && s2.length > this.options.maxEntitySize) throw new Error(`Entity "${n2}" size (${s2.length}) exceeds maximum allowed size (${this.options.maxEntitySize})`);
return [i2, n2, --e2]; return [n2, s2, --e2];
} }
readNotationExp(t2, e2) { readNotationExp(t2, e2) {
e2 = j(t2, e2); const i2 = e2 = j(t2, e2);
let i2 = ""; for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) i2 += t2[e2], e2++; let n2 = t2.substring(i2, e2);
!this.suppressValidationErr && D(i2), e2 = j(t2, e2); !this.suppressValidationErr && D(n2), e2 = j(t2, e2);
const n2 = t2.substring(e2, e2 + 6).toUpperCase(); const s2 = t2.substring(e2, e2 + 6).toUpperCase();
if (!this.suppressValidationErr && "SYSTEM" !== n2 && "PUBLIC" !== n2) throw new Error(`Expected SYSTEM or PUBLIC, found "${n2}"`); if (!this.suppressValidationErr && "SYSTEM" !== s2 && "PUBLIC" !== s2) throw new Error(`Expected SYSTEM or PUBLIC, found "${s2}"`);
e2 += n2.length, e2 = j(t2, e2); e2 += s2.length, e2 = j(t2, e2);
let s2 = null, r2 = null; let r2 = null, o2 = null;
if ("PUBLIC" === n2) [e2, s2] = this.readIdentifierVal(t2, e2, "publicIdentifier"), '"' !== t2[e2 = j(t2, e2)] && "'" !== t2[e2] || ([e2, r2] = this.readIdentifierVal(t2, e2, "systemIdentifier")); if ("PUBLIC" === s2) [e2, r2] = this.readIdentifierVal(t2, e2, "publicIdentifier"), '"' !== t2[e2 = j(t2, e2)] && "'" !== t2[e2] || ([e2, o2] = this.readIdentifierVal(t2, e2, "systemIdentifier"));
else if ("SYSTEM" === n2 && ([e2, r2] = this.readIdentifierVal(t2, e2, "systemIdentifier"), !this.suppressValidationErr && !r2)) throw new Error("Missing mandatory system identifier for SYSTEM notation"); else if ("SYSTEM" === s2 && ([e2, o2] = this.readIdentifierVal(t2, e2, "systemIdentifier"), !this.suppressValidationErr && !o2)) throw new Error("Missing mandatory system identifier for SYSTEM notation");
return { notationName: i2, publicIdentifier: s2, systemIdentifier: r2, index: --e2 }; return { notationName: n2, publicIdentifier: r2, systemIdentifier: o2, index: --e2 };
} }
readIdentifierVal(t2, e2, i2) { readIdentifierVal(t2, e2, i2) {
let n2 = ""; let n2 = "";
const s2 = t2[e2]; const s2 = t2[e2];
if ('"' !== s2 && "'" !== s2) throw new Error(`Expected quoted string, found "${s2}"`); if ('"' !== s2 && "'" !== s2) throw new Error(`Expected quoted string, found "${s2}"`);
for (e2++; e2 < t2.length && t2[e2] !== s2; ) n2 += t2[e2], e2++; const r2 = ++e2;
if (t2[e2] !== s2) throw new Error(`Unterminated ${i2} value`); for (; e2 < t2.length && t2[e2] !== s2; ) e2++;
if (n2 = t2.substring(r2, e2), t2[e2] !== s2) throw new Error(`Unterminated ${i2} value`);
return [++e2, n2]; return [++e2, n2];
} }
readElementExp(t2, e2) { readElementExp(t2, e2) {
e2 = j(t2, e2); const i2 = e2 = j(t2, e2);
let i2 = ""; for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) i2 += t2[e2], e2++; let n2 = t2.substring(i2, e2);
if (!this.suppressValidationErr && !r(i2)) throw new Error(`Invalid element name: "${i2}"`); if (!this.suppressValidationErr && !r(n2)) throw new Error(`Invalid element name: "${n2}"`);
let n2 = ""; let s2 = "";
if ("E" === t2[e2 = j(t2, e2)] && _(t2, "MPTY", e2)) e2 += 4; if ("E" === t2[e2 = j(t2, e2)] && _(t2, "MPTY", e2)) e2 += 4;
else if ("A" === t2[e2] && _(t2, "NY", e2)) e2 += 2; else if ("A" === t2[e2] && _(t2, "NY", e2)) e2 += 2;
else if ("(" === t2[e2]) { else if ("(" === t2[e2]) {
for (e2++; e2 < t2.length && ")" !== t2[e2]; ) n2 += t2[e2], e2++; const i3 = ++e2;
if (")" !== t2[e2]) throw new Error("Unterminated content model"); for (; e2 < t2.length && ")" !== t2[e2]; ) e2++;
if (s2 = t2.substring(i3, e2), ")" !== t2[e2]) throw new Error("Unterminated content model");
} else if (!this.suppressValidationErr) throw new Error(`Invalid Element Expression, found "${t2[e2]}"`); } else if (!this.suppressValidationErr) throw new Error(`Invalid Element Expression, found "${t2[e2]}"`);
return { elementName: i2, contentModel: n2.trim(), index: e2 }; return { elementName: n2, contentModel: s2.trim(), index: e2 };
} }
readAttlistExp(t2, e2) { readAttlistExp(t2, e2) {
let i2 = e2 = j(t2, e2);
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
let n2 = t2.substring(i2, e2);
for (D(n2), i2 = e2 = j(t2, e2); e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
let s2 = t2.substring(i2, e2);
if (!D(s2)) throw new Error(`Invalid attribute name: "${s2}"`);
e2 = j(t2, e2); e2 = j(t2, e2);
let i2 = ""; let r2 = "";
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) i2 += t2[e2], e2++;
D(i2), e2 = j(t2, e2);
let n2 = "";
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) n2 += t2[e2], e2++;
if (!D(n2)) throw new Error(`Invalid attribute name: "${n2}"`);
e2 = j(t2, e2);
let s2 = "";
if ("NOTATION" === t2.substring(e2, e2 + 8).toUpperCase()) { if ("NOTATION" === t2.substring(e2, e2 + 8).toUpperCase()) {
if (s2 = "NOTATION", "(" !== t2[e2 = j(t2, e2 += 8)]) throw new Error(`Expected '(', found "${t2[e2]}"`); if (r2 = "NOTATION", "(" !== t2[e2 = j(t2, e2 += 8)]) throw new Error(`Expected '(', found "${t2[e2]}"`);
e2++; e2++;
let i3 = []; let i3 = [];
for (; e2 < t2.length && ")" !== t2[e2]; ) { for (; e2 < t2.length && ")" !== t2[e2]; ) {
let n3 = ""; const n3 = e2;
for (; e2 < t2.length && "|" !== t2[e2] && ")" !== t2[e2]; ) n3 += t2[e2], e2++; for (; e2 < t2.length && "|" !== t2[e2] && ")" !== t2[e2]; ) e2++;
if (n3 = n3.trim(), !D(n3)) throw new Error(`Invalid notation name: "${n3}"`); let s3 = t2.substring(n3, e2);
i3.push(n3), "|" === t2[e2] && (e2++, e2 = j(t2, e2)); if (s3 = s3.trim(), !D(s3)) throw new Error(`Invalid notation name: "${s3}"`);
i3.push(s3), "|" === t2[e2] && (e2++, e2 = j(t2, e2));
} }
if (")" !== t2[e2]) throw new Error("Unterminated list of notations"); if (")" !== t2[e2]) throw new Error("Unterminated list of notations");
e2++, s2 += " (" + i3.join("|") + ")"; e2++, r2 += " (" + i3.join("|") + ")";
} else { } else {
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) s2 += t2[e2], e2++; const i3 = e2;
const i3 = ["CDATA", "ID", "IDREF", "IDREFS", "ENTITY", "ENTITIES", "NMTOKEN", "NMTOKENS"]; for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
if (!this.suppressValidationErr && !i3.includes(s2.toUpperCase())) throw new Error(`Invalid attribute type: "${s2}"`); r2 += t2.substring(i3, e2);
const n3 = ["CDATA", "ID", "IDREF", "IDREFS", "ENTITY", "ENTITIES", "NMTOKEN", "NMTOKENS"];
if (!this.suppressValidationErr && !n3.includes(r2.toUpperCase())) throw new Error(`Invalid attribute type: "${r2}"`);
} }
e2 = j(t2, e2); e2 = j(t2, e2);
let r2 = ""; let o2 = "";
return "#REQUIRED" === t2.substring(e2, e2 + 8).toUpperCase() ? (r2 = "#REQUIRED", e2 += 8) : "#IMPLIED" === t2.substring(e2, e2 + 7).toUpperCase() ? (r2 = "#IMPLIED", e2 += 7) : [e2, r2] = this.readIdentifierVal(t2, e2, "ATTLIST"), { elementName: i2, attributeName: n2, attributeType: s2, defaultValue: r2, index: e2 }; return "#REQUIRED" === t2.substring(e2, e2 + 8).toUpperCase() ? (o2 = "#REQUIRED", e2 += 8) : "#IMPLIED" === t2.substring(e2, e2 + 7).toUpperCase() ? (o2 = "#IMPLIED", e2 += 7) : [e2, o2] = this.readIdentifierVal(t2, e2, "ATTLIST"), { elementName: n2, attributeName: s2, attributeType: r2, defaultValue: o2, index: e2 };
} }
} }
const j = (t2, e2) => { const j = (t2, e2) => {
@@ -60887,9 +60891,9 @@ var require_fxp = __commonJS({
if (r(t2)) return t2; if (r(t2)) return t2;
throw new Error(`Invalid entity name ${t2}`); throw new Error(`Invalid entity name ${t2}`);
} }
const V = /^[-+]?0x[a-fA-F0-9]+$/, k = /^([\-\+])?(0*)([0-9]*(\.[0-9]*)?)$/, F = { hex: true, leadingZeros: true, decimalPoint: ".", eNotation: true }; const V = /^[-+]?0x[a-fA-F0-9]+$/, k = /^([\-\+])?(0*)([0-9]*(\.[0-9]*)?)$/, M = { hex: true, leadingZeros: true, decimalPoint: ".", eNotation: true, infinity: "original" };
const L = /^([-+])?(0*)(\d*(\.\d*)?[eE][-\+]?\d+)$/; const F = /^([-+])?(0*)(\d*(\.\d*)?[eE][-\+]?\d+)$/;
class M { class L {
constructor(t2 = {}) { constructor(t2 = {}) {
this.separator = t2.separator || ".", this.path = [], this.siblingStacks = []; this.separator = t2.separator || ".", this.path = [], this.siblingStacks = [];
} }
@@ -61096,7 +61100,7 @@ var require_fxp = __commonJS({
if ("string" == typeof i2 && t3 === i2) return true; if ("string" == typeof i2 && t3 === i2) return true;
if (i2 instanceof RegExp && i2.test(t3)) return true; if (i2 instanceof RegExp && i2.test(t3)) return true;
} }
} : () => false, this.entityExpansionCount = 0, this.currentExpandedLength = 0, this.matcher = new M(), this.isCurrentNodeStopNode = false, this.options.stopNodes && this.options.stopNodes.length > 0) { } : () => false, this.entityExpansionCount = 0, this.currentExpandedLength = 0, this.matcher = new L(), this.isCurrentNodeStopNode = false, this.options.stopNodes && this.options.stopNodes.length > 0) {
this.stopNodeExpressions = []; this.stopNodeExpressions = [];
for (let t3 = 0; t3 < this.options.stopNodes.length; t3++) { for (let t3 = 0; t3 < this.options.stopNodes.length; t3++) {
const e3 = this.options.stopNodes[t3]; const e3 = this.options.stopNodes[t3];
@@ -61207,7 +61211,7 @@ var require_fxp = __commonJS({
let o2 = s3.tagName; let o2 = s3.tagName;
const a2 = s3.rawTagName; const a2 = s3.rawTagName;
let h2 = s3.tagExp, l2 = s3.attrExpPresent, p2 = s3.closeIndex; let h2 = s3.tagExp, l2 = s3.attrExpPresent, p2 = s3.closeIndex;
if ({ tagName: o2, tagExp: h2 } = rt(this.options.transformTagName, o2, h2, this.options), this.options.strictReservedNames && (o2 === this.options.commentPropName || o2 === this.options.cdataPropName)) throw new Error(`Invalid tag name: ${o2}`); if ({ tagName: o2, tagExp: h2 } = rt(this.options.transformTagName, o2, h2, this.options), this.options.strictReservedNames && (o2 === this.options.commentPropName || o2 === this.options.cdataPropName || o2 === this.options.textNodeName || o2 === this.options.attributesGroupName)) throw new Error(`Invalid tag name: ${o2}`);
i2 && n2 && "!xml" !== i2.tagname && (n2 = this.saveTextToParentTag(n2, i2, this.matcher, false)); i2 && n2 && "!xml" !== i2.tagname && (n2 = this.saveTextToParentTag(n2, i2, this.matcher, false));
const u2 = i2; const u2 = i2;
u2 && -1 !== this.options.unpairedTags.indexOf(u2.tagname) && (i2 = this.tagsNodeStack.pop(), this.matcher.pop()); u2 && -1 !== this.options.unpairedTags.indexOf(u2.tagname) && (i2 = this.tagsNodeStack.pop(), this.matcher.pop());
@@ -61345,7 +61349,7 @@ var require_fxp = __commonJS({
if (e2 && "string" == typeof t2) { if (e2 && "string" == typeof t2) {
const e3 = t2.trim(); const e3 = t2.trim();
return "true" === e3 || "false" !== e3 && (function(t3, e4 = {}) { return "true" === e3 || "false" !== e3 && (function(t3, e4 = {}) {
if (e4 = Object.assign({}, F, e4), !t3 || "string" != typeof t3) return t3; if (e4 = Object.assign({}, M, e4), !t3 || "string" != typeof t3) return t3;
let i3 = t3.trim(); let i3 = t3.trim();
if (void 0 !== e4.skipLike && e4.skipLike.test(i3)) return t3; if (void 0 !== e4.skipLike && e4.skipLike.test(i3)) return t3;
if ("0" === t3) return 0; if ("0" === t3) return 0;
@@ -61355,35 +61359,50 @@ var require_fxp = __commonJS({
if (window && window.parseInt) return window.parseInt(t4, 16); if (window && window.parseInt) return window.parseInt(t4, 16);
throw new Error("parseInt, Number.parseInt, window.parseInt are not supported"); throw new Error("parseInt, Number.parseInt, window.parseInt are not supported");
})(i3); })(i3);
if (i3.includes("e") || i3.includes("E")) return (function(t4, e5, i4) { if (isFinite(i3)) {
if (!i4.eNotation) return t4; if (i3.includes("e") || i3.includes("E")) return (function(t4, e5, i4) {
const n3 = e5.match(L); if (!i4.eNotation) return t4;
if (n3) { const n3 = e5.match(F);
let s2 = n3[1] || ""; if (n3) {
const r2 = -1 === n3[3].indexOf("e") ? "E" : "e", o2 = n3[2], a2 = s2 ? t4[o2.length + 1] === r2 : t4[o2.length] === r2; let s2 = n3[1] || "";
return o2.length > 1 && a2 ? t4 : 1 !== o2.length || !n3[3].startsWith(`.${r2}`) && n3[3][0] !== r2 ? i4.leadingZeros && !a2 ? (e5 = (n3[1] || "") + n3[3], Number(e5)) : t4 : Number(e5); const r2 = -1 === n3[3].indexOf("e") ? "E" : "e", o2 = n3[2], a2 = s2 ? t4[o2.length + 1] === r2 : t4[o2.length] === r2;
} return o2.length > 1 && a2 ? t4 : (1 !== o2.length || !n3[3].startsWith(`.${r2}`) && n3[3][0] !== r2) && o2.length > 0 ? i4.leadingZeros && !a2 ? (e5 = (n3[1] || "") + n3[3], Number(e5)) : t4 : Number(e5);
return t4;
})(t3, i3, e4);
{
const s2 = k.exec(i3);
if (s2) {
const r2 = s2[1] || "", o2 = s2[2];
let a2 = (n2 = s2[3]) && -1 !== n2.indexOf(".") ? ("." === (n2 = n2.replace(/0+$/, "")) ? n2 = "0" : "." === n2[0] ? n2 = "0" + n2 : "." === n2[n2.length - 1] && (n2 = n2.substring(0, n2.length - 1)), n2) : n2;
const h2 = r2 ? "." === t3[o2.length + 1] : "." === t3[o2.length];
if (!e4.leadingZeros && (o2.length > 1 || 1 === o2.length && !h2)) return t3;
{
const n3 = Number(i3), s3 = String(n3);
if (0 === n3) return n3;
if (-1 !== s3.search(/[eE]/)) return e4.eNotation ? n3 : t3;
if (-1 !== i3.indexOf(".")) return "0" === s3 || s3 === a2 || s3 === `${r2}${a2}` ? n3 : t3;
let h3 = o2 ? a2 : i3;
return o2 ? h3 === s3 || r2 + h3 === s3 ? n3 : t3 : h3 === s3 || h3 === r2 + s3 ? n3 : t3;
} }
return t4;
})(t3, i3, e4);
{
const s2 = k.exec(i3);
if (s2) {
const r2 = s2[1] || "", o2 = s2[2];
let a2 = (n2 = s2[3]) && -1 !== n2.indexOf(".") ? ("." === (n2 = n2.replace(/0+$/, "")) ? n2 = "0" : "." === n2[0] ? n2 = "0" + n2 : "." === n2[n2.length - 1] && (n2 = n2.substring(0, n2.length - 1)), n2) : n2;
const h2 = r2 ? "." === t3[o2.length + 1] : "." === t3[o2.length];
if (!e4.leadingZeros && (o2.length > 1 || 1 === o2.length && !h2)) return t3;
{
const n3 = Number(i3), s3 = String(n3);
if (0 === n3) return n3;
if (-1 !== s3.search(/[eE]/)) return e4.eNotation ? n3 : t3;
if (-1 !== i3.indexOf(".")) return "0" === s3 || s3 === a2 || s3 === `${r2}${a2}` ? n3 : t3;
let h3 = o2 ? a2 : i3;
return o2 ? h3 === s3 || r2 + h3 === s3 ? n3 : t3 : h3 === s3 || h3 === r2 + s3 ? n3 : t3;
}
}
return t3;
} }
return t3;
} }
var n2; var n2;
return (function(t4, e5, i4) {
const n3 = e5 === 1 / 0;
switch (i4.infinity.toLowerCase()) {
case "null":
return null;
case "infinity":
return e5;
case "string":
return n3 ? "Infinity" : "-Infinity";
default:
return t4;
}
})(t3, Number(i3), e4);
})(t2, i2); })(t2, i2);
} }
return void 0 !== t2 ? t2 : ""; return void 0 !== t2 ? t2 : "";
@@ -61495,7 +61514,7 @@ var require_fxp = __commonJS({
const i3 = e2.stopNodes[t3]; const i3 = e2.stopNodes[t3];
"string" == typeof i3 ? n2.push(new G(i3)) : i3 instanceof G && n2.push(i3); "string" == typeof i3 ? n2.push(new G(i3)) : i3 instanceof G && n2.push(i3);
} }
return mt(t2, e2, i2, new M(), n2); return mt(t2, e2, i2, new L(), n2);
} }
function mt(t2, e2, i2, n2, s2) { function mt(t2, e2, i2, n2, s2) {
let r2 = "", o2 = false; let r2 = "", o2 = false;
@@ -61643,7 +61662,7 @@ var require_fxp = __commonJS({
if (this.options.preserveOrder) return gt(t2, this.options); if (this.options.preserveOrder) return gt(t2, this.options);
{ {
Array.isArray(t2) && this.options.arrayNodeName && this.options.arrayNodeName.length > 1 && (t2 = { [this.options.arrayNodeName]: t2 }); Array.isArray(t2) && this.options.arrayNodeName && this.options.arrayNodeName.length > 1 && (t2 = { [this.options.arrayNodeName]: t2 });
const e2 = new M(); const e2 = new L();
return this.j2x(t2, 0, e2).val; return this.j2x(t2, 0, e2).val;
} }
}, Pt.prototype.j2x = function(t2, e2, i2) { }, Pt.prototype.j2x = function(t2, e2, i2) {
@@ -100521,8 +100540,8 @@ var require_follow_redirects = __commonJS({
} }
return parsed; return parsed;
} }
function resolveUrl(relative2, base) { function resolveUrl(relative3, base) {
return useNativeURL ? new URL2(relative2, base) : parseUrl2(url.resolve(base, relative2)); return useNativeURL ? new URL2(relative3, base) : parseUrl2(url.resolve(base, relative3));
} }
function validateUrl(input) { function validateUrl(input) {
if (/^\[/.test(input.hostname) && !/^\[[:0-9a-f]+\]$/i.test(input.hostname)) { if (/^\[/.test(input.hostname) && !/^\[[:0-9a-f]+\]$/i.test(input.hostname)) {
@@ -103605,8 +103624,12 @@ function getTemporaryDirectory() {
const value = process.env["CODEQL_ACTION_TEMP"]; const value = process.env["CODEQL_ACTION_TEMP"];
return value !== void 0 && value !== "" ? value : getRequiredEnvParam("RUNNER_TEMP"); return value !== void 0 && value !== "" ? value : getRequiredEnvParam("RUNNER_TEMP");
} }
var PR_DIFF_RANGE_JSON_FILENAME = "pr-diff-range.json";
function getDiffRangesJsonFilePath() {
return path2.join(getTemporaryDirectory(), PR_DIFF_RANGE_JSON_FILENAME);
}
function getActionVersion() { function getActionVersion() {
return "4.34.1"; return "4.35.2";
} }
function getWorkflowEventName() { function getWorkflowEventName() {
return getRequiredEnvParam("GITHUB_EVENT_NAME"); return getRequiredEnvParam("GITHUB_EVENT_NAME");
@@ -103961,8 +103984,8 @@ var path4 = __toESM(require("path"));
var semver4 = __toESM(require_semver2()); var semver4 = __toESM(require_semver2());
// src/defaults.json // src/defaults.json
var bundleVersion = "codeql-bundle-v2.24.3"; var bundleVersion = "codeql-bundle-v2.25.1";
var cliVersion = "2.24.3"; var cliVersion = "2.25.1";
// src/overlay/index.ts // src/overlay/index.ts
var fs3 = __toESM(require("fs")); var fs3 = __toESM(require("fs"));
@@ -104050,14 +104073,26 @@ var decodeGitFilePath = function(filePath) {
} }
return filePath; return filePath;
}; };
var getGitRoot = async function(sourceRoot) {
try {
const stdout = await runGitCommand(
sourceRoot,
["rev-parse", "--show-toplevel"],
`Cannot find Git repository root from the source root ${sourceRoot}.`
);
return stdout.trim();
} catch {
return void 0;
}
};
var getFileOidsUnderPath = async function(basePath) { var getFileOidsUnderPath = async function(basePath) {
const stdout = await runGitCommand( const stdout = await runGitCommand(
basePath, basePath,
["ls-files", "--recurse-submodules", "--format=%(objectname)_%(path)"], ["ls-files", "--recurse-submodules", "--stage"],
"Cannot list Git OIDs of tracked files." "Cannot list Git OIDs of tracked files."
); );
const fileOidMap = {}; const fileOidMap = {};
const regex = /^([0-9a-f]{40})_(.+)$/; const regex = /^[0-9]+ ([0-9a-f]{40}) [0-9]+\t(.+)$/;
for (const line of stdout.split("\n")) { for (const line of stdout.split("\n")) {
if (line) { if (line) {
const match = line.match(regex); const match = line.match(regex);
@@ -104197,10 +104232,12 @@ async function readBaseDatabaseOidsFile(config, logger) {
async function writeOverlayChangesFile(config, sourceRoot, logger) { async function writeOverlayChangesFile(config, sourceRoot, logger) {
const baseFileOids = await readBaseDatabaseOidsFile(config, logger); const baseFileOids = await readBaseDatabaseOidsFile(config, logger);
const overlayFileOids = await getFileOidsUnderPath(sourceRoot); const overlayFileOids = await getFileOidsUnderPath(sourceRoot);
const changedFiles = computeChangedFiles(baseFileOids, overlayFileOids); const oidChangedFiles = computeChangedFiles(baseFileOids, overlayFileOids);
logger.info( logger.info(
`Found ${changedFiles.length} changed file(s) under ${sourceRoot}.` `Found ${oidChangedFiles.length} changed file(s) under ${sourceRoot} from OID comparison.`
); );
const diffRangeFiles = await getDiffRangeFilePaths(sourceRoot, logger);
const changedFiles = [.../* @__PURE__ */ new Set([...oidChangedFiles, ...diffRangeFiles])];
const changedFilesJson = JSON.stringify({ changes: changedFiles }); const changedFilesJson = JSON.stringify({ changes: changedFiles });
const overlayChangesFile = path3.join( const overlayChangesFile = path3.join(
getTemporaryDirectory(), getTemporaryDirectory(),
@@ -104226,6 +104263,52 @@ function computeChangedFiles(baseFileOids, overlayFileOids) {
} }
return changes; return changes;
} }
async function getDiffRangeFilePaths(sourceRoot, logger) {
const jsonFilePath = getDiffRangesJsonFilePath();
if (!fs3.existsSync(jsonFilePath)) {
logger.debug(
`No diff ranges JSON file found at ${jsonFilePath}; skipping.`
);
return [];
}
let contents;
try {
contents = await fs3.promises.readFile(jsonFilePath, "utf8");
} catch (e) {
logger.warning(
`Failed to read diff ranges JSON file at ${jsonFilePath}: ${e}`
);
return [];
}
let diffRanges;
try {
diffRanges = JSON.parse(contents);
} catch (e) {
logger.warning(
`Failed to parse diff ranges JSON file at ${jsonFilePath}: ${e}`
);
return [];
}
logger.debug(
`Read ${diffRanges.length} diff range(s) from ${jsonFilePath} for overlay changes.`
);
const repoRoot = await getGitRoot(sourceRoot);
if (repoRoot === void 0) {
if (getOptionalInput("source-root")) {
throw new Error(
"Cannot determine git root to convert diff range paths relative to source-root. Failing to avoid omitting files from the analysis."
);
}
logger.warning(
"Cannot determine git root; returning diff range paths as-is."
);
return [...new Set(diffRanges.map((r) => r.path))];
}
const relativePaths = diffRanges.map(
(r) => path3.relative(sourceRoot, path3.join(repoRoot, r.path)).replaceAll(path3.sep, "/")
).filter((rel) => !rel.startsWith(".."));
return [...new Set(relativePaths)];
}
// src/tools-features.ts // src/tools-features.ts
var semver3 = __toESM(require_semver2()); var semver3 = __toESM(require_semver2());
+115 -96
View File
@@ -41057,18 +41057,18 @@ var init_dist_src2 = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js
var VERSION5; var VERSION5;
var init_version2 = __esm({ var init_version2 = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js"() {
VERSION5 = "17.0.0"; VERSION5 = "17.0.0";
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js
var Endpoints, endpoints_default; var Endpoints, endpoints_default;
var init_endpoints = __esm({ var init_endpoints = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js"() {
Endpoints = { Endpoints = {
actions: { actions: {
addCustomLabelsToSelfHostedRunnerForOrg: [ addCustomLabelsToSelfHostedRunnerForOrg: [
@@ -43362,7 +43362,7 @@ var init_endpoints = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js
function endpointsToMethods(octokit) { function endpointsToMethods(octokit) {
const newMethods = {}; const newMethods = {};
for (const scope of endpointMethodsMap.keys()) { for (const scope of endpointMethodsMap.keys()) {
@@ -43413,7 +43413,7 @@ function decorate(octokit, scope, methodName, defaults, decorations) {
} }
var endpointMethodsMap, handler; var endpointMethodsMap, handler;
var init_endpoints_to_methods = __esm({ var init_endpoints_to_methods = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js"() {
init_endpoints(); init_endpoints();
endpointMethodsMap = /* @__PURE__ */ new Map(); endpointMethodsMap = /* @__PURE__ */ new Map();
for (const [scope, endpoints] of Object.entries(endpoints_default)) { for (const [scope, endpoints] of Object.entries(endpoints_default)) {
@@ -43491,7 +43491,7 @@ var init_endpoints_to_methods = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js
var dist_src_exports2 = {}; var dist_src_exports2 = {};
__export(dist_src_exports2, { __export(dist_src_exports2, {
legacyRestEndpointMethods: () => legacyRestEndpointMethods, legacyRestEndpointMethods: () => legacyRestEndpointMethods,
@@ -43511,7 +43511,7 @@ function legacyRestEndpointMethods(octokit) {
}; };
} }
var init_dist_src3 = __esm({ var init_dist_src3 = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js"() {
init_version2(); init_version2();
init_endpoints_to_methods(); init_endpoints_to_methods();
restEndpointMethods.VERSION = VERSION5; restEndpointMethods.VERSION = VERSION5;
@@ -43519,7 +43519,7 @@ var init_dist_src3 = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js // node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js
var dist_bundle_exports = {}; var dist_bundle_exports = {};
__export(dist_bundle_exports, { __export(dist_bundle_exports, {
composePaginateRest: () => composePaginateRest, composePaginateRest: () => composePaginateRest,
@@ -43645,7 +43645,7 @@ function paginateRest(octokit) {
} }
var VERSION6, composePaginateRest, paginatingEndpoints; var VERSION6, composePaginateRest, paginatingEndpoints;
var init_dist_bundle5 = __esm({ var init_dist_bundle5 = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js"() { "node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js"() {
VERSION6 = "0.0.0-development"; VERSION6 = "0.0.0-development";
composePaginateRest = Object.assign(paginate, { composePaginateRest = Object.assign(paginate, {
iterator iterator
@@ -49102,7 +49102,7 @@ var require_brace_expansion = __commonJS({
var x = numeric(n[0]); var x = numeric(n[0]);
var y = numeric(n[1]); var y = numeric(n[1]);
var width = Math.max(n[0].length, n[1].length); var width = Math.max(n[0].length, n[1].length);
var incr = n.length == 3 ? Math.abs(numeric(n[2])) : 1; var incr = n.length == 3 ? Math.max(Math.abs(numeric(n[2])), 1) : 1;
var test = lte; var test = lte;
var reverse = y < x; var reverse = y < x;
if (reverse) { if (reverse) {
@@ -62029,7 +62029,7 @@ var require_fxp = __commonJS({
if (a.some((t3) => i2 === t3.toLowerCase())) throw new Error(`[SECURITY] Invalid ${e2}: "${t2}" is a reserved JavaScript keyword that could cause prototype pollution`); if (a.some((t3) => i2 === t3.toLowerCase())) throw new Error(`[SECURITY] Invalid ${e2}: "${t2}" is a reserved JavaScript keyword that could cause prototype pollution`);
} }
function A(t2) { function A(t2) {
return "boolean" == typeof t2 ? { enabled: t2, maxEntitySize: 1e4, maxExpansionDepth: 10, maxTotalExpansions: 1e3, maxExpandedLength: 1e5, maxEntityCount: 100, allowedTags: null, tagFilter: null } : "object" == typeof t2 && null !== t2 ? { enabled: false !== t2.enabled, maxEntitySize: t2.maxEntitySize ?? 1e4, maxExpansionDepth: t2.maxExpansionDepth ?? 10, maxTotalExpansions: t2.maxTotalExpansions ?? 1e3, maxExpandedLength: t2.maxExpandedLength ?? 1e5, maxEntityCount: t2.maxEntityCount ?? 100, allowedTags: t2.allowedTags ?? null, tagFilter: t2.tagFilter ?? null } : A(true); return "boolean" == typeof t2 ? { enabled: t2, maxEntitySize: 1e4, maxExpansionDepth: 10, maxTotalExpansions: 1e3, maxExpandedLength: 1e5, maxEntityCount: 100, allowedTags: null, tagFilter: null } : "object" == typeof t2 && null !== t2 ? { enabled: false !== t2.enabled, maxEntitySize: Math.max(1, t2.maxEntitySize ?? 1e4), maxExpansionDepth: Math.max(1, t2.maxExpansionDepth ?? 10), maxTotalExpansions: Math.max(1, t2.maxTotalExpansions ?? 1e3), maxExpandedLength: Math.max(1, t2.maxExpandedLength ?? 1e5), maxEntityCount: Math.max(1, t2.maxEntityCount ?? 100), allowedTags: t2.allowedTags ?? null, tagFilter: t2.tagFilter ?? null } : A(true);
} }
const C = function(t2) { const C = function(t2) {
const e2 = Object.assign({}, P, t2), i2 = [{ value: e2.attributeNamePrefix, name: "attributeNamePrefix" }, { value: e2.attributesGroupName, name: "attributesGroupName" }, { value: e2.textNodeName, name: "textNodeName" }, { value: e2.cdataPropName, name: "cdataPropName" }, { value: e2.commentPropName, name: "commentPropName" }]; const e2 = Object.assign({}, P, t2), i2 = [{ value: e2.attributeNamePrefix, name: "attributeNamePrefix" }, { value: e2.attributesGroupName, name: "attributesGroupName" }, { value: e2.textNodeName, name: "textNodeName" }, { value: e2.cdataPropName, name: "cdataPropName" }, { value: e2.commentPropName, name: "commentPropName" }];
@@ -62070,7 +62070,7 @@ var require_fxp = __commonJS({
if (r2 && _2(t2, "!ENTITY", e2)) { if (r2 && _2(t2, "!ENTITY", e2)) {
let s3, r3; let s3, r3;
if (e2 += 7, [s3, r3, e2] = this.readEntityExp(t2, e2 + 1, this.suppressValidationErr), -1 === r3.indexOf("&")) { if (e2 += 7, [s3, r3, e2] = this.readEntityExp(t2, e2 + 1, this.suppressValidationErr), -1 === r3.indexOf("&")) {
if (false !== this.options.enabled && this.options.maxEntityCount && n2 >= this.options.maxEntityCount) throw new Error(`Entity count (${n2 + 1}) exceeds maximum allowed (${this.options.maxEntityCount})`); if (false !== this.options.enabled && null != this.options.maxEntityCount && n2 >= this.options.maxEntityCount) throw new Error(`Entity count (${n2 + 1}) exceeds maximum allowed (${this.options.maxEntityCount})`);
const t3 = s3.replace(/[.*+?^${}()|[\]\\]/g, "\\$&"); const t3 = s3.replace(/[.*+?^${}()|[\]\\]/g, "\\$&");
i2[s3] = { regx: RegExp(`&${t3};`, "g"), val: r3 }, n2++; i2[s3] = { regx: RegExp(`&${t3};`, "g"), val: r3 }, n2++;
} }
@@ -62094,82 +62094,86 @@ var require_fxp = __commonJS({
return { entities: i2, i: e2 }; return { entities: i2, i: e2 };
} }
readEntityExp(t2, e2) { readEntityExp(t2, e2) {
e2 = j(t2, e2); const i2 = e2 = j(t2, e2);
let i2 = ""; for (; e2 < t2.length && !/\s/.test(t2[e2]) && '"' !== t2[e2] && "'" !== t2[e2]; ) e2++;
for (; e2 < t2.length && !/\s/.test(t2[e2]) && '"' !== t2[e2] && "'" !== t2[e2]; ) i2 += t2[e2], e2++; let n2 = t2.substring(i2, e2);
if (D(i2), e2 = j(t2, e2), !this.suppressValidationErr) { if (D(n2), e2 = j(t2, e2), !this.suppressValidationErr) {
if ("SYSTEM" === t2.substring(e2, e2 + 6).toUpperCase()) throw new Error("External entities are not supported"); if ("SYSTEM" === t2.substring(e2, e2 + 6).toUpperCase()) throw new Error("External entities are not supported");
if ("%" === t2[e2]) throw new Error("Parameter entities are not supported"); if ("%" === t2[e2]) throw new Error("Parameter entities are not supported");
} }
let n2 = ""; let s2 = "";
if ([e2, n2] = this.readIdentifierVal(t2, e2, "entity"), false !== this.options.enabled && this.options.maxEntitySize && n2.length > this.options.maxEntitySize) throw new Error(`Entity "${i2}" size (${n2.length}) exceeds maximum allowed size (${this.options.maxEntitySize})`); if ([e2, s2] = this.readIdentifierVal(t2, e2, "entity"), false !== this.options.enabled && null != this.options.maxEntitySize && s2.length > this.options.maxEntitySize) throw new Error(`Entity "${n2}" size (${s2.length}) exceeds maximum allowed size (${this.options.maxEntitySize})`);
return [i2, n2, --e2]; return [n2, s2, --e2];
} }
readNotationExp(t2, e2) { readNotationExp(t2, e2) {
e2 = j(t2, e2); const i2 = e2 = j(t2, e2);
let i2 = ""; for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) i2 += t2[e2], e2++; let n2 = t2.substring(i2, e2);
!this.suppressValidationErr && D(i2), e2 = j(t2, e2); !this.suppressValidationErr && D(n2), e2 = j(t2, e2);
const n2 = t2.substring(e2, e2 + 6).toUpperCase(); const s2 = t2.substring(e2, e2 + 6).toUpperCase();
if (!this.suppressValidationErr && "SYSTEM" !== n2 && "PUBLIC" !== n2) throw new Error(`Expected SYSTEM or PUBLIC, found "${n2}"`); if (!this.suppressValidationErr && "SYSTEM" !== s2 && "PUBLIC" !== s2) throw new Error(`Expected SYSTEM or PUBLIC, found "${s2}"`);
e2 += n2.length, e2 = j(t2, e2); e2 += s2.length, e2 = j(t2, e2);
let s2 = null, r2 = null; let r2 = null, o2 = null;
if ("PUBLIC" === n2) [e2, s2] = this.readIdentifierVal(t2, e2, "publicIdentifier"), '"' !== t2[e2 = j(t2, e2)] && "'" !== t2[e2] || ([e2, r2] = this.readIdentifierVal(t2, e2, "systemIdentifier")); if ("PUBLIC" === s2) [e2, r2] = this.readIdentifierVal(t2, e2, "publicIdentifier"), '"' !== t2[e2 = j(t2, e2)] && "'" !== t2[e2] || ([e2, o2] = this.readIdentifierVal(t2, e2, "systemIdentifier"));
else if ("SYSTEM" === n2 && ([e2, r2] = this.readIdentifierVal(t2, e2, "systemIdentifier"), !this.suppressValidationErr && !r2)) throw new Error("Missing mandatory system identifier for SYSTEM notation"); else if ("SYSTEM" === s2 && ([e2, o2] = this.readIdentifierVal(t2, e2, "systemIdentifier"), !this.suppressValidationErr && !o2)) throw new Error("Missing mandatory system identifier for SYSTEM notation");
return { notationName: i2, publicIdentifier: s2, systemIdentifier: r2, index: --e2 }; return { notationName: n2, publicIdentifier: r2, systemIdentifier: o2, index: --e2 };
} }
readIdentifierVal(t2, e2, i2) { readIdentifierVal(t2, e2, i2) {
let n2 = ""; let n2 = "";
const s2 = t2[e2]; const s2 = t2[e2];
if ('"' !== s2 && "'" !== s2) throw new Error(`Expected quoted string, found "${s2}"`); if ('"' !== s2 && "'" !== s2) throw new Error(`Expected quoted string, found "${s2}"`);
for (e2++; e2 < t2.length && t2[e2] !== s2; ) n2 += t2[e2], e2++; const r2 = ++e2;
if (t2[e2] !== s2) throw new Error(`Unterminated ${i2} value`); for (; e2 < t2.length && t2[e2] !== s2; ) e2++;
if (n2 = t2.substring(r2, e2), t2[e2] !== s2) throw new Error(`Unterminated ${i2} value`);
return [++e2, n2]; return [++e2, n2];
} }
readElementExp(t2, e2) { readElementExp(t2, e2) {
e2 = j(t2, e2); const i2 = e2 = j(t2, e2);
let i2 = ""; for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) i2 += t2[e2], e2++; let n2 = t2.substring(i2, e2);
if (!this.suppressValidationErr && !r(i2)) throw new Error(`Invalid element name: "${i2}"`); if (!this.suppressValidationErr && !r(n2)) throw new Error(`Invalid element name: "${n2}"`);
let n2 = ""; let s2 = "";
if ("E" === t2[e2 = j(t2, e2)] && _2(t2, "MPTY", e2)) e2 += 4; if ("E" === t2[e2 = j(t2, e2)] && _2(t2, "MPTY", e2)) e2 += 4;
else if ("A" === t2[e2] && _2(t2, "NY", e2)) e2 += 2; else if ("A" === t2[e2] && _2(t2, "NY", e2)) e2 += 2;
else if ("(" === t2[e2]) { else if ("(" === t2[e2]) {
for (e2++; e2 < t2.length && ")" !== t2[e2]; ) n2 += t2[e2], e2++; const i3 = ++e2;
if (")" !== t2[e2]) throw new Error("Unterminated content model"); for (; e2 < t2.length && ")" !== t2[e2]; ) e2++;
if (s2 = t2.substring(i3, e2), ")" !== t2[e2]) throw new Error("Unterminated content model");
} else if (!this.suppressValidationErr) throw new Error(`Invalid Element Expression, found "${t2[e2]}"`); } else if (!this.suppressValidationErr) throw new Error(`Invalid Element Expression, found "${t2[e2]}"`);
return { elementName: i2, contentModel: n2.trim(), index: e2 }; return { elementName: n2, contentModel: s2.trim(), index: e2 };
} }
readAttlistExp(t2, e2) { readAttlistExp(t2, e2) {
let i2 = e2 = j(t2, e2);
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
let n2 = t2.substring(i2, e2);
for (D(n2), i2 = e2 = j(t2, e2); e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
let s2 = t2.substring(i2, e2);
if (!D(s2)) throw new Error(`Invalid attribute name: "${s2}"`);
e2 = j(t2, e2); e2 = j(t2, e2);
let i2 = ""; let r2 = "";
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) i2 += t2[e2], e2++;
D(i2), e2 = j(t2, e2);
let n2 = "";
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) n2 += t2[e2], e2++;
if (!D(n2)) throw new Error(`Invalid attribute name: "${n2}"`);
e2 = j(t2, e2);
let s2 = "";
if ("NOTATION" === t2.substring(e2, e2 + 8).toUpperCase()) { if ("NOTATION" === t2.substring(e2, e2 + 8).toUpperCase()) {
if (s2 = "NOTATION", "(" !== t2[e2 = j(t2, e2 += 8)]) throw new Error(`Expected '(', found "${t2[e2]}"`); if (r2 = "NOTATION", "(" !== t2[e2 = j(t2, e2 += 8)]) throw new Error(`Expected '(', found "${t2[e2]}"`);
e2++; e2++;
let i3 = []; let i3 = [];
for (; e2 < t2.length && ")" !== t2[e2]; ) { for (; e2 < t2.length && ")" !== t2[e2]; ) {
let n3 = ""; const n3 = e2;
for (; e2 < t2.length && "|" !== t2[e2] && ")" !== t2[e2]; ) n3 += t2[e2], e2++; for (; e2 < t2.length && "|" !== t2[e2] && ")" !== t2[e2]; ) e2++;
if (n3 = n3.trim(), !D(n3)) throw new Error(`Invalid notation name: "${n3}"`); let s3 = t2.substring(n3, e2);
i3.push(n3), "|" === t2[e2] && (e2++, e2 = j(t2, e2)); if (s3 = s3.trim(), !D(s3)) throw new Error(`Invalid notation name: "${s3}"`);
i3.push(s3), "|" === t2[e2] && (e2++, e2 = j(t2, e2));
} }
if (")" !== t2[e2]) throw new Error("Unterminated list of notations"); if (")" !== t2[e2]) throw new Error("Unterminated list of notations");
e2++, s2 += " (" + i3.join("|") + ")"; e2++, r2 += " (" + i3.join("|") + ")";
} else { } else {
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) s2 += t2[e2], e2++; const i3 = e2;
const i3 = ["CDATA", "ID", "IDREF", "IDREFS", "ENTITY", "ENTITIES", "NMTOKEN", "NMTOKENS"]; for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
if (!this.suppressValidationErr && !i3.includes(s2.toUpperCase())) throw new Error(`Invalid attribute type: "${s2}"`); r2 += t2.substring(i3, e2);
const n3 = ["CDATA", "ID", "IDREF", "IDREFS", "ENTITY", "ENTITIES", "NMTOKEN", "NMTOKENS"];
if (!this.suppressValidationErr && !n3.includes(r2.toUpperCase())) throw new Error(`Invalid attribute type: "${r2}"`);
} }
e2 = j(t2, e2); e2 = j(t2, e2);
let r2 = ""; let o2 = "";
return "#REQUIRED" === t2.substring(e2, e2 + 8).toUpperCase() ? (r2 = "#REQUIRED", e2 += 8) : "#IMPLIED" === t2.substring(e2, e2 + 7).toUpperCase() ? (r2 = "#IMPLIED", e2 += 7) : [e2, r2] = this.readIdentifierVal(t2, e2, "ATTLIST"), { elementName: i2, attributeName: n2, attributeType: s2, defaultValue: r2, index: e2 }; return "#REQUIRED" === t2.substring(e2, e2 + 8).toUpperCase() ? (o2 = "#REQUIRED", e2 += 8) : "#IMPLIED" === t2.substring(e2, e2 + 7).toUpperCase() ? (o2 = "#IMPLIED", e2 += 7) : [e2, o2] = this.readIdentifierVal(t2, e2, "ATTLIST"), { elementName: n2, attributeName: s2, attributeType: r2, defaultValue: o2, index: e2 };
} }
} }
const j = (t2, e2) => { const j = (t2, e2) => {
@@ -62184,9 +62188,9 @@ var require_fxp = __commonJS({
if (r(t2)) return t2; if (r(t2)) return t2;
throw new Error(`Invalid entity name ${t2}`); throw new Error(`Invalid entity name ${t2}`);
} }
const V = /^[-+]?0x[a-fA-F0-9]+$/, k = /^([\-\+])?(0*)([0-9]*(\.[0-9]*)?)$/, F = { hex: true, leadingZeros: true, decimalPoint: ".", eNotation: true }; const V = /^[-+]?0x[a-fA-F0-9]+$/, k = /^([\-\+])?(0*)([0-9]*(\.[0-9]*)?)$/, M = { hex: true, leadingZeros: true, decimalPoint: ".", eNotation: true, infinity: "original" };
const L = /^([-+])?(0*)(\d*(\.\d*)?[eE][-\+]?\d+)$/; const F = /^([-+])?(0*)(\d*(\.\d*)?[eE][-\+]?\d+)$/;
class M { class L {
constructor(t2 = {}) { constructor(t2 = {}) {
this.separator = t2.separator || ".", this.path = [], this.siblingStacks = []; this.separator = t2.separator || ".", this.path = [], this.siblingStacks = [];
} }
@@ -62393,7 +62397,7 @@ var require_fxp = __commonJS({
if ("string" == typeof i2 && t3 === i2) return true; if ("string" == typeof i2 && t3 === i2) return true;
if (i2 instanceof RegExp && i2.test(t3)) return true; if (i2 instanceof RegExp && i2.test(t3)) return true;
} }
} : () => false, this.entityExpansionCount = 0, this.currentExpandedLength = 0, this.matcher = new M(), this.isCurrentNodeStopNode = false, this.options.stopNodes && this.options.stopNodes.length > 0) { } : () => false, this.entityExpansionCount = 0, this.currentExpandedLength = 0, this.matcher = new L(), this.isCurrentNodeStopNode = false, this.options.stopNodes && this.options.stopNodes.length > 0) {
this.stopNodeExpressions = []; this.stopNodeExpressions = [];
for (let t3 = 0; t3 < this.options.stopNodes.length; t3++) { for (let t3 = 0; t3 < this.options.stopNodes.length; t3++) {
const e3 = this.options.stopNodes[t3]; const e3 = this.options.stopNodes[t3];
@@ -62504,7 +62508,7 @@ var require_fxp = __commonJS({
let o2 = s3.tagName; let o2 = s3.tagName;
const a2 = s3.rawTagName; const a2 = s3.rawTagName;
let h2 = s3.tagExp, l2 = s3.attrExpPresent, p2 = s3.closeIndex; let h2 = s3.tagExp, l2 = s3.attrExpPresent, p2 = s3.closeIndex;
if ({ tagName: o2, tagExp: h2 } = rt(this.options.transformTagName, o2, h2, this.options), this.options.strictReservedNames && (o2 === this.options.commentPropName || o2 === this.options.cdataPropName)) throw new Error(`Invalid tag name: ${o2}`); if ({ tagName: o2, tagExp: h2 } = rt(this.options.transformTagName, o2, h2, this.options), this.options.strictReservedNames && (o2 === this.options.commentPropName || o2 === this.options.cdataPropName || o2 === this.options.textNodeName || o2 === this.options.attributesGroupName)) throw new Error(`Invalid tag name: ${o2}`);
i2 && n2 && "!xml" !== i2.tagname && (n2 = this.saveTextToParentTag(n2, i2, this.matcher, false)); i2 && n2 && "!xml" !== i2.tagname && (n2 = this.saveTextToParentTag(n2, i2, this.matcher, false));
const u2 = i2; const u2 = i2;
u2 && -1 !== this.options.unpairedTags.indexOf(u2.tagname) && (i2 = this.tagsNodeStack.pop(), this.matcher.pop()); u2 && -1 !== this.options.unpairedTags.indexOf(u2.tagname) && (i2 = this.tagsNodeStack.pop(), this.matcher.pop());
@@ -62642,7 +62646,7 @@ var require_fxp = __commonJS({
if (e2 && "string" == typeof t2) { if (e2 && "string" == typeof t2) {
const e3 = t2.trim(); const e3 = t2.trim();
return "true" === e3 || "false" !== e3 && (function(t3, e4 = {}) { return "true" === e3 || "false" !== e3 && (function(t3, e4 = {}) {
if (e4 = Object.assign({}, F, e4), !t3 || "string" != typeof t3) return t3; if (e4 = Object.assign({}, M, e4), !t3 || "string" != typeof t3) return t3;
let i3 = t3.trim(); let i3 = t3.trim();
if (void 0 !== e4.skipLike && e4.skipLike.test(i3)) return t3; if (void 0 !== e4.skipLike && e4.skipLike.test(i3)) return t3;
if ("0" === t3) return 0; if ("0" === t3) return 0;
@@ -62652,35 +62656,50 @@ var require_fxp = __commonJS({
if (window && window.parseInt) return window.parseInt(t4, 16); if (window && window.parseInt) return window.parseInt(t4, 16);
throw new Error("parseInt, Number.parseInt, window.parseInt are not supported"); throw new Error("parseInt, Number.parseInt, window.parseInt are not supported");
})(i3); })(i3);
if (i3.includes("e") || i3.includes("E")) return (function(t4, e5, i4) { if (isFinite(i3)) {
if (!i4.eNotation) return t4; if (i3.includes("e") || i3.includes("E")) return (function(t4, e5, i4) {
const n3 = e5.match(L); if (!i4.eNotation) return t4;
if (n3) { const n3 = e5.match(F);
let s2 = n3[1] || ""; if (n3) {
const r2 = -1 === n3[3].indexOf("e") ? "E" : "e", o2 = n3[2], a2 = s2 ? t4[o2.length + 1] === r2 : t4[o2.length] === r2; let s2 = n3[1] || "";
return o2.length > 1 && a2 ? t4 : 1 !== o2.length || !n3[3].startsWith(`.${r2}`) && n3[3][0] !== r2 ? i4.leadingZeros && !a2 ? (e5 = (n3[1] || "") + n3[3], Number(e5)) : t4 : Number(e5); const r2 = -1 === n3[3].indexOf("e") ? "E" : "e", o2 = n3[2], a2 = s2 ? t4[o2.length + 1] === r2 : t4[o2.length] === r2;
} return o2.length > 1 && a2 ? t4 : (1 !== o2.length || !n3[3].startsWith(`.${r2}`) && n3[3][0] !== r2) && o2.length > 0 ? i4.leadingZeros && !a2 ? (e5 = (n3[1] || "") + n3[3], Number(e5)) : t4 : Number(e5);
return t4;
})(t3, i3, e4);
{
const s2 = k.exec(i3);
if (s2) {
const r2 = s2[1] || "", o2 = s2[2];
let a2 = (n2 = s2[3]) && -1 !== n2.indexOf(".") ? ("." === (n2 = n2.replace(/0+$/, "")) ? n2 = "0" : "." === n2[0] ? n2 = "0" + n2 : "." === n2[n2.length - 1] && (n2 = n2.substring(0, n2.length - 1)), n2) : n2;
const h2 = r2 ? "." === t3[o2.length + 1] : "." === t3[o2.length];
if (!e4.leadingZeros && (o2.length > 1 || 1 === o2.length && !h2)) return t3;
{
const n3 = Number(i3), s3 = String(n3);
if (0 === n3) return n3;
if (-1 !== s3.search(/[eE]/)) return e4.eNotation ? n3 : t3;
if (-1 !== i3.indexOf(".")) return "0" === s3 || s3 === a2 || s3 === `${r2}${a2}` ? n3 : t3;
let h3 = o2 ? a2 : i3;
return o2 ? h3 === s3 || r2 + h3 === s3 ? n3 : t3 : h3 === s3 || h3 === r2 + s3 ? n3 : t3;
} }
return t4;
})(t3, i3, e4);
{
const s2 = k.exec(i3);
if (s2) {
const r2 = s2[1] || "", o2 = s2[2];
let a2 = (n2 = s2[3]) && -1 !== n2.indexOf(".") ? ("." === (n2 = n2.replace(/0+$/, "")) ? n2 = "0" : "." === n2[0] ? n2 = "0" + n2 : "." === n2[n2.length - 1] && (n2 = n2.substring(0, n2.length - 1)), n2) : n2;
const h2 = r2 ? "." === t3[o2.length + 1] : "." === t3[o2.length];
if (!e4.leadingZeros && (o2.length > 1 || 1 === o2.length && !h2)) return t3;
{
const n3 = Number(i3), s3 = String(n3);
if (0 === n3) return n3;
if (-1 !== s3.search(/[eE]/)) return e4.eNotation ? n3 : t3;
if (-1 !== i3.indexOf(".")) return "0" === s3 || s3 === a2 || s3 === `${r2}${a2}` ? n3 : t3;
let h3 = o2 ? a2 : i3;
return o2 ? h3 === s3 || r2 + h3 === s3 ? n3 : t3 : h3 === s3 || h3 === r2 + s3 ? n3 : t3;
}
}
return t3;
} }
return t3;
} }
var n2; var n2;
return (function(t4, e5, i4) {
const n3 = e5 === 1 / 0;
switch (i4.infinity.toLowerCase()) {
case "null":
return null;
case "infinity":
return e5;
case "string":
return n3 ? "Infinity" : "-Infinity";
default:
return t4;
}
})(t3, Number(i3), e4);
})(t2, i2); })(t2, i2);
} }
return void 0 !== t2 ? t2 : ""; return void 0 !== t2 ? t2 : "";
@@ -62792,7 +62811,7 @@ var require_fxp = __commonJS({
const i3 = e2.stopNodes[t3]; const i3 = e2.stopNodes[t3];
"string" == typeof i3 ? n2.push(new G(i3)) : i3 instanceof G && n2.push(i3); "string" == typeof i3 ? n2.push(new G(i3)) : i3 instanceof G && n2.push(i3);
} }
return mt(t2, e2, i2, new M(), n2); return mt(t2, e2, i2, new L(), n2);
} }
function mt(t2, e2, i2, n2, s2) { function mt(t2, e2, i2, n2, s2) {
let r2 = "", o2 = false; let r2 = "", o2 = false;
@@ -62940,7 +62959,7 @@ var require_fxp = __commonJS({
if (this.options.preserveOrder) return gt(t2, this.options); if (this.options.preserveOrder) return gt(t2, this.options);
{ {
Array.isArray(t2) && this.options.arrayNodeName && this.options.arrayNodeName.length > 1 && (t2 = { [this.options.arrayNodeName]: t2 }); Array.isArray(t2) && this.options.arrayNodeName && this.options.arrayNodeName.length > 1 && (t2 = { [this.options.arrayNodeName]: t2 });
const e2 = new M(); const e2 = new L();
return this.j2x(t2, 0, e2).val; return this.j2x(t2, 0, e2).val;
} }
}, Pt.prototype.j2x = function(t2, e2, i2) { }, Pt.prototype.j2x = function(t2, e2, i2) {
@@ -115616,7 +115635,7 @@ var require_commonjs19 = __commonJS({
var openPattern = /\\{/g; var openPattern = /\\{/g;
var closePattern = /\\}/g; var closePattern = /\\}/g;
var commaPattern = /\\,/g; var commaPattern = /\\,/g;
var periodPattern = /\\./g; var periodPattern = /\\\./g;
exports2.EXPANSION_MAX = 1e5; exports2.EXPANSION_MAX = 1e5;
function numeric(str2) { function numeric(str2) {
return !isNaN(str2) ? parseInt(str2, 10) : str2.charCodeAt(0); return !isNaN(str2) ? parseInt(str2, 10) : str2.charCodeAt(0);
@@ -115711,7 +115730,7 @@ var require_commonjs19 = __commonJS({
const x = numeric(n[0]); const x = numeric(n[0]);
const y = numeric(n[1]); const y = numeric(n[1]);
const width = Math.max(n[0].length, n[1].length); const width = Math.max(n[0].length, n[1].length);
let incr = n.length === 3 && n[2] !== void 0 ? Math.abs(numeric(n[2])) : 1; let incr = n.length === 3 && n[2] !== void 0 ? Math.max(Math.abs(numeric(n[2])), 1) : 1;
let test = lte; let test = lte;
const reverse = y < x; const reverse = y < x;
if (reverse) { if (reverse) {
@@ -161479,7 +161498,7 @@ function getTemporaryDirectory() {
return value !== void 0 && value !== "" ? value : getRequiredEnvParam("RUNNER_TEMP"); return value !== void 0 && value !== "" ? value : getRequiredEnvParam("RUNNER_TEMP");
} }
function getActionVersion() { function getActionVersion() {
return "4.34.1"; return "4.35.2";
} }
var persistedInputsKey = "persisted_inputs"; var persistedInputsKey = "persisted_inputs";
var restoreInputs = function() { var restoreInputs = function() {
+167 -104
View File
@@ -41057,18 +41057,18 @@ var init_dist_src2 = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js
var VERSION5; var VERSION5;
var init_version2 = __esm({ var init_version2 = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js"() {
VERSION5 = "17.0.0"; VERSION5 = "17.0.0";
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js
var Endpoints, endpoints_default; var Endpoints, endpoints_default;
var init_endpoints = __esm({ var init_endpoints = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js"() {
Endpoints = { Endpoints = {
actions: { actions: {
addCustomLabelsToSelfHostedRunnerForOrg: [ addCustomLabelsToSelfHostedRunnerForOrg: [
@@ -43362,7 +43362,7 @@ var init_endpoints = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js
function endpointsToMethods(octokit) { function endpointsToMethods(octokit) {
const newMethods = {}; const newMethods = {};
for (const scope of endpointMethodsMap.keys()) { for (const scope of endpointMethodsMap.keys()) {
@@ -43413,7 +43413,7 @@ function decorate(octokit, scope, methodName, defaults, decorations) {
} }
var endpointMethodsMap, handler; var endpointMethodsMap, handler;
var init_endpoints_to_methods = __esm({ var init_endpoints_to_methods = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js"() {
init_endpoints(); init_endpoints();
endpointMethodsMap = /* @__PURE__ */ new Map(); endpointMethodsMap = /* @__PURE__ */ new Map();
for (const [scope, endpoints] of Object.entries(endpoints_default)) { for (const [scope, endpoints] of Object.entries(endpoints_default)) {
@@ -43491,7 +43491,7 @@ var init_endpoints_to_methods = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js
var dist_src_exports2 = {}; var dist_src_exports2 = {};
__export(dist_src_exports2, { __export(dist_src_exports2, {
legacyRestEndpointMethods: () => legacyRestEndpointMethods, legacyRestEndpointMethods: () => legacyRestEndpointMethods,
@@ -43511,7 +43511,7 @@ function legacyRestEndpointMethods(octokit) {
}; };
} }
var init_dist_src3 = __esm({ var init_dist_src3 = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js"() {
init_version2(); init_version2();
init_endpoints_to_methods(); init_endpoints_to_methods();
restEndpointMethods.VERSION = VERSION5; restEndpointMethods.VERSION = VERSION5;
@@ -43519,7 +43519,7 @@ var init_dist_src3 = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js // node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js
var dist_bundle_exports = {}; var dist_bundle_exports = {};
__export(dist_bundle_exports, { __export(dist_bundle_exports, {
composePaginateRest: () => composePaginateRest, composePaginateRest: () => composePaginateRest,
@@ -43645,7 +43645,7 @@ function paginateRest(octokit) {
} }
var VERSION6, composePaginateRest, paginatingEndpoints; var VERSION6, composePaginateRest, paginatingEndpoints;
var init_dist_bundle5 = __esm({ var init_dist_bundle5 = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js"() { "node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js"() {
VERSION6 = "0.0.0-development"; VERSION6 = "0.0.0-development";
composePaginateRest = Object.assign(paginate, { composePaginateRest = Object.assign(paginate, {
iterator iterator
@@ -47805,7 +47805,7 @@ var require_brace_expansion = __commonJS({
var x = numeric(n[0]); var x = numeric(n[0]);
var y = numeric(n[1]); var y = numeric(n[1]);
var width = Math.max(n[0].length, n[1].length); var width = Math.max(n[0].length, n[1].length);
var incr = n.length == 3 ? Math.abs(numeric(n[2])) : 1; var incr = n.length == 3 ? Math.max(Math.abs(numeric(n[2])), 1) : 1;
var test = lte; var test = lte;
var reverse = y < x; var reverse = y < x;
if (reverse) { if (reverse) {
@@ -60732,7 +60732,7 @@ var require_fxp = __commonJS({
if (a.some((t3) => i2 === t3.toLowerCase())) throw new Error(`[SECURITY] Invalid ${e2}: "${t2}" is a reserved JavaScript keyword that could cause prototype pollution`); if (a.some((t3) => i2 === t3.toLowerCase())) throw new Error(`[SECURITY] Invalid ${e2}: "${t2}" is a reserved JavaScript keyword that could cause prototype pollution`);
} }
function A(t2) { function A(t2) {
return "boolean" == typeof t2 ? { enabled: t2, maxEntitySize: 1e4, maxExpansionDepth: 10, maxTotalExpansions: 1e3, maxExpandedLength: 1e5, maxEntityCount: 100, allowedTags: null, tagFilter: null } : "object" == typeof t2 && null !== t2 ? { enabled: false !== t2.enabled, maxEntitySize: t2.maxEntitySize ?? 1e4, maxExpansionDepth: t2.maxExpansionDepth ?? 10, maxTotalExpansions: t2.maxTotalExpansions ?? 1e3, maxExpandedLength: t2.maxExpandedLength ?? 1e5, maxEntityCount: t2.maxEntityCount ?? 100, allowedTags: t2.allowedTags ?? null, tagFilter: t2.tagFilter ?? null } : A(true); return "boolean" == typeof t2 ? { enabled: t2, maxEntitySize: 1e4, maxExpansionDepth: 10, maxTotalExpansions: 1e3, maxExpandedLength: 1e5, maxEntityCount: 100, allowedTags: null, tagFilter: null } : "object" == typeof t2 && null !== t2 ? { enabled: false !== t2.enabled, maxEntitySize: Math.max(1, t2.maxEntitySize ?? 1e4), maxExpansionDepth: Math.max(1, t2.maxExpansionDepth ?? 10), maxTotalExpansions: Math.max(1, t2.maxTotalExpansions ?? 1e3), maxExpandedLength: Math.max(1, t2.maxExpandedLength ?? 1e5), maxEntityCount: Math.max(1, t2.maxEntityCount ?? 100), allowedTags: t2.allowedTags ?? null, tagFilter: t2.tagFilter ?? null } : A(true);
} }
const C = function(t2) { const C = function(t2) {
const e2 = Object.assign({}, P, t2), i2 = [{ value: e2.attributeNamePrefix, name: "attributeNamePrefix" }, { value: e2.attributesGroupName, name: "attributesGroupName" }, { value: e2.textNodeName, name: "textNodeName" }, { value: e2.cdataPropName, name: "cdataPropName" }, { value: e2.commentPropName, name: "commentPropName" }]; const e2 = Object.assign({}, P, t2), i2 = [{ value: e2.attributeNamePrefix, name: "attributeNamePrefix" }, { value: e2.attributesGroupName, name: "attributesGroupName" }, { value: e2.textNodeName, name: "textNodeName" }, { value: e2.cdataPropName, name: "cdataPropName" }, { value: e2.commentPropName, name: "commentPropName" }];
@@ -60773,7 +60773,7 @@ var require_fxp = __commonJS({
if (r2 && _(t2, "!ENTITY", e2)) { if (r2 && _(t2, "!ENTITY", e2)) {
let s3, r3; let s3, r3;
if (e2 += 7, [s3, r3, e2] = this.readEntityExp(t2, e2 + 1, this.suppressValidationErr), -1 === r3.indexOf("&")) { if (e2 += 7, [s3, r3, e2] = this.readEntityExp(t2, e2 + 1, this.suppressValidationErr), -1 === r3.indexOf("&")) {
if (false !== this.options.enabled && this.options.maxEntityCount && n2 >= this.options.maxEntityCount) throw new Error(`Entity count (${n2 + 1}) exceeds maximum allowed (${this.options.maxEntityCount})`); if (false !== this.options.enabled && null != this.options.maxEntityCount && n2 >= this.options.maxEntityCount) throw new Error(`Entity count (${n2 + 1}) exceeds maximum allowed (${this.options.maxEntityCount})`);
const t3 = s3.replace(/[.*+?^${}()|[\]\\]/g, "\\$&"); const t3 = s3.replace(/[.*+?^${}()|[\]\\]/g, "\\$&");
i2[s3] = { regx: RegExp(`&${t3};`, "g"), val: r3 }, n2++; i2[s3] = { regx: RegExp(`&${t3};`, "g"), val: r3 }, n2++;
} }
@@ -60797,82 +60797,86 @@ var require_fxp = __commonJS({
return { entities: i2, i: e2 }; return { entities: i2, i: e2 };
} }
readEntityExp(t2, e2) { readEntityExp(t2, e2) {
e2 = j(t2, e2); const i2 = e2 = j(t2, e2);
let i2 = ""; for (; e2 < t2.length && !/\s/.test(t2[e2]) && '"' !== t2[e2] && "'" !== t2[e2]; ) e2++;
for (; e2 < t2.length && !/\s/.test(t2[e2]) && '"' !== t2[e2] && "'" !== t2[e2]; ) i2 += t2[e2], e2++; let n2 = t2.substring(i2, e2);
if (D(i2), e2 = j(t2, e2), !this.suppressValidationErr) { if (D(n2), e2 = j(t2, e2), !this.suppressValidationErr) {
if ("SYSTEM" === t2.substring(e2, e2 + 6).toUpperCase()) throw new Error("External entities are not supported"); if ("SYSTEM" === t2.substring(e2, e2 + 6).toUpperCase()) throw new Error("External entities are not supported");
if ("%" === t2[e2]) throw new Error("Parameter entities are not supported"); if ("%" === t2[e2]) throw new Error("Parameter entities are not supported");
} }
let n2 = ""; let s2 = "";
if ([e2, n2] = this.readIdentifierVal(t2, e2, "entity"), false !== this.options.enabled && this.options.maxEntitySize && n2.length > this.options.maxEntitySize) throw new Error(`Entity "${i2}" size (${n2.length}) exceeds maximum allowed size (${this.options.maxEntitySize})`); if ([e2, s2] = this.readIdentifierVal(t2, e2, "entity"), false !== this.options.enabled && null != this.options.maxEntitySize && s2.length > this.options.maxEntitySize) throw new Error(`Entity "${n2}" size (${s2.length}) exceeds maximum allowed size (${this.options.maxEntitySize})`);
return [i2, n2, --e2]; return [n2, s2, --e2];
} }
readNotationExp(t2, e2) { readNotationExp(t2, e2) {
e2 = j(t2, e2); const i2 = e2 = j(t2, e2);
let i2 = ""; for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) i2 += t2[e2], e2++; let n2 = t2.substring(i2, e2);
!this.suppressValidationErr && D(i2), e2 = j(t2, e2); !this.suppressValidationErr && D(n2), e2 = j(t2, e2);
const n2 = t2.substring(e2, e2 + 6).toUpperCase(); const s2 = t2.substring(e2, e2 + 6).toUpperCase();
if (!this.suppressValidationErr && "SYSTEM" !== n2 && "PUBLIC" !== n2) throw new Error(`Expected SYSTEM or PUBLIC, found "${n2}"`); if (!this.suppressValidationErr && "SYSTEM" !== s2 && "PUBLIC" !== s2) throw new Error(`Expected SYSTEM or PUBLIC, found "${s2}"`);
e2 += n2.length, e2 = j(t2, e2); e2 += s2.length, e2 = j(t2, e2);
let s2 = null, r2 = null; let r2 = null, o2 = null;
if ("PUBLIC" === n2) [e2, s2] = this.readIdentifierVal(t2, e2, "publicIdentifier"), '"' !== t2[e2 = j(t2, e2)] && "'" !== t2[e2] || ([e2, r2] = this.readIdentifierVal(t2, e2, "systemIdentifier")); if ("PUBLIC" === s2) [e2, r2] = this.readIdentifierVal(t2, e2, "publicIdentifier"), '"' !== t2[e2 = j(t2, e2)] && "'" !== t2[e2] || ([e2, o2] = this.readIdentifierVal(t2, e2, "systemIdentifier"));
else if ("SYSTEM" === n2 && ([e2, r2] = this.readIdentifierVal(t2, e2, "systemIdentifier"), !this.suppressValidationErr && !r2)) throw new Error("Missing mandatory system identifier for SYSTEM notation"); else if ("SYSTEM" === s2 && ([e2, o2] = this.readIdentifierVal(t2, e2, "systemIdentifier"), !this.suppressValidationErr && !o2)) throw new Error("Missing mandatory system identifier for SYSTEM notation");
return { notationName: i2, publicIdentifier: s2, systemIdentifier: r2, index: --e2 }; return { notationName: n2, publicIdentifier: r2, systemIdentifier: o2, index: --e2 };
} }
readIdentifierVal(t2, e2, i2) { readIdentifierVal(t2, e2, i2) {
let n2 = ""; let n2 = "";
const s2 = t2[e2]; const s2 = t2[e2];
if ('"' !== s2 && "'" !== s2) throw new Error(`Expected quoted string, found "${s2}"`); if ('"' !== s2 && "'" !== s2) throw new Error(`Expected quoted string, found "${s2}"`);
for (e2++; e2 < t2.length && t2[e2] !== s2; ) n2 += t2[e2], e2++; const r2 = ++e2;
if (t2[e2] !== s2) throw new Error(`Unterminated ${i2} value`); for (; e2 < t2.length && t2[e2] !== s2; ) e2++;
if (n2 = t2.substring(r2, e2), t2[e2] !== s2) throw new Error(`Unterminated ${i2} value`);
return [++e2, n2]; return [++e2, n2];
} }
readElementExp(t2, e2) { readElementExp(t2, e2) {
e2 = j(t2, e2); const i2 = e2 = j(t2, e2);
let i2 = ""; for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) i2 += t2[e2], e2++; let n2 = t2.substring(i2, e2);
if (!this.suppressValidationErr && !r(i2)) throw new Error(`Invalid element name: "${i2}"`); if (!this.suppressValidationErr && !r(n2)) throw new Error(`Invalid element name: "${n2}"`);
let n2 = ""; let s2 = "";
if ("E" === t2[e2 = j(t2, e2)] && _(t2, "MPTY", e2)) e2 += 4; if ("E" === t2[e2 = j(t2, e2)] && _(t2, "MPTY", e2)) e2 += 4;
else if ("A" === t2[e2] && _(t2, "NY", e2)) e2 += 2; else if ("A" === t2[e2] && _(t2, "NY", e2)) e2 += 2;
else if ("(" === t2[e2]) { else if ("(" === t2[e2]) {
for (e2++; e2 < t2.length && ")" !== t2[e2]; ) n2 += t2[e2], e2++; const i3 = ++e2;
if (")" !== t2[e2]) throw new Error("Unterminated content model"); for (; e2 < t2.length && ")" !== t2[e2]; ) e2++;
if (s2 = t2.substring(i3, e2), ")" !== t2[e2]) throw new Error("Unterminated content model");
} else if (!this.suppressValidationErr) throw new Error(`Invalid Element Expression, found "${t2[e2]}"`); } else if (!this.suppressValidationErr) throw new Error(`Invalid Element Expression, found "${t2[e2]}"`);
return { elementName: i2, contentModel: n2.trim(), index: e2 }; return { elementName: n2, contentModel: s2.trim(), index: e2 };
} }
readAttlistExp(t2, e2) { readAttlistExp(t2, e2) {
let i2 = e2 = j(t2, e2);
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
let n2 = t2.substring(i2, e2);
for (D(n2), i2 = e2 = j(t2, e2); e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
let s2 = t2.substring(i2, e2);
if (!D(s2)) throw new Error(`Invalid attribute name: "${s2}"`);
e2 = j(t2, e2); e2 = j(t2, e2);
let i2 = ""; let r2 = "";
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) i2 += t2[e2], e2++;
D(i2), e2 = j(t2, e2);
let n2 = "";
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) n2 += t2[e2], e2++;
if (!D(n2)) throw new Error(`Invalid attribute name: "${n2}"`);
e2 = j(t2, e2);
let s2 = "";
if ("NOTATION" === t2.substring(e2, e2 + 8).toUpperCase()) { if ("NOTATION" === t2.substring(e2, e2 + 8).toUpperCase()) {
if (s2 = "NOTATION", "(" !== t2[e2 = j(t2, e2 += 8)]) throw new Error(`Expected '(', found "${t2[e2]}"`); if (r2 = "NOTATION", "(" !== t2[e2 = j(t2, e2 += 8)]) throw new Error(`Expected '(', found "${t2[e2]}"`);
e2++; e2++;
let i3 = []; let i3 = [];
for (; e2 < t2.length && ")" !== t2[e2]; ) { for (; e2 < t2.length && ")" !== t2[e2]; ) {
let n3 = ""; const n3 = e2;
for (; e2 < t2.length && "|" !== t2[e2] && ")" !== t2[e2]; ) n3 += t2[e2], e2++; for (; e2 < t2.length && "|" !== t2[e2] && ")" !== t2[e2]; ) e2++;
if (n3 = n3.trim(), !D(n3)) throw new Error(`Invalid notation name: "${n3}"`); let s3 = t2.substring(n3, e2);
i3.push(n3), "|" === t2[e2] && (e2++, e2 = j(t2, e2)); if (s3 = s3.trim(), !D(s3)) throw new Error(`Invalid notation name: "${s3}"`);
i3.push(s3), "|" === t2[e2] && (e2++, e2 = j(t2, e2));
} }
if (")" !== t2[e2]) throw new Error("Unterminated list of notations"); if (")" !== t2[e2]) throw new Error("Unterminated list of notations");
e2++, s2 += " (" + i3.join("|") + ")"; e2++, r2 += " (" + i3.join("|") + ")";
} else { } else {
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) s2 += t2[e2], e2++; const i3 = e2;
const i3 = ["CDATA", "ID", "IDREF", "IDREFS", "ENTITY", "ENTITIES", "NMTOKEN", "NMTOKENS"]; for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
if (!this.suppressValidationErr && !i3.includes(s2.toUpperCase())) throw new Error(`Invalid attribute type: "${s2}"`); r2 += t2.substring(i3, e2);
const n3 = ["CDATA", "ID", "IDREF", "IDREFS", "ENTITY", "ENTITIES", "NMTOKEN", "NMTOKENS"];
if (!this.suppressValidationErr && !n3.includes(r2.toUpperCase())) throw new Error(`Invalid attribute type: "${r2}"`);
} }
e2 = j(t2, e2); e2 = j(t2, e2);
let r2 = ""; let o2 = "";
return "#REQUIRED" === t2.substring(e2, e2 + 8).toUpperCase() ? (r2 = "#REQUIRED", e2 += 8) : "#IMPLIED" === t2.substring(e2, e2 + 7).toUpperCase() ? (r2 = "#IMPLIED", e2 += 7) : [e2, r2] = this.readIdentifierVal(t2, e2, "ATTLIST"), { elementName: i2, attributeName: n2, attributeType: s2, defaultValue: r2, index: e2 }; return "#REQUIRED" === t2.substring(e2, e2 + 8).toUpperCase() ? (o2 = "#REQUIRED", e2 += 8) : "#IMPLIED" === t2.substring(e2, e2 + 7).toUpperCase() ? (o2 = "#IMPLIED", e2 += 7) : [e2, o2] = this.readIdentifierVal(t2, e2, "ATTLIST"), { elementName: n2, attributeName: s2, attributeType: r2, defaultValue: o2, index: e2 };
} }
} }
const j = (t2, e2) => { const j = (t2, e2) => {
@@ -60887,9 +60891,9 @@ var require_fxp = __commonJS({
if (r(t2)) return t2; if (r(t2)) return t2;
throw new Error(`Invalid entity name ${t2}`); throw new Error(`Invalid entity name ${t2}`);
} }
const V = /^[-+]?0x[a-fA-F0-9]+$/, k = /^([\-\+])?(0*)([0-9]*(\.[0-9]*)?)$/, F = { hex: true, leadingZeros: true, decimalPoint: ".", eNotation: true }; const V = /^[-+]?0x[a-fA-F0-9]+$/, k = /^([\-\+])?(0*)([0-9]*(\.[0-9]*)?)$/, M = { hex: true, leadingZeros: true, decimalPoint: ".", eNotation: true, infinity: "original" };
const L = /^([-+])?(0*)(\d*(\.\d*)?[eE][-\+]?\d+)$/; const F = /^([-+])?(0*)(\d*(\.\d*)?[eE][-\+]?\d+)$/;
class M { class L {
constructor(t2 = {}) { constructor(t2 = {}) {
this.separator = t2.separator || ".", this.path = [], this.siblingStacks = []; this.separator = t2.separator || ".", this.path = [], this.siblingStacks = [];
} }
@@ -61096,7 +61100,7 @@ var require_fxp = __commonJS({
if ("string" == typeof i2 && t3 === i2) return true; if ("string" == typeof i2 && t3 === i2) return true;
if (i2 instanceof RegExp && i2.test(t3)) return true; if (i2 instanceof RegExp && i2.test(t3)) return true;
} }
} : () => false, this.entityExpansionCount = 0, this.currentExpandedLength = 0, this.matcher = new M(), this.isCurrentNodeStopNode = false, this.options.stopNodes && this.options.stopNodes.length > 0) { } : () => false, this.entityExpansionCount = 0, this.currentExpandedLength = 0, this.matcher = new L(), this.isCurrentNodeStopNode = false, this.options.stopNodes && this.options.stopNodes.length > 0) {
this.stopNodeExpressions = []; this.stopNodeExpressions = [];
for (let t3 = 0; t3 < this.options.stopNodes.length; t3++) { for (let t3 = 0; t3 < this.options.stopNodes.length; t3++) {
const e3 = this.options.stopNodes[t3]; const e3 = this.options.stopNodes[t3];
@@ -61207,7 +61211,7 @@ var require_fxp = __commonJS({
let o2 = s3.tagName; let o2 = s3.tagName;
const a2 = s3.rawTagName; const a2 = s3.rawTagName;
let h2 = s3.tagExp, l2 = s3.attrExpPresent, p2 = s3.closeIndex; let h2 = s3.tagExp, l2 = s3.attrExpPresent, p2 = s3.closeIndex;
if ({ tagName: o2, tagExp: h2 } = rt(this.options.transformTagName, o2, h2, this.options), this.options.strictReservedNames && (o2 === this.options.commentPropName || o2 === this.options.cdataPropName)) throw new Error(`Invalid tag name: ${o2}`); if ({ tagName: o2, tagExp: h2 } = rt(this.options.transformTagName, o2, h2, this.options), this.options.strictReservedNames && (o2 === this.options.commentPropName || o2 === this.options.cdataPropName || o2 === this.options.textNodeName || o2 === this.options.attributesGroupName)) throw new Error(`Invalid tag name: ${o2}`);
i2 && n2 && "!xml" !== i2.tagname && (n2 = this.saveTextToParentTag(n2, i2, this.matcher, false)); i2 && n2 && "!xml" !== i2.tagname && (n2 = this.saveTextToParentTag(n2, i2, this.matcher, false));
const u2 = i2; const u2 = i2;
u2 && -1 !== this.options.unpairedTags.indexOf(u2.tagname) && (i2 = this.tagsNodeStack.pop(), this.matcher.pop()); u2 && -1 !== this.options.unpairedTags.indexOf(u2.tagname) && (i2 = this.tagsNodeStack.pop(), this.matcher.pop());
@@ -61345,7 +61349,7 @@ var require_fxp = __commonJS({
if (e2 && "string" == typeof t2) { if (e2 && "string" == typeof t2) {
const e3 = t2.trim(); const e3 = t2.trim();
return "true" === e3 || "false" !== e3 && (function(t3, e4 = {}) { return "true" === e3 || "false" !== e3 && (function(t3, e4 = {}) {
if (e4 = Object.assign({}, F, e4), !t3 || "string" != typeof t3) return t3; if (e4 = Object.assign({}, M, e4), !t3 || "string" != typeof t3) return t3;
let i3 = t3.trim(); let i3 = t3.trim();
if (void 0 !== e4.skipLike && e4.skipLike.test(i3)) return t3; if (void 0 !== e4.skipLike && e4.skipLike.test(i3)) return t3;
if ("0" === t3) return 0; if ("0" === t3) return 0;
@@ -61355,35 +61359,50 @@ var require_fxp = __commonJS({
if (window && window.parseInt) return window.parseInt(t4, 16); if (window && window.parseInt) return window.parseInt(t4, 16);
throw new Error("parseInt, Number.parseInt, window.parseInt are not supported"); throw new Error("parseInt, Number.parseInt, window.parseInt are not supported");
})(i3); })(i3);
if (i3.includes("e") || i3.includes("E")) return (function(t4, e5, i4) { if (isFinite(i3)) {
if (!i4.eNotation) return t4; if (i3.includes("e") || i3.includes("E")) return (function(t4, e5, i4) {
const n3 = e5.match(L); if (!i4.eNotation) return t4;
if (n3) { const n3 = e5.match(F);
let s2 = n3[1] || ""; if (n3) {
const r2 = -1 === n3[3].indexOf("e") ? "E" : "e", o2 = n3[2], a2 = s2 ? t4[o2.length + 1] === r2 : t4[o2.length] === r2; let s2 = n3[1] || "";
return o2.length > 1 && a2 ? t4 : 1 !== o2.length || !n3[3].startsWith(`.${r2}`) && n3[3][0] !== r2 ? i4.leadingZeros && !a2 ? (e5 = (n3[1] || "") + n3[3], Number(e5)) : t4 : Number(e5); const r2 = -1 === n3[3].indexOf("e") ? "E" : "e", o2 = n3[2], a2 = s2 ? t4[o2.length + 1] === r2 : t4[o2.length] === r2;
} return o2.length > 1 && a2 ? t4 : (1 !== o2.length || !n3[3].startsWith(`.${r2}`) && n3[3][0] !== r2) && o2.length > 0 ? i4.leadingZeros && !a2 ? (e5 = (n3[1] || "") + n3[3], Number(e5)) : t4 : Number(e5);
return t4;
})(t3, i3, e4);
{
const s2 = k.exec(i3);
if (s2) {
const r2 = s2[1] || "", o2 = s2[2];
let a2 = (n2 = s2[3]) && -1 !== n2.indexOf(".") ? ("." === (n2 = n2.replace(/0+$/, "")) ? n2 = "0" : "." === n2[0] ? n2 = "0" + n2 : "." === n2[n2.length - 1] && (n2 = n2.substring(0, n2.length - 1)), n2) : n2;
const h2 = r2 ? "." === t3[o2.length + 1] : "." === t3[o2.length];
if (!e4.leadingZeros && (o2.length > 1 || 1 === o2.length && !h2)) return t3;
{
const n3 = Number(i3), s3 = String(n3);
if (0 === n3) return n3;
if (-1 !== s3.search(/[eE]/)) return e4.eNotation ? n3 : t3;
if (-1 !== i3.indexOf(".")) return "0" === s3 || s3 === a2 || s3 === `${r2}${a2}` ? n3 : t3;
let h3 = o2 ? a2 : i3;
return o2 ? h3 === s3 || r2 + h3 === s3 ? n3 : t3 : h3 === s3 || h3 === r2 + s3 ? n3 : t3;
} }
return t4;
})(t3, i3, e4);
{
const s2 = k.exec(i3);
if (s2) {
const r2 = s2[1] || "", o2 = s2[2];
let a2 = (n2 = s2[3]) && -1 !== n2.indexOf(".") ? ("." === (n2 = n2.replace(/0+$/, "")) ? n2 = "0" : "." === n2[0] ? n2 = "0" + n2 : "." === n2[n2.length - 1] && (n2 = n2.substring(0, n2.length - 1)), n2) : n2;
const h2 = r2 ? "." === t3[o2.length + 1] : "." === t3[o2.length];
if (!e4.leadingZeros && (o2.length > 1 || 1 === o2.length && !h2)) return t3;
{
const n3 = Number(i3), s3 = String(n3);
if (0 === n3) return n3;
if (-1 !== s3.search(/[eE]/)) return e4.eNotation ? n3 : t3;
if (-1 !== i3.indexOf(".")) return "0" === s3 || s3 === a2 || s3 === `${r2}${a2}` ? n3 : t3;
let h3 = o2 ? a2 : i3;
return o2 ? h3 === s3 || r2 + h3 === s3 ? n3 : t3 : h3 === s3 || h3 === r2 + s3 ? n3 : t3;
}
}
return t3;
} }
return t3;
} }
var n2; var n2;
return (function(t4, e5, i4) {
const n3 = e5 === 1 / 0;
switch (i4.infinity.toLowerCase()) {
case "null":
return null;
case "infinity":
return e5;
case "string":
return n3 ? "Infinity" : "-Infinity";
default:
return t4;
}
})(t3, Number(i3), e4);
})(t2, i2); })(t2, i2);
} }
return void 0 !== t2 ? t2 : ""; return void 0 !== t2 ? t2 : "";
@@ -61495,7 +61514,7 @@ var require_fxp = __commonJS({
const i3 = e2.stopNodes[t3]; const i3 = e2.stopNodes[t3];
"string" == typeof i3 ? n2.push(new G(i3)) : i3 instanceof G && n2.push(i3); "string" == typeof i3 ? n2.push(new G(i3)) : i3 instanceof G && n2.push(i3);
} }
return mt(t2, e2, i2, new M(), n2); return mt(t2, e2, i2, new L(), n2);
} }
function mt(t2, e2, i2, n2, s2) { function mt(t2, e2, i2, n2, s2) {
let r2 = "", o2 = false; let r2 = "", o2 = false;
@@ -61643,7 +61662,7 @@ var require_fxp = __commonJS({
if (this.options.preserveOrder) return gt(t2, this.options); if (this.options.preserveOrder) return gt(t2, this.options);
{ {
Array.isArray(t2) && this.options.arrayNodeName && this.options.arrayNodeName.length > 1 && (t2 = { [this.options.arrayNodeName]: t2 }); Array.isArray(t2) && this.options.arrayNodeName && this.options.arrayNodeName.length > 1 && (t2 = { [this.options.arrayNodeName]: t2 });
const e2 = new M(); const e2 = new L();
return this.j2x(t2, 0, e2).val; return this.j2x(t2, 0, e2).val;
} }
}, Pt.prototype.j2x = function(t2, e2, i2) { }, Pt.prototype.j2x = function(t2, e2, i2) {
@@ -102697,6 +102716,7 @@ var require_oids = __commonJS({
_IN("2.5.4.15", "businessCategory"); _IN("2.5.4.15", "businessCategory");
_IN("2.5.4.17", "postalCode"); _IN("2.5.4.17", "postalCode");
_IN("2.5.4.42", "givenName"); _IN("2.5.4.42", "givenName");
_IN("2.5.4.65", "pseudonym");
_IN("1.3.6.1.4.1.311.60.2.1.2", "jurisdictionOfIncorporationStateOrProvinceName"); _IN("1.3.6.1.4.1.311.60.2.1.2", "jurisdictionOfIncorporationStateOrProvinceName");
_IN("1.3.6.1.4.1.311.60.2.1.3", "jurisdictionOfIncorporationCountryName"); _IN("1.3.6.1.4.1.311.60.2.1.3", "jurisdictionOfIncorporationCountryName");
_IN("2.16.840.1.113730.1.1", "nsCertType"); _IN("2.16.840.1.113730.1.1", "nsCertType");
@@ -106309,6 +106329,11 @@ var require_jsbn = __commonJS({
this.multiplyTo(a, r); this.multiplyTo(a, r);
return r; return r;
} }
function bnSquare() {
var r = nbi();
this.squareTo(r);
return r;
}
function bnDivide(a) { function bnDivide(a) {
var r = nbi(); var r = nbi();
this.divRemTo(a, r, null); this.divRemTo(a, r, null);
@@ -106532,6 +106557,9 @@ var require_jsbn = __commonJS({
return r; return r;
} }
function bnModInverse(m) { function bnModInverse(m) {
if (this.signum() == 0) {
return BigInteger.ZERO;
}
var ac = m.isEven(); var ac = m.isEven();
if (this.isEven() && ac || m.signum() == 0) return BigInteger.ZERO; if (this.isEven() && ac || m.signum() == 0) return BigInteger.ZERO;
var u = m.clone(), v = this.clone(); var u = m.clone(), v = this.clone();
@@ -106576,7 +106604,7 @@ var require_jsbn = __commonJS({
if (d.signum() < 0) return d.add(m); if (d.signum() < 0) return d.add(m);
else return d; else return d;
} }
var lowprimes = [2, 3, 5, 7, 11, 13, 17, 19, 23, 29, 31, 37, 41, 43, 47, 53, 59, 61, 67, 71, 73, 79, 83, 89, 97, 101, 103, 107, 109, 113, 127, 131, 137, 139, 149, 151, 157, 163, 167, 173, 179, 181, 191, 193, 197, 199, 211, 223, 227, 229, 233, 239, 241, 251, 257, 263, 269, 271, 277, 281, 283, 293, 307, 311, 313, 317, 331, 337, 347, 349, 353, 359, 367, 373, 379, 383, 389, 397, 401, 409, 419, 421, 431, 433, 439, 443, 449, 457, 461, 463, 467, 479, 487, 491, 499, 503, 509]; var lowprimes = [2, 3, 5, 7, 11, 13, 17, 19, 23, 29, 31, 37, 41, 43, 47, 53, 59, 61, 67, 71, 73, 79, 83, 89, 97, 101, 103, 107, 109, 113, 127, 131, 137, 139, 149, 151, 157, 163, 167, 173, 179, 181, 191, 193, 197, 199, 211, 223, 227, 229, 233, 239, 241, 251, 257, 263, 269, 271, 277, 281, 283, 293, 307, 311, 313, 317, 331, 337, 347, 349, 353, 359, 367, 373, 379, 383, 389, 397, 401, 409, 419, 421, 431, 433, 439, 443, 449, 457, 461, 463, 467, 479, 487, 491, 499, 503, 509, 521, 523, 541, 547, 557, 563, 569, 571, 577, 587, 593, 599, 601, 607, 613, 617, 619, 631, 641, 643, 647, 653, 659, 661, 673, 677, 683, 691, 701, 709, 719, 727, 733, 739, 743, 751, 757, 761, 769, 773, 787, 797, 809, 811, 821, 823, 827, 829, 839, 853, 857, 859, 863, 877, 881, 883, 887, 907, 911, 919, 929, 937, 941, 947, 953, 967, 971, 977, 983, 991, 997];
var lplim = (1 << 26) / lowprimes[lowprimes.length - 1]; var lplim = (1 << 26) / lowprimes[lowprimes.length - 1];
function bnIsProbablePrime(t) { function bnIsProbablePrime(t) {
var i, x = this.abs(); var i, x = this.abs();
@@ -106674,6 +106702,7 @@ var require_jsbn = __commonJS({
BigInteger.prototype.pow = bnPow; BigInteger.prototype.pow = bnPow;
BigInteger.prototype.gcd = bnGCD; BigInteger.prototype.gcd = bnGCD;
BigInteger.prototype.isProbablePrime = bnIsProbablePrime; BigInteger.prototype.isProbablePrime = bnIsProbablePrime;
BigInteger.prototype.square = bnSquare;
} }
}); });
@@ -107869,22 +107898,26 @@ var require_rsa = __commonJS({
} }
if (options === void 0) { if (options === void 0) {
options = { options = {
_parseAllDigestBytes: true _parseAllDigestBytes: true,
_skipPaddingChecks: false
}; };
} }
if (!("_parseAllDigestBytes" in options)) { if (!("_parseAllDigestBytes" in options)) {
options._parseAllDigestBytes = true; options._parseAllDigestBytes = true;
} }
if (!("_skipPaddingChecks" in options)) {
options._skipPaddingChecks = false;
}
if (scheme === "RSASSA-PKCS1-V1_5") { if (scheme === "RSASSA-PKCS1-V1_5") {
scheme = { scheme = {
verify: function(digest2, d2) { verify: function(digest2, d2) {
d2 = _decodePkcs1_v1_5(d2, key, true); d2 = _decodePkcs1_v1_5(d2, key, true, void 0, options);
var obj = asn1.fromDer(d2, { var obj = asn1.fromDer(d2, {
parseAllBytes: options._parseAllDigestBytes parseAllBytes: options._parseAllDigestBytes
}); });
var capture = {}; var capture = {};
var errors = []; var errors = [];
if (!asn1.validate(obj, digestInfoValidator, capture, errors)) { if (!asn1.validate(obj, digestInfoValidator, capture, errors) || obj.value.length !== 2) {
var error3 = new Error( var error3 = new Error(
"ASN.1 object does not contain a valid RSASSA-PKCS1-v1_5 DigestInfo value." "ASN.1 object does not contain a valid RSASSA-PKCS1-v1_5 DigestInfo value."
); );
@@ -107912,7 +107945,7 @@ var require_rsa = __commonJS({
} else if (scheme === "NONE" || scheme === "NULL" || scheme === null) { } else if (scheme === "NONE" || scheme === "NULL" || scheme === null) {
scheme = { scheme = {
verify: function(digest2, d2) { verify: function(digest2, d2) {
d2 = _decodePkcs1_v1_5(d2, key, true); d2 = _decodePkcs1_v1_5(d2, key, true, void 0, options);
return digest2 === d2; return digest2 === d2;
} }
}; };
@@ -108204,12 +108237,12 @@ var require_rsa = __commonJS({
eb.putBytes(m); eb.putBytes(m);
return eb; return eb;
} }
function _decodePkcs1_v1_5(em, key, pub, ml) { function _decodePkcs1_v1_5(em, key, pub, ml, options) {
var k = Math.ceil(key.n.bitLength() / 8); var k = Math.ceil(key.n.bitLength() / 8);
var eb = forge.util.createBuffer(em); var eb = forge.util.createBuffer(em);
var first = eb.getByte(); var first = eb.getByte();
var bt = eb.getByte(); var bt = eb.getByte();
if (first !== 0 || pub && bt !== 0 && bt !== 1 || !pub && bt != 2 || pub && bt === 0 && typeof ml === "undefined") { if (first !== 0 || pub && bt !== 0 && bt !== 1 || !pub && bt !== 2 || pub && bt === 0 && typeof ml === "undefined") {
throw new Error("Encryption block is invalid."); throw new Error("Encryption block is invalid.");
} }
var padNum = 0; var padNum = 0;
@@ -108229,6 +108262,9 @@ var require_rsa = __commonJS({
} }
++padNum; ++padNum;
} }
if (padNum < 8 && !(options ? options._skipPaddingChecks : false)) {
throw new Error("Encryption block is invalid.");
}
} else if (bt === 2) { } else if (bt === 2) {
padNum = 0; padNum = 0;
while (eb.length() > 1) { while (eb.length() > 1) {
@@ -108238,6 +108274,9 @@ var require_rsa = __commonJS({
} }
++padNum; ++padNum;
} }
if (padNum < 8 && !(options ? options._skipPaddingChecks : false)) {
throw new Error("Encryption block is invalid.");
}
} }
var zero = eb.getByte(); var zero = eb.getByte();
if (zero !== 0 || padNum !== k - 3 - eb.length()) { if (zero !== 0 || padNum !== k - 3 - eb.length()) {
@@ -111695,6 +111734,12 @@ var require_x509 = __commonJS({
}; };
} }
} }
if (error3 === null && bcExt === null) {
error3 = {
message: "Certificate is missing basicConstraints extension and cannot be used as a CA.",
error: pki2.certificateError.bad_certificate
};
}
if (error3 === null && bcExt !== null && !bcExt.cA) { if (error3 === null && bcExt !== null && !bcExt.cA) {
error3 = { error3 = {
message: "Certificate basicConstraints indicates the certificate is not a CA.", message: "Certificate basicConstraints indicates the certificate is not a CA.",
@@ -115746,6 +115791,9 @@ var require_ed25519 = __commonJS({
if (unpackneg(q, pk)) { if (unpackneg(q, pk)) {
return -1; return -1;
} }
if (!_isCanonicalSignatureScalar(sm, 32)) {
return -1;
}
for (i = 0; i < n; ++i) { for (i = 0; i < n; ++i) {
m[i] = sm[i]; m[i] = sm[i];
} }
@@ -115771,6 +115819,18 @@ var require_ed25519 = __commonJS({
mlen = n; mlen = n;
return mlen; return mlen;
} }
function _isCanonicalSignatureScalar(bytes, offset) {
var i;
for (i = 31; i >= 0; --i) {
if (bytes[offset + i] < L[i]) {
return true;
}
if (bytes[offset + i] > L[i]) {
return false;
}
}
return false;
}
function modL(r, x) { function modL(r, x) {
var carry, i, j, k; var carry, i, j, k;
for (i = 63; i >= 32; --i) { for (i = 63; i >= 32; --i) {
@@ -120658,7 +120718,7 @@ function getTemporaryDirectory() {
return value !== void 0 && value !== "" ? value : getRequiredEnvParam("RUNNER_TEMP"); return value !== void 0 && value !== "" ? value : getRequiredEnvParam("RUNNER_TEMP");
} }
function getActionVersion() { function getActionVersion() {
return "4.34.1"; return "4.35.2";
} }
function getWorkflowEventName() { function getWorkflowEventName() {
return getRequiredEnvParam("GITHUB_EVENT_NAME"); return getRequiredEnvParam("GITHUB_EVENT_NAME");
@@ -120905,8 +120965,8 @@ var path = __toESM(require("path"));
var semver4 = __toESM(require_semver2()); var semver4 = __toESM(require_semver2());
// src/defaults.json // src/defaults.json
var bundleVersion = "codeql-bundle-v2.24.3"; var bundleVersion = "codeql-bundle-v2.25.1";
var cliVersion = "2.24.3"; var cliVersion = "2.25.1";
// src/overlay/index.ts // src/overlay/index.ts
var actionsCache = __toESM(require_cache5()); var actionsCache = __toESM(require_cache5());
@@ -122223,7 +122283,10 @@ function getCredentials(logger, registrySecrets, registriesCredentials, language
); );
} }
} }
if ((!hasUsername(authConfig) || !isDefined2(authConfig.username)) && isUsernamePassword(authConfig) && isDefined2(authConfig.password) && isPAT(authConfig.password) || isToken(authConfig) && isDefined2(authConfig.token) && isPAT(authConfig.token)) { const noUsername = !hasUsername(authConfig) || !isDefined2(authConfig.username);
const passwordIsPAT = isUsernamePassword(authConfig) && isDefined2(authConfig.password) && isPAT(authConfig.password);
const tokenIsPAT = isToken(authConfig) && isDefined2(authConfig.token) && isPAT(authConfig.token);
if (noUsername && (passwordIsPAT || tokenIsPAT)) {
logger.warning( logger.warning(
`A ${e.type} private registry is configured for ${e.host || e.url} using a GitHub Personal Access Token (PAT), but no username was provided. This may not work correctly. When configuring a private registry using a PAT, select "Username and password" and enter the username of the user who generated the PAT.` `A ${e.type} private registry is configured for ${e.host || e.url} using a GitHub Personal Access Token (PAT), but no username was provided. This may not work correctly. When configuring a private registry using a PAT, select "Username and password" and enter the username of the user who generated the PAT.`
); );
+441 -355
View File
File diff suppressed because it is too large Load Diff
+115 -96
View File
@@ -41057,18 +41057,18 @@ var init_dist_src2 = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js
var VERSION5; var VERSION5;
var init_version2 = __esm({ var init_version2 = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/version.js"() {
VERSION5 = "17.0.0"; VERSION5 = "17.0.0";
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js
var Endpoints, endpoints_default; var Endpoints, endpoints_default;
var init_endpoints = __esm({ var init_endpoints = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/generated/endpoints.js"() {
Endpoints = { Endpoints = {
actions: { actions: {
addCustomLabelsToSelfHostedRunnerForOrg: [ addCustomLabelsToSelfHostedRunnerForOrg: [
@@ -43362,7 +43362,7 @@ var init_endpoints = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js
function endpointsToMethods(octokit) { function endpointsToMethods(octokit) {
const newMethods = {}; const newMethods = {};
for (const scope of endpointMethodsMap.keys()) { for (const scope of endpointMethodsMap.keys()) {
@@ -43413,7 +43413,7 @@ function decorate(octokit, scope, methodName, defaults, decorations) {
} }
var endpointMethodsMap, handler; var endpointMethodsMap, handler;
var init_endpoints_to_methods = __esm({ var init_endpoints_to_methods = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/endpoints-to-methods.js"() {
init_endpoints(); init_endpoints();
endpointMethodsMap = /* @__PURE__ */ new Map(); endpointMethodsMap = /* @__PURE__ */ new Map();
for (const [scope, endpoints] of Object.entries(endpoints_default)) { for (const [scope, endpoints] of Object.entries(endpoints_default)) {
@@ -43491,7 +43491,7 @@ var init_endpoints_to_methods = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js // node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js
var dist_src_exports2 = {}; var dist_src_exports2 = {};
__export(dist_src_exports2, { __export(dist_src_exports2, {
legacyRestEndpointMethods: () => legacyRestEndpointMethods, legacyRestEndpointMethods: () => legacyRestEndpointMethods,
@@ -43511,7 +43511,7 @@ function legacyRestEndpointMethods(octokit) {
}; };
} }
var init_dist_src3 = __esm({ var init_dist_src3 = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js"() { "node_modules/@octokit/plugin-rest-endpoint-methods/dist-src/index.js"() {
init_version2(); init_version2();
init_endpoints_to_methods(); init_endpoints_to_methods();
restEndpointMethods.VERSION = VERSION5; restEndpointMethods.VERSION = VERSION5;
@@ -43519,7 +43519,7 @@ var init_dist_src3 = __esm({
} }
}); });
// node_modules/@actions/github/node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js // node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js
var dist_bundle_exports = {}; var dist_bundle_exports = {};
__export(dist_bundle_exports, { __export(dist_bundle_exports, {
composePaginateRest: () => composePaginateRest, composePaginateRest: () => composePaginateRest,
@@ -43645,7 +43645,7 @@ function paginateRest(octokit) {
} }
var VERSION6, composePaginateRest, paginatingEndpoints; var VERSION6, composePaginateRest, paginatingEndpoints;
var init_dist_bundle5 = __esm({ var init_dist_bundle5 = __esm({
"node_modules/@actions/github/node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js"() { "node_modules/@octokit/plugin-paginate-rest/dist-bundle/index.js"() {
VERSION6 = "0.0.0-development"; VERSION6 = "0.0.0-development";
composePaginateRest = Object.assign(paginate, { composePaginateRest = Object.assign(paginate, {
iterator iterator
@@ -64242,7 +64242,7 @@ var require_fxp = __commonJS({
if (a.some((t3) => i2 === t3.toLowerCase())) throw new Error(`[SECURITY] Invalid ${e2}: "${t2}" is a reserved JavaScript keyword that could cause prototype pollution`); if (a.some((t3) => i2 === t3.toLowerCase())) throw new Error(`[SECURITY] Invalid ${e2}: "${t2}" is a reserved JavaScript keyword that could cause prototype pollution`);
} }
function A(t2) { function A(t2) {
return "boolean" == typeof t2 ? { enabled: t2, maxEntitySize: 1e4, maxExpansionDepth: 10, maxTotalExpansions: 1e3, maxExpandedLength: 1e5, maxEntityCount: 100, allowedTags: null, tagFilter: null } : "object" == typeof t2 && null !== t2 ? { enabled: false !== t2.enabled, maxEntitySize: t2.maxEntitySize ?? 1e4, maxExpansionDepth: t2.maxExpansionDepth ?? 10, maxTotalExpansions: t2.maxTotalExpansions ?? 1e3, maxExpandedLength: t2.maxExpandedLength ?? 1e5, maxEntityCount: t2.maxEntityCount ?? 100, allowedTags: t2.allowedTags ?? null, tagFilter: t2.tagFilter ?? null } : A(true); return "boolean" == typeof t2 ? { enabled: t2, maxEntitySize: 1e4, maxExpansionDepth: 10, maxTotalExpansions: 1e3, maxExpandedLength: 1e5, maxEntityCount: 100, allowedTags: null, tagFilter: null } : "object" == typeof t2 && null !== t2 ? { enabled: false !== t2.enabled, maxEntitySize: Math.max(1, t2.maxEntitySize ?? 1e4), maxExpansionDepth: Math.max(1, t2.maxExpansionDepth ?? 10), maxTotalExpansions: Math.max(1, t2.maxTotalExpansions ?? 1e3), maxExpandedLength: Math.max(1, t2.maxExpandedLength ?? 1e5), maxEntityCount: Math.max(1, t2.maxEntityCount ?? 100), allowedTags: t2.allowedTags ?? null, tagFilter: t2.tagFilter ?? null } : A(true);
} }
const C = function(t2) { const C = function(t2) {
const e2 = Object.assign({}, P, t2), i2 = [{ value: e2.attributeNamePrefix, name: "attributeNamePrefix" }, { value: e2.attributesGroupName, name: "attributesGroupName" }, { value: e2.textNodeName, name: "textNodeName" }, { value: e2.cdataPropName, name: "cdataPropName" }, { value: e2.commentPropName, name: "commentPropName" }]; const e2 = Object.assign({}, P, t2), i2 = [{ value: e2.attributeNamePrefix, name: "attributeNamePrefix" }, { value: e2.attributesGroupName, name: "attributesGroupName" }, { value: e2.textNodeName, name: "textNodeName" }, { value: e2.cdataPropName, name: "cdataPropName" }, { value: e2.commentPropName, name: "commentPropName" }];
@@ -64283,7 +64283,7 @@ var require_fxp = __commonJS({
if (r2 && _2(t2, "!ENTITY", e2)) { if (r2 && _2(t2, "!ENTITY", e2)) {
let s3, r3; let s3, r3;
if (e2 += 7, [s3, r3, e2] = this.readEntityExp(t2, e2 + 1, this.suppressValidationErr), -1 === r3.indexOf("&")) { if (e2 += 7, [s3, r3, e2] = this.readEntityExp(t2, e2 + 1, this.suppressValidationErr), -1 === r3.indexOf("&")) {
if (false !== this.options.enabled && this.options.maxEntityCount && n2 >= this.options.maxEntityCount) throw new Error(`Entity count (${n2 + 1}) exceeds maximum allowed (${this.options.maxEntityCount})`); if (false !== this.options.enabled && null != this.options.maxEntityCount && n2 >= this.options.maxEntityCount) throw new Error(`Entity count (${n2 + 1}) exceeds maximum allowed (${this.options.maxEntityCount})`);
const t3 = s3.replace(/[.*+?^${}()|[\]\\]/g, "\\$&"); const t3 = s3.replace(/[.*+?^${}()|[\]\\]/g, "\\$&");
i2[s3] = { regx: RegExp(`&${t3};`, "g"), val: r3 }, n2++; i2[s3] = { regx: RegExp(`&${t3};`, "g"), val: r3 }, n2++;
} }
@@ -64307,82 +64307,86 @@ var require_fxp = __commonJS({
return { entities: i2, i: e2 }; return { entities: i2, i: e2 };
} }
readEntityExp(t2, e2) { readEntityExp(t2, e2) {
e2 = j(t2, e2); const i2 = e2 = j(t2, e2);
let i2 = ""; for (; e2 < t2.length && !/\s/.test(t2[e2]) && '"' !== t2[e2] && "'" !== t2[e2]; ) e2++;
for (; e2 < t2.length && !/\s/.test(t2[e2]) && '"' !== t2[e2] && "'" !== t2[e2]; ) i2 += t2[e2], e2++; let n2 = t2.substring(i2, e2);
if (D(i2), e2 = j(t2, e2), !this.suppressValidationErr) { if (D(n2), e2 = j(t2, e2), !this.suppressValidationErr) {
if ("SYSTEM" === t2.substring(e2, e2 + 6).toUpperCase()) throw new Error("External entities are not supported"); if ("SYSTEM" === t2.substring(e2, e2 + 6).toUpperCase()) throw new Error("External entities are not supported");
if ("%" === t2[e2]) throw new Error("Parameter entities are not supported"); if ("%" === t2[e2]) throw new Error("Parameter entities are not supported");
} }
let n2 = ""; let s2 = "";
if ([e2, n2] = this.readIdentifierVal(t2, e2, "entity"), false !== this.options.enabled && this.options.maxEntitySize && n2.length > this.options.maxEntitySize) throw new Error(`Entity "${i2}" size (${n2.length}) exceeds maximum allowed size (${this.options.maxEntitySize})`); if ([e2, s2] = this.readIdentifierVal(t2, e2, "entity"), false !== this.options.enabled && null != this.options.maxEntitySize && s2.length > this.options.maxEntitySize) throw new Error(`Entity "${n2}" size (${s2.length}) exceeds maximum allowed size (${this.options.maxEntitySize})`);
return [i2, n2, --e2]; return [n2, s2, --e2];
} }
readNotationExp(t2, e2) { readNotationExp(t2, e2) {
e2 = j(t2, e2); const i2 = e2 = j(t2, e2);
let i2 = ""; for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) i2 += t2[e2], e2++; let n2 = t2.substring(i2, e2);
!this.suppressValidationErr && D(i2), e2 = j(t2, e2); !this.suppressValidationErr && D(n2), e2 = j(t2, e2);
const n2 = t2.substring(e2, e2 + 6).toUpperCase(); const s2 = t2.substring(e2, e2 + 6).toUpperCase();
if (!this.suppressValidationErr && "SYSTEM" !== n2 && "PUBLIC" !== n2) throw new Error(`Expected SYSTEM or PUBLIC, found "${n2}"`); if (!this.suppressValidationErr && "SYSTEM" !== s2 && "PUBLIC" !== s2) throw new Error(`Expected SYSTEM or PUBLIC, found "${s2}"`);
e2 += n2.length, e2 = j(t2, e2); e2 += s2.length, e2 = j(t2, e2);
let s2 = null, r2 = null; let r2 = null, o2 = null;
if ("PUBLIC" === n2) [e2, s2] = this.readIdentifierVal(t2, e2, "publicIdentifier"), '"' !== t2[e2 = j(t2, e2)] && "'" !== t2[e2] || ([e2, r2] = this.readIdentifierVal(t2, e2, "systemIdentifier")); if ("PUBLIC" === s2) [e2, r2] = this.readIdentifierVal(t2, e2, "publicIdentifier"), '"' !== t2[e2 = j(t2, e2)] && "'" !== t2[e2] || ([e2, o2] = this.readIdentifierVal(t2, e2, "systemIdentifier"));
else if ("SYSTEM" === n2 && ([e2, r2] = this.readIdentifierVal(t2, e2, "systemIdentifier"), !this.suppressValidationErr && !r2)) throw new Error("Missing mandatory system identifier for SYSTEM notation"); else if ("SYSTEM" === s2 && ([e2, o2] = this.readIdentifierVal(t2, e2, "systemIdentifier"), !this.suppressValidationErr && !o2)) throw new Error("Missing mandatory system identifier for SYSTEM notation");
return { notationName: i2, publicIdentifier: s2, systemIdentifier: r2, index: --e2 }; return { notationName: n2, publicIdentifier: r2, systemIdentifier: o2, index: --e2 };
} }
readIdentifierVal(t2, e2, i2) { readIdentifierVal(t2, e2, i2) {
let n2 = ""; let n2 = "";
const s2 = t2[e2]; const s2 = t2[e2];
if ('"' !== s2 && "'" !== s2) throw new Error(`Expected quoted string, found "${s2}"`); if ('"' !== s2 && "'" !== s2) throw new Error(`Expected quoted string, found "${s2}"`);
for (e2++; e2 < t2.length && t2[e2] !== s2; ) n2 += t2[e2], e2++; const r2 = ++e2;
if (t2[e2] !== s2) throw new Error(`Unterminated ${i2} value`); for (; e2 < t2.length && t2[e2] !== s2; ) e2++;
if (n2 = t2.substring(r2, e2), t2[e2] !== s2) throw new Error(`Unterminated ${i2} value`);
return [++e2, n2]; return [++e2, n2];
} }
readElementExp(t2, e2) { readElementExp(t2, e2) {
e2 = j(t2, e2); const i2 = e2 = j(t2, e2);
let i2 = ""; for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) i2 += t2[e2], e2++; let n2 = t2.substring(i2, e2);
if (!this.suppressValidationErr && !r(i2)) throw new Error(`Invalid element name: "${i2}"`); if (!this.suppressValidationErr && !r(n2)) throw new Error(`Invalid element name: "${n2}"`);
let n2 = ""; let s2 = "";
if ("E" === t2[e2 = j(t2, e2)] && _2(t2, "MPTY", e2)) e2 += 4; if ("E" === t2[e2 = j(t2, e2)] && _2(t2, "MPTY", e2)) e2 += 4;
else if ("A" === t2[e2] && _2(t2, "NY", e2)) e2 += 2; else if ("A" === t2[e2] && _2(t2, "NY", e2)) e2 += 2;
else if ("(" === t2[e2]) { else if ("(" === t2[e2]) {
for (e2++; e2 < t2.length && ")" !== t2[e2]; ) n2 += t2[e2], e2++; const i3 = ++e2;
if (")" !== t2[e2]) throw new Error("Unterminated content model"); for (; e2 < t2.length && ")" !== t2[e2]; ) e2++;
if (s2 = t2.substring(i3, e2), ")" !== t2[e2]) throw new Error("Unterminated content model");
} else if (!this.suppressValidationErr) throw new Error(`Invalid Element Expression, found "${t2[e2]}"`); } else if (!this.suppressValidationErr) throw new Error(`Invalid Element Expression, found "${t2[e2]}"`);
return { elementName: i2, contentModel: n2.trim(), index: e2 }; return { elementName: n2, contentModel: s2.trim(), index: e2 };
} }
readAttlistExp(t2, e2) { readAttlistExp(t2, e2) {
let i2 = e2 = j(t2, e2);
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
let n2 = t2.substring(i2, e2);
for (D(n2), i2 = e2 = j(t2, e2); e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
let s2 = t2.substring(i2, e2);
if (!D(s2)) throw new Error(`Invalid attribute name: "${s2}"`);
e2 = j(t2, e2); e2 = j(t2, e2);
let i2 = ""; let r2 = "";
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) i2 += t2[e2], e2++;
D(i2), e2 = j(t2, e2);
let n2 = "";
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) n2 += t2[e2], e2++;
if (!D(n2)) throw new Error(`Invalid attribute name: "${n2}"`);
e2 = j(t2, e2);
let s2 = "";
if ("NOTATION" === t2.substring(e2, e2 + 8).toUpperCase()) { if ("NOTATION" === t2.substring(e2, e2 + 8).toUpperCase()) {
if (s2 = "NOTATION", "(" !== t2[e2 = j(t2, e2 += 8)]) throw new Error(`Expected '(', found "${t2[e2]}"`); if (r2 = "NOTATION", "(" !== t2[e2 = j(t2, e2 += 8)]) throw new Error(`Expected '(', found "${t2[e2]}"`);
e2++; e2++;
let i3 = []; let i3 = [];
for (; e2 < t2.length && ")" !== t2[e2]; ) { for (; e2 < t2.length && ")" !== t2[e2]; ) {
let n3 = ""; const n3 = e2;
for (; e2 < t2.length && "|" !== t2[e2] && ")" !== t2[e2]; ) n3 += t2[e2], e2++; for (; e2 < t2.length && "|" !== t2[e2] && ")" !== t2[e2]; ) e2++;
if (n3 = n3.trim(), !D(n3)) throw new Error(`Invalid notation name: "${n3}"`); let s3 = t2.substring(n3, e2);
i3.push(n3), "|" === t2[e2] && (e2++, e2 = j(t2, e2)); if (s3 = s3.trim(), !D(s3)) throw new Error(`Invalid notation name: "${s3}"`);
i3.push(s3), "|" === t2[e2] && (e2++, e2 = j(t2, e2));
} }
if (")" !== t2[e2]) throw new Error("Unterminated list of notations"); if (")" !== t2[e2]) throw new Error("Unterminated list of notations");
e2++, s2 += " (" + i3.join("|") + ")"; e2++, r2 += " (" + i3.join("|") + ")";
} else { } else {
for (; e2 < t2.length && !/\s/.test(t2[e2]); ) s2 += t2[e2], e2++; const i3 = e2;
const i3 = ["CDATA", "ID", "IDREF", "IDREFS", "ENTITY", "ENTITIES", "NMTOKEN", "NMTOKENS"]; for (; e2 < t2.length && !/\s/.test(t2[e2]); ) e2++;
if (!this.suppressValidationErr && !i3.includes(s2.toUpperCase())) throw new Error(`Invalid attribute type: "${s2}"`); r2 += t2.substring(i3, e2);
const n3 = ["CDATA", "ID", "IDREF", "IDREFS", "ENTITY", "ENTITIES", "NMTOKEN", "NMTOKENS"];
if (!this.suppressValidationErr && !n3.includes(r2.toUpperCase())) throw new Error(`Invalid attribute type: "${r2}"`);
} }
e2 = j(t2, e2); e2 = j(t2, e2);
let r2 = ""; let o2 = "";
return "#REQUIRED" === t2.substring(e2, e2 + 8).toUpperCase() ? (r2 = "#REQUIRED", e2 += 8) : "#IMPLIED" === t2.substring(e2, e2 + 7).toUpperCase() ? (r2 = "#IMPLIED", e2 += 7) : [e2, r2] = this.readIdentifierVal(t2, e2, "ATTLIST"), { elementName: i2, attributeName: n2, attributeType: s2, defaultValue: r2, index: e2 }; return "#REQUIRED" === t2.substring(e2, e2 + 8).toUpperCase() ? (o2 = "#REQUIRED", e2 += 8) : "#IMPLIED" === t2.substring(e2, e2 + 7).toUpperCase() ? (o2 = "#IMPLIED", e2 += 7) : [e2, o2] = this.readIdentifierVal(t2, e2, "ATTLIST"), { elementName: n2, attributeName: s2, attributeType: r2, defaultValue: o2, index: e2 };
} }
} }
const j = (t2, e2) => { const j = (t2, e2) => {
@@ -64397,9 +64401,9 @@ var require_fxp = __commonJS({
if (r(t2)) return t2; if (r(t2)) return t2;
throw new Error(`Invalid entity name ${t2}`); throw new Error(`Invalid entity name ${t2}`);
} }
const V = /^[-+]?0x[a-fA-F0-9]+$/, k = /^([\-\+])?(0*)([0-9]*(\.[0-9]*)?)$/, F = { hex: true, leadingZeros: true, decimalPoint: ".", eNotation: true }; const V = /^[-+]?0x[a-fA-F0-9]+$/, k = /^([\-\+])?(0*)([0-9]*(\.[0-9]*)?)$/, M = { hex: true, leadingZeros: true, decimalPoint: ".", eNotation: true, infinity: "original" };
const L = /^([-+])?(0*)(\d*(\.\d*)?[eE][-\+]?\d+)$/; const F = /^([-+])?(0*)(\d*(\.\d*)?[eE][-\+]?\d+)$/;
class M { class L {
constructor(t2 = {}) { constructor(t2 = {}) {
this.separator = t2.separator || ".", this.path = [], this.siblingStacks = []; this.separator = t2.separator || ".", this.path = [], this.siblingStacks = [];
} }
@@ -64606,7 +64610,7 @@ var require_fxp = __commonJS({
if ("string" == typeof i2 && t3 === i2) return true; if ("string" == typeof i2 && t3 === i2) return true;
if (i2 instanceof RegExp && i2.test(t3)) return true; if (i2 instanceof RegExp && i2.test(t3)) return true;
} }
} : () => false, this.entityExpansionCount = 0, this.currentExpandedLength = 0, this.matcher = new M(), this.isCurrentNodeStopNode = false, this.options.stopNodes && this.options.stopNodes.length > 0) { } : () => false, this.entityExpansionCount = 0, this.currentExpandedLength = 0, this.matcher = new L(), this.isCurrentNodeStopNode = false, this.options.stopNodes && this.options.stopNodes.length > 0) {
this.stopNodeExpressions = []; this.stopNodeExpressions = [];
for (let t3 = 0; t3 < this.options.stopNodes.length; t3++) { for (let t3 = 0; t3 < this.options.stopNodes.length; t3++) {
const e3 = this.options.stopNodes[t3]; const e3 = this.options.stopNodes[t3];
@@ -64717,7 +64721,7 @@ var require_fxp = __commonJS({
let o2 = s3.tagName; let o2 = s3.tagName;
const a2 = s3.rawTagName; const a2 = s3.rawTagName;
let h2 = s3.tagExp, l2 = s3.attrExpPresent, p2 = s3.closeIndex; let h2 = s3.tagExp, l2 = s3.attrExpPresent, p2 = s3.closeIndex;
if ({ tagName: o2, tagExp: h2 } = rt(this.options.transformTagName, o2, h2, this.options), this.options.strictReservedNames && (o2 === this.options.commentPropName || o2 === this.options.cdataPropName)) throw new Error(`Invalid tag name: ${o2}`); if ({ tagName: o2, tagExp: h2 } = rt(this.options.transformTagName, o2, h2, this.options), this.options.strictReservedNames && (o2 === this.options.commentPropName || o2 === this.options.cdataPropName || o2 === this.options.textNodeName || o2 === this.options.attributesGroupName)) throw new Error(`Invalid tag name: ${o2}`);
i2 && n2 && "!xml" !== i2.tagname && (n2 = this.saveTextToParentTag(n2, i2, this.matcher, false)); i2 && n2 && "!xml" !== i2.tagname && (n2 = this.saveTextToParentTag(n2, i2, this.matcher, false));
const u2 = i2; const u2 = i2;
u2 && -1 !== this.options.unpairedTags.indexOf(u2.tagname) && (i2 = this.tagsNodeStack.pop(), this.matcher.pop()); u2 && -1 !== this.options.unpairedTags.indexOf(u2.tagname) && (i2 = this.tagsNodeStack.pop(), this.matcher.pop());
@@ -64855,7 +64859,7 @@ var require_fxp = __commonJS({
if (e2 && "string" == typeof t2) { if (e2 && "string" == typeof t2) {
const e3 = t2.trim(); const e3 = t2.trim();
return "true" === e3 || "false" !== e3 && (function(t3, e4 = {}) { return "true" === e3 || "false" !== e3 && (function(t3, e4 = {}) {
if (e4 = Object.assign({}, F, e4), !t3 || "string" != typeof t3) return t3; if (e4 = Object.assign({}, M, e4), !t3 || "string" != typeof t3) return t3;
let i3 = t3.trim(); let i3 = t3.trim();
if (void 0 !== e4.skipLike && e4.skipLike.test(i3)) return t3; if (void 0 !== e4.skipLike && e4.skipLike.test(i3)) return t3;
if ("0" === t3) return 0; if ("0" === t3) return 0;
@@ -64865,35 +64869,50 @@ var require_fxp = __commonJS({
if (window && window.parseInt) return window.parseInt(t4, 16); if (window && window.parseInt) return window.parseInt(t4, 16);
throw new Error("parseInt, Number.parseInt, window.parseInt are not supported"); throw new Error("parseInt, Number.parseInt, window.parseInt are not supported");
})(i3); })(i3);
if (i3.includes("e") || i3.includes("E")) return (function(t4, e5, i4) { if (isFinite(i3)) {
if (!i4.eNotation) return t4; if (i3.includes("e") || i3.includes("E")) return (function(t4, e5, i4) {
const n3 = e5.match(L); if (!i4.eNotation) return t4;
if (n3) { const n3 = e5.match(F);
let s2 = n3[1] || ""; if (n3) {
const r2 = -1 === n3[3].indexOf("e") ? "E" : "e", o2 = n3[2], a2 = s2 ? t4[o2.length + 1] === r2 : t4[o2.length] === r2; let s2 = n3[1] || "";
return o2.length > 1 && a2 ? t4 : 1 !== o2.length || !n3[3].startsWith(`.${r2}`) && n3[3][0] !== r2 ? i4.leadingZeros && !a2 ? (e5 = (n3[1] || "") + n3[3], Number(e5)) : t4 : Number(e5); const r2 = -1 === n3[3].indexOf("e") ? "E" : "e", o2 = n3[2], a2 = s2 ? t4[o2.length + 1] === r2 : t4[o2.length] === r2;
} return o2.length > 1 && a2 ? t4 : (1 !== o2.length || !n3[3].startsWith(`.${r2}`) && n3[3][0] !== r2) && o2.length > 0 ? i4.leadingZeros && !a2 ? (e5 = (n3[1] || "") + n3[3], Number(e5)) : t4 : Number(e5);
return t4;
})(t3, i3, e4);
{
const s2 = k.exec(i3);
if (s2) {
const r2 = s2[1] || "", o2 = s2[2];
let a2 = (n2 = s2[3]) && -1 !== n2.indexOf(".") ? ("." === (n2 = n2.replace(/0+$/, "")) ? n2 = "0" : "." === n2[0] ? n2 = "0" + n2 : "." === n2[n2.length - 1] && (n2 = n2.substring(0, n2.length - 1)), n2) : n2;
const h2 = r2 ? "." === t3[o2.length + 1] : "." === t3[o2.length];
if (!e4.leadingZeros && (o2.length > 1 || 1 === o2.length && !h2)) return t3;
{
const n3 = Number(i3), s3 = String(n3);
if (0 === n3) return n3;
if (-1 !== s3.search(/[eE]/)) return e4.eNotation ? n3 : t3;
if (-1 !== i3.indexOf(".")) return "0" === s3 || s3 === a2 || s3 === `${r2}${a2}` ? n3 : t3;
let h3 = o2 ? a2 : i3;
return o2 ? h3 === s3 || r2 + h3 === s3 ? n3 : t3 : h3 === s3 || h3 === r2 + s3 ? n3 : t3;
} }
return t4;
})(t3, i3, e4);
{
const s2 = k.exec(i3);
if (s2) {
const r2 = s2[1] || "", o2 = s2[2];
let a2 = (n2 = s2[3]) && -1 !== n2.indexOf(".") ? ("." === (n2 = n2.replace(/0+$/, "")) ? n2 = "0" : "." === n2[0] ? n2 = "0" + n2 : "." === n2[n2.length - 1] && (n2 = n2.substring(0, n2.length - 1)), n2) : n2;
const h2 = r2 ? "." === t3[o2.length + 1] : "." === t3[o2.length];
if (!e4.leadingZeros && (o2.length > 1 || 1 === o2.length && !h2)) return t3;
{
const n3 = Number(i3), s3 = String(n3);
if (0 === n3) return n3;
if (-1 !== s3.search(/[eE]/)) return e4.eNotation ? n3 : t3;
if (-1 !== i3.indexOf(".")) return "0" === s3 || s3 === a2 || s3 === `${r2}${a2}` ? n3 : t3;
let h3 = o2 ? a2 : i3;
return o2 ? h3 === s3 || r2 + h3 === s3 ? n3 : t3 : h3 === s3 || h3 === r2 + s3 ? n3 : t3;
}
}
return t3;
} }
return t3;
} }
var n2; var n2;
return (function(t4, e5, i4) {
const n3 = e5 === 1 / 0;
switch (i4.infinity.toLowerCase()) {
case "null":
return null;
case "infinity":
return e5;
case "string":
return n3 ? "Infinity" : "-Infinity";
default:
return t4;
}
})(t3, Number(i3), e4);
})(t2, i2); })(t2, i2);
} }
return void 0 !== t2 ? t2 : ""; return void 0 !== t2 ? t2 : "";
@@ -65005,7 +65024,7 @@ var require_fxp = __commonJS({
const i3 = e2.stopNodes[t3]; const i3 = e2.stopNodes[t3];
"string" == typeof i3 ? n2.push(new G(i3)) : i3 instanceof G && n2.push(i3); "string" == typeof i3 ? n2.push(new G(i3)) : i3 instanceof G && n2.push(i3);
} }
return mt(t2, e2, i2, new M(), n2); return mt(t2, e2, i2, new L(), n2);
} }
function mt(t2, e2, i2, n2, s2) { function mt(t2, e2, i2, n2, s2) {
let r2 = "", o2 = false; let r2 = "", o2 = false;
@@ -65153,7 +65172,7 @@ var require_fxp = __commonJS({
if (this.options.preserveOrder) return gt(t2, this.options); if (this.options.preserveOrder) return gt(t2, this.options);
{ {
Array.isArray(t2) && this.options.arrayNodeName && this.options.arrayNodeName.length > 1 && (t2 = { [this.options.arrayNodeName]: t2 }); Array.isArray(t2) && this.options.arrayNodeName && this.options.arrayNodeName.length > 1 && (t2 = { [this.options.arrayNodeName]: t2 });
const e2 = new M(); const e2 = new L();
return this.j2x(t2, 0, e2).val; return this.j2x(t2, 0, e2).val;
} }
}, Pt.prototype.j2x = function(t2, e2, i2) { }, Pt.prototype.j2x = function(t2, e2, i2) {
@@ -107800,7 +107819,7 @@ var require_commonjs19 = __commonJS({
var openPattern = /\\{/g; var openPattern = /\\{/g;
var closePattern = /\\}/g; var closePattern = /\\}/g;
var commaPattern = /\\,/g; var commaPattern = /\\,/g;
var periodPattern = /\\./g; var periodPattern = /\\\./g;
exports2.EXPANSION_MAX = 1e5; exports2.EXPANSION_MAX = 1e5;
function numeric(str2) { function numeric(str2) {
return !isNaN(str2) ? parseInt(str2, 10) : str2.charCodeAt(0); return !isNaN(str2) ? parseInt(str2, 10) : str2.charCodeAt(0);
@@ -107895,7 +107914,7 @@ var require_commonjs19 = __commonJS({
const x = numeric(n[0]); const x = numeric(n[0]);
const y = numeric(n[1]); const y = numeric(n[1]);
const width = Math.max(n[0].length, n[1].length); const width = Math.max(n[0].length, n[1].length);
let incr = n.length === 3 && n[2] !== void 0 ? Math.abs(numeric(n[2])) : 1; let incr = n.length === 3 && n[2] !== void 0 ? Math.max(Math.abs(numeric(n[2])), 1) : 1;
let test = lte; let test = lte;
const reverse = y < x; const reverse = y < x;
if (reverse) { if (reverse) {
@@ -151274,7 +151293,7 @@ var require_brace_expansion2 = __commonJS({
var x = numeric(n[0]); var x = numeric(n[0]);
var y = numeric(n[1]); var y = numeric(n[1]);
var width = Math.max(n[0].length, n[1].length); var width = Math.max(n[0].length, n[1].length);
var incr = n.length == 3 ? Math.abs(numeric(n[2])) : 1; var incr = n.length == 3 ? Math.max(Math.abs(numeric(n[2])), 1) : 1;
var test = lte; var test = lte;
var reverse = y < x; var reverse = y < x;
if (reverse) { if (reverse) {
@@ -161479,7 +161498,7 @@ function getTemporaryDirectory() {
return value !== void 0 && value !== "" ? value : getRequiredEnvParam("RUNNER_TEMP"); return value !== void 0 && value !== "" ? value : getRequiredEnvParam("RUNNER_TEMP");
} }
function getActionVersion() { function getActionVersion() {
return "4.34.1"; return "4.35.2";
} }
var persistedInputsKey = "persisted_inputs"; var persistedInputsKey = "persisted_inputs";
var restoreInputs = function() { var restoreInputs = function() {
+441 -355
View File
File diff suppressed because it is too large Load Diff
+580 -257
View File
File diff suppressed because it is too large Load Diff
+16 -9
View File
@@ -1,6 +1,6 @@
{ {
"name": "codeql", "name": "codeql",
"version": "4.34.1", "version": "4.35.2",
"private": true, "private": true,
"description": "CodeQL action", "description": "CodeQL action",
"scripts": { "scripts": {
@@ -12,7 +12,9 @@
"ava": "npm run transpile && ava --verbose", "ava": "npm run transpile && ava --verbose",
"test": "npm run ava -- src/", "test": "npm run ava -- src/",
"test-debug": "npm run test -- --timeout=20m", "test-debug": "npm run test -- --timeout=20m",
"transpile": "tsc --build --verbose" "test-coverage": "c8 npm run test",
"transpile": "tsc --build --verbose",
"coverage": "c8 report --check-coverage"
}, },
"license": "MIT", "license": "MIT",
"workspaces": [ "workspaces": [
@@ -30,7 +32,6 @@
"@actions/io": "^2.0.0", "@actions/io": "^2.0.0",
"@actions/tool-cache": "^3.0.1", "@actions/tool-cache": "^3.0.1",
"@octokit/plugin-retry": "^8.0.0", "@octokit/plugin-retry": "^8.0.0",
"@schemastore/package": "0.0.10",
"archiver": "^7.0.1", "archiver": "^7.0.1",
"fast-deep-equal": "^3.1.3", "fast-deep-equal": "^3.1.3",
"follow-redirects": "^1.15.11", "follow-redirects": "^1.15.11",
@@ -39,7 +40,7 @@
"js-yaml": "^4.1.1", "js-yaml": "^4.1.1",
"jsonschema": "1.4.1", "jsonschema": "1.4.1",
"long": "^5.3.2", "long": "^5.3.2",
"node-forge": "^1.3.3", "node-forge": "^1.4.0",
"semver": "^7.7.4", "semver": "^7.7.4",
"uuid": "^13.0.0" "uuid": "^13.0.0"
}, },
@@ -57,19 +58,20 @@
"@types/semver": "^7.7.1", "@types/semver": "^7.7.1",
"@types/sinon": "^21.0.0", "@types/sinon": "^21.0.0",
"ava": "^7.0.0", "ava": "^7.0.0",
"esbuild": "^0.27.3", "c8": "^11.0.0",
"esbuild": "^0.27.4",
"eslint": "^9.39.2", "eslint": "^9.39.2",
"eslint-import-resolver-typescript": "^3.8.7", "eslint-import-resolver-typescript": "^3.8.7",
"eslint-plugin-github": "^6.0.0", "eslint-plugin-github": "^6.0.0",
"eslint-plugin-import-x": "^4.16.1", "eslint-plugin-import-x": "^4.16.2",
"eslint-plugin-jsdoc": "^62.7.1", "eslint-plugin-jsdoc": "^62.8.0",
"eslint-plugin-no-async-foreach": "^0.1.1", "eslint-plugin-no-async-foreach": "^0.1.1",
"glob": "^11.1.0", "glob": "^11.1.0",
"globals": "^17.4.0", "globals": "^17.4.0",
"nock": "^14.0.11", "nock": "^14.0.11",
"sinon": "^21.0.2", "sinon": "^21.0.3",
"typescript": "^5.9.3", "typescript": "^5.9.3",
"typescript-eslint": "^8.57.0" "typescript-eslint": "^8.57.1"
}, },
"overrides": { "overrides": {
"@actions/tool-cache": { "@actions/tool-cache": {
@@ -92,5 +94,10 @@
}, },
"brace-expansion@2.0.1": "2.0.2", "brace-expansion@2.0.1": "2.0.2",
"glob": "^11.1.0" "glob": "^11.1.0"
},
"c8": {
"functions": 80,
"lines": 80,
"branches": 80
} }
} }
+1 -1
View File
@@ -5,7 +5,7 @@ versions:
- default - default
steps: steps:
- name: Set up Ruby - name: Set up Ruby
uses: ruby/setup-ruby@09a7688d3b55cf0e976497ff046b70949eeaccfd # v1.288.0 uses: ruby/setup-ruby@319994f95fa847cf3fb3cd3dbe89f6dcde9f178f # v1.295.0
with: with:
ruby-version: 2.6 ruby-version: 2.6
- name: Install Code Scanning integration - name: Install Code Scanning integration
+10
View File
@@ -0,0 +1,10 @@
import path from "path";
/** The oldest supported major version of the CodeQL Action. */
export const OLDEST_SUPPORTED_MAJOR_VERSION = 3;
/** The `pr-checks` directory. */
export const PR_CHECKS_DIR = __dirname;
/** The path of the file configuring which checks shouldn't be required. */
export const PR_CHECK_EXCLUDED_FILE = path.join(PR_CHECKS_DIR, "excluded.yml");
+16
View File
@@ -0,0 +1,16 @@
# PR checks to exclude from required checks
contains:
- "https://"
- "Update"
- "ESLint"
- "update"
- "test-setup-python-scripts"
is:
- "CodeQL"
- "Dependabot"
- "check-expected-release-files"
- "Agent"
- "Cleanup artifacts"
- "Prepare"
- "Upload results"
- "Label PR with size"
+7 -3
View File
@@ -2,11 +2,15 @@
"private": true, "private": true,
"description": "Dependencies for the sync.ts", "description": "Dependencies for the sync.ts",
"dependencies": { "dependencies": {
"yaml": "^2.8.2" "@actions/core": "^2.0.3",
"@actions/github": "^8.0.1",
"@octokit/core": "^7.0.6",
"@octokit/plugin-paginate-rest": ">=9.2.2",
"@octokit/plugin-rest-endpoint-methods": "^17.0.0",
"yaml": "^2.8.3"
}, },
"devDependencies": { "devDependencies": {
"@types/node": "^20.19.9", "@types/node": "^20.19.9",
"tsx": "^4.21.0", "tsx": "^4.21.0"
"typescript": "^5.9.3"
} }
} }
+61
View File
@@ -0,0 +1,61 @@
#!/usr/bin/env npx tsx
/*
Tests for the release-branches.ts script
*/
import * as assert from "node:assert/strict";
import { describe, it } from "node:test";
import { computeBackportBranches } from "./release-branches";
describe("computeBackportBranches", async () => {
await it("rejects invalid major versions", () => {
// The majorVersion is expected to be in vN format.
assert.throws(() => computeBackportBranches("3", "v4.28.0", 3));
assert.throws(() => computeBackportBranches("v3.1", "v4.28.0", 3));
});
await it("rejects invalid latest tags", () => {
// The latestTag is expected to be in vN.M.P format.
assert.throws(() => computeBackportBranches("v3", "v4", 3));
assert.throws(() => computeBackportBranches("v3", "4", 3));
assert.throws(() => computeBackportBranches("v3", "v4.28", 3));
assert.throws(() => computeBackportBranches("v3", "4.28", 3));
assert.throws(() => computeBackportBranches("v3", "4.28.0", 3));
});
await it("sets backport source branch based on major version", () => {
// Test that the backport source branch is releases/v{majorVersion}
const result = computeBackportBranches("v3", "v4.28.0", 3);
assert.equal(result.backportSourceBranch, "releases/v3");
});
await it("no backport targets when major version is the oldest supported", () => {
// When majorVersion equals the major version of latestTag and we do not support older major versions,
// then there are no older supported branches to backport to.
const result = computeBackportBranches("v3", "v3.28.0", 3);
assert.deepEqual(result.backportTargetBranches, []);
});
await it("backports to older supported major versions", () => {
const result = computeBackportBranches("v4", "v4.1.0", 3);
assert.equal(result.backportSourceBranch, "releases/v4");
assert.deepEqual(result.backportTargetBranches, ["releases/v3"]);
});
await it("backports to multiple older supported branches", () => {
const result = computeBackportBranches("v5", "v5.0.0", 3);
assert.equal(result.backportSourceBranch, "releases/v5");
assert.deepEqual(result.backportTargetBranches, [
"releases/v4",
"releases/v3",
]);
});
await it("does not backport when major version is older than latest tag", () => {
const result = computeBackportBranches("v2", "v3.28.0", 2);
assert.equal(result.backportSourceBranch, "releases/v2");
assert.deepEqual(result.backportTargetBranches, []);
});
});
+121
View File
@@ -0,0 +1,121 @@
#!/usr/bin/env npx tsx
import { parseArgs } from "node:util";
import * as core from "@actions/core";
import { OLDEST_SUPPORTED_MAJOR_VERSION } from "./config";
/** The results of checking which release branches to backport to. */
export interface BackportInfo {
/** The source release branch. */
backportSourceBranch: string;
/**
* The computed release branches we should backport to.
* Will be empty if there are no branches we need to backport to.
*/
backportTargetBranches: string[];
}
/**
* Compute the backport source and target branches for a release.
*
* @param majorVersion - The major version string (e.g. "v4").
* @param latestTag - The most recent tag published to the repository (e.g. "v4.32.6").
* @param oldestSupportedMajorVersion - The oldest supported major version number.
* @returns The names of the source branch and target branches.
*/
export function computeBackportBranches(
majorVersion: string,
latestTag: string,
oldestSupportedMajorVersion: number,
): BackportInfo {
// Perform some sanity checks on the inputs.
// For `majorVersion`, we expect exactly `vN` for some `N`.
const majorVersionMatch = majorVersion.match(/^v(\d+)$/);
if (!majorVersionMatch) {
throw new Error("--major-version value must be in `vN` format.");
}
// For latestTag, we expect something starting with `vN.M.P`
const latestTagMatch = latestTag.match(/^v(\d+)\.\d+\.\d+/);
if (!latestTagMatch) {
throw new Error(
`--latest-tag value must be in 'vN.M.P' format, but '${latestTag}' is not.`,
);
}
const majorVersionNumber = Number.parseInt(majorVersionMatch[1]);
const latestTagMajor = Number.parseInt(latestTagMatch[1]);
// If this is a primary release, we backport to all supported branches,
// so we check whether the majorVersion taken from the package.json
// is greater than or equal to the latest tag pulled from the repo.
// For example...
// 'v1' >= 'v2' is False # we're operating from an older release branch and should not backport
// 'v2' >= 'v2' is True # the normal case where we're updating the current version
// 'v3' >= 'v2' is True # in this case we are making the first release of a new major version
const considerBackports = majorVersionNumber >= latestTagMajor;
const backportSourceBranch = `releases/v${majorVersionNumber}`;
const backportTargetBranches: string[] = [];
if (considerBackports) {
for (let i = majorVersionNumber - 1; i > 0; i--) {
const branchName = `releases/v${i}`;
if (i >= oldestSupportedMajorVersion) {
backportTargetBranches.push(branchName);
}
}
}
return { backportSourceBranch, backportTargetBranches };
}
async function main() {
const { values: options } = parseArgs({
options: {
// The major version of the release in `vN` format (e.g. `v4`).
"major-version": {
type: "string",
},
// The most recent tag published to the repository (e.g. `v4.28.0`).
"latest-tag": {
type: "string",
},
},
strict: true,
});
if (options["major-version"] === undefined) {
throw Error("--major-version is required");
}
if (options["latest-tag"] === undefined) {
throw Error("--latest-tag is required");
}
const majorVersion = options["major-version"];
const latestTag = options["latest-tag"];
console.log(`Major version: ${majorVersion}`);
console.log(`Latest tag: ${latestTag}`);
const result = computeBackportBranches(
majorVersion,
latestTag,
OLDEST_SUPPORTED_MAJOR_VERSION,
);
core.setOutput("backport_source_branch", result.backportSourceBranch);
core.setOutput(
"backport_target_branches",
JSON.stringify(result.backportTargetBranches),
);
process.exit(0);
}
// Only call `main` if this script was run directly.
if (require.main === module) {
void main();
}
+60
View File
@@ -0,0 +1,60 @@
#!/usr/bin/env npx tsx
/*
Tests for the sync-checks.ts script
*/
import * as assert from "node:assert/strict";
import { describe, it } from "node:test";
import { CheckInfo, Exclusions, Options, removeExcluded } from "./sync-checks";
const defaultOptions: Options = {
apply: false,
verbose: false,
};
const toCheckInfo = (name: string) =>
({ context: name, app_id: -1 }) satisfies CheckInfo;
const expectedPartialMatches = ["PR Check - Foo", "https://example.com"].map(
toCheckInfo,
);
const expectedExactMatches = ["CodeQL", "Update"].map(toCheckInfo);
const testChecks = expectedExactMatches.concat(expectedPartialMatches);
const emptyExclusions: Exclusions = {
is: [],
contains: [],
};
describe("removeExcluded", async () => {
await it("retains all checks if no exclusions are configured", () => {
const retained = removeExcluded(
defaultOptions,
emptyExclusions,
testChecks,
);
assert.deepEqual(retained, testChecks);
});
await it("removes exact matches", () => {
const retained = removeExcluded(
defaultOptions,
{ ...emptyExclusions, is: ["CodeQL", "Update"] },
testChecks,
);
assert.deepEqual(retained, expectedPartialMatches);
});
await it("removes partial matches", () => {
const retained = removeExcluded(
defaultOptions,
{ ...emptyExclusions, contains: ["https://", "PR Check"] },
testChecks,
);
assert.deepEqual(retained, expectedExactMatches);
});
});
+299
View File
@@ -0,0 +1,299 @@
#!/usr/bin/env npx tsx
/** Update the required checks based on the current branch. */
import * as fs from "fs";
import { parseArgs } from "node:util";
import * as githubUtils from "@actions/github/lib/utils";
import { type Octokit } from "@octokit/core";
import { type PaginateInterface } from "@octokit/plugin-paginate-rest";
import { type Api } from "@octokit/plugin-rest-endpoint-methods";
import * as yaml from "yaml";
import {
OLDEST_SUPPORTED_MAJOR_VERSION,
PR_CHECK_EXCLUDED_FILE,
} from "./config";
/** Represents the command-line options. */
export interface Options {
/** The token to use to authenticate to the GitHub API. */
token?: string;
/** The git ref to use the checks for. */
ref?: string;
/** Whether to actually apply the changes or not. */
apply: boolean;
/** Whether to output additional information. */
verbose: boolean;
}
/** Identifies the CodeQL Action repository. */
const codeqlActionRepo = {
owner: "github",
repo: "codeql-action",
};
/** Represents a configuration of which checks should not be set up as required checks. */
export interface Exclusions {
/** A list of strings that, if contained in a check name, are excluded. */
contains: string[];
/** A list of check names that are excluded if their name is an exact match. */
is: string[];
}
/** Loads the configuration for which checks to exclude. */
function loadExclusions(): Exclusions {
return yaml.parse(
fs.readFileSync(PR_CHECK_EXCLUDED_FILE, "utf-8"),
) as Exclusions;
}
/** The type of the Octokit client. */
type ApiClient = Octokit & Api & { paginate: PaginateInterface };
/** Constructs an `ApiClient` using `token` for authentication. */
function getApiClient(token: string): ApiClient {
const opts = githubUtils.getOctokitOptions(token);
return new githubUtils.GitHub(opts);
}
/**
* Represents information about a check run. We track the `app_id` that generated the check,
* because the API will require it in addition to the name in the future.
*/
export interface CheckInfo {
/** The display name of the check. */
context: string;
/** The ID of the app that generated the check. */
app_id: number;
}
/** Removes entries from `checkInfos` based on the configuration. */
export function removeExcluded(
options: Options,
exclusions: Exclusions,
checkInfos: CheckInfo[],
): CheckInfo[] {
if (options.verbose) {
console.log(exclusions);
}
return checkInfos.filter((checkInfo) => {
if (exclusions.is.includes(checkInfo.context)) {
console.info(
`Excluding '${checkInfo.context}' because it is an exact exclusion.`,
);
return false;
}
for (const containsStr of exclusions.contains) {
if (checkInfo.context.includes(containsStr)) {
console.info(
`Excluding '${checkInfo.context}' because it contains '${containsStr}'.`,
);
return false;
}
}
// Keep.
return true;
});
}
/** Gets a list of check run names for `ref`. */
async function getChecksFor(
options: Options,
client: ApiClient,
ref: string,
): Promise<CheckInfo[]> {
console.info(`Getting checks for '${ref}'`);
const response = await client.paginate(
"GET /repos/{owner}/{repo}/commits/{ref}/check-runs",
{
...codeqlActionRepo,
ref,
},
);
if (response.length === 0) {
throw new Error(`No checks found for '${ref}'.`);
}
console.info(`Retrieved ${response.length} check runs.`);
const notSkipped = response.filter(
(checkRun) => checkRun.conclusion !== "skipped",
);
console.info(`Of those: ${notSkipped.length} were not skipped.`);
// We use the ID of the app that generated the check run when returned by the API,
// but default to -1 to tell the API that any check with the given name should be
// required.
const checkInfos = notSkipped.map((check) => ({
context: check.name,
app_id: check.app?.id || -1,
}));
// Load the configuration for which checks to exclude and apply it before
// returning the checks.
const exclusions = loadExclusions();
return removeExcluded(options, exclusions, checkInfos);
}
/** Gets the current list of release branches. */
async function getReleaseBranches(client: ApiClient): Promise<string[]> {
const refs = await client.rest.git.listMatchingRefs({
...codeqlActionRepo,
ref: "heads/releases/v",
});
return refs.data.map((ref) => ref.ref).sort();
}
/** Updates the required status checks for `branch` to `checks`. */
async function patchBranchProtectionRule(
client: ApiClient,
branch: string,
checks: Set<string>,
) {
await client.rest.repos.setStatusCheckContexts({
...codeqlActionRepo,
branch,
contexts: Array.from(checks),
});
}
/** Sets `checkNames` as required checks for `branch`. */
async function updateBranch(
options: Options,
client: ApiClient,
branch: string,
checkNames: Set<string>,
) {
console.info(`Updating '${branch}'...`);
// Query the current set of required checks for this branch.
const currentContexts = await client.rest.repos.getAllStatusCheckContexts({
...codeqlActionRepo,
branch,
});
// Identify which required checks we will remove and which ones we will add.
const currentCheckNames = new Set(currentContexts.data);
let additions = 0;
let removals = 0;
let unchanged = 0;
for (const currentCheck of currentCheckNames) {
if (!checkNames.has(currentCheck)) {
console.info(`- Removing '${currentCheck}' for branch '${branch}'`);
removals++;
} else {
unchanged++;
}
}
for (const newCheck of checkNames) {
if (!currentCheckNames.has(newCheck)) {
console.info(`+ Adding '${newCheck}' for branch '${branch}'`);
additions++;
}
}
console.info(
`For '${branch}': ${removals} removals; ${additions} additions; ${unchanged} unchanged`,
);
// Perform the update if there are changes and `--apply` was specified.
if (unchanged === checkNames.size && removals === 0 && additions === 0) {
console.info("Not applying changes because there is nothing to do.");
} else if (options.apply) {
await patchBranchProtectionRule(client, branch, checkNames);
} else {
console.info("Not applying changes because `--apply` was not specified.");
}
}
async function main(): Promise<void> {
const { values: options } = parseArgs({
options: {
// The token to use to authenticate to the API.
token: {
type: "string",
},
// The git ref for which to retrieve the check runs.
ref: {
type: "string",
default: "main",
},
// By default, we perform a dry-run. Setting `apply` to `true` actually applies the changes.
apply: {
type: "boolean",
default: false,
},
// Whether to output additional information.
verbose: {
type: "boolean",
default: false,
},
},
strict: true,
});
if (options.token === undefined) {
throw new Error("Missing --token");
}
console.info(
`Oldest supported major version is: ${OLDEST_SUPPORTED_MAJOR_VERSION}`,
);
// Initialise the API client.
const client = getApiClient(options.token);
// Find the check runs for the specified `ref` that we will later set as the required checks
// for the main and release branches.
const checkInfos = await getChecksFor(options, client, options.ref);
const checkNames = new Set(checkInfos.map((info) => info.context));
// Update the main branch.
await updateBranch(options, client, "main", checkNames);
// Retrieve the refs of the release branches.
const releaseBranches = await getReleaseBranches(client);
console.info(
`Found ${releaseBranches.length} release branches: ${releaseBranches.join(", ")}`,
);
for (const releaseBranchRef of releaseBranches) {
// Sanity check that the ref name is in the expected format and extract the major version.
const releaseBranchMatch = releaseBranchRef.match(
/^refs\/heads\/(releases\/v(\d+))/,
);
if (!releaseBranchMatch) {
console.warn(
`Branch ref '${releaseBranchRef}' not in the expected format.`,
);
continue;
}
const releaseBranch = releaseBranchMatch[1];
const releaseBranchMajor = Number.parseInt(releaseBranchMatch[2]);
// Update the required checks for this major version if it is still supported.
if (releaseBranchMajor < OLDEST_SUPPORTED_MAJOR_VERSION) {
console.info(
`Skipping '${releaseBranch}' since it is older than v${OLDEST_SUPPORTED_MAJOR_VERSION}`,
);
continue;
} else {
await updateBranch(options, client, releaseBranch, checkNames);
}
}
process.exit(0);
}
// Only call `main` if this script was run directly.
if (require.main === module) {
void main();
}
+6
View File
@@ -53,6 +53,12 @@ export function getTemporaryDirectory(): string {
: getRequiredEnvParam("RUNNER_TEMP"); : getRequiredEnvParam("RUNNER_TEMP");
} }
const PR_DIFF_RANGE_JSON_FILENAME = "pr-diff-range.json";
export function getDiffRangesJsonFilePath(): string {
return path.join(getTemporaryDirectory(), PR_DIFF_RANGE_JSON_FILENAME);
}
export function getActionVersion(): string { export function getActionVersion(): string {
return __CODEQL_ACTION_VERSION__; return __CODEQL_ACTION_VERSION__;
} }
+2 -9
View File
@@ -28,7 +28,6 @@ import {
DependencyCacheUploadStatusReport, DependencyCacheUploadStatusReport,
uploadDependencyCaches, uploadDependencyCaches,
} from "./dependency-caching"; } from "./dependency-caching";
import { getDiffInformedAnalysisBranches } from "./diff-informed-analysis-utils";
import { EnvVar } from "./environment"; import { EnvVar } from "./environment";
import { initFeatures } from "./feature-flags"; import { initFeatures } from "./feature-flags";
import { KnownLanguage } from "./languages"; import { KnownLanguage } from "./languages";
@@ -305,14 +304,8 @@ async function run(startedAt: Date) {
logger, logger,
); );
const branches = await getDiffInformedAnalysisBranches( // Setup diff informed analysis if needed (based on whether init created the file)
codeql, const diffRangePackDir = await setupDiffInformedQueryRun(logger);
features,
logger,
);
const diffRangePackDir = branches
? await setupDiffInformedQueryRun(branches, logger)
: undefined;
await warnIfGoInstalledAfterInit(config, logger); await warnIfGoInstalledAfterInit(config, logger);
await runAutobuildIfLegacyGoWorkflow(config, logger); await runAutobuildIfLegacyGoWorkflow(config, logger);
+10 -16
View File
@@ -5,11 +5,7 @@ import { performance } from "perf_hooks";
import * as io from "@actions/io"; import * as io from "@actions/io";
import * as yaml from "js-yaml"; import * as yaml from "js-yaml";
import { import { getTemporaryDirectory, getRequiredInput } from "./actions-util";
getTemporaryDirectory,
getRequiredInput,
PullRequestBranches,
} from "./actions-util";
import * as analyses from "./analyses"; import * as analyses from "./analyses";
import { setupCppAutobuild } from "./autobuild"; import { setupCppAutobuild } from "./autobuild";
import { type CodeQL } from "./codeql"; import { type CodeQL } from "./codeql";
@@ -21,8 +17,7 @@ import {
import { addDiagnostic, makeDiagnostic } from "./diagnostics"; import { addDiagnostic, makeDiagnostic } from "./diagnostics";
import { import {
DiffThunkRange, DiffThunkRange,
writeDiffRangesJsonFile, readDiffRangesJsonFile,
getPullRequestEditedDiffRanges,
} from "./diff-informed-analysis-utils"; } from "./diff-informed-analysis-utils";
import { EnvVar } from "./environment"; import { EnvVar } from "./environment";
import { FeatureEnablement, Feature } from "./feature-flags"; import { FeatureEnablement, Feature } from "./feature-flags";
@@ -237,16 +232,19 @@ async function finalizeDatabaseCreation(
* the diff range information, or `undefined` if the feature is disabled. * the diff range information, or `undefined` if the feature is disabled.
*/ */
export async function setupDiffInformedQueryRun( export async function setupDiffInformedQueryRun(
branches: PullRequestBranches,
logger: Logger, logger: Logger,
): Promise<string | undefined> { ): Promise<string | undefined> {
return await withGroupAsync( return await withGroupAsync(
"Generating diff range extension pack", "Generating diff range extension pack",
async () => { async () => {
logger.info( const diffRanges = readDiffRangesJsonFile(logger);
`Calculating diff ranges for ${branches.base}...${branches.head}`, if (diffRanges === undefined) {
); logger.info(
const diffRanges = await getPullRequestEditedDiffRanges(branches, logger); "No precomputed diff ranges found; skipping diff-informed analysis stage.",
);
return undefined;
}
const checkoutPath = getRequiredInput("checkout_path"); const checkoutPath = getRequiredInput("checkout_path");
const packDir = writeDiffRangeDataExtensionPack( const packDir = writeDiffRangeDataExtensionPack(
logger, logger,
@@ -368,10 +366,6 @@ dataExtensions:
`Wrote pr-diff-range extension pack to ${extensionFilePath}:\n${extensionContents}`, `Wrote pr-diff-range extension pack to ${extensionFilePath}:\n${extensionContents}`,
); );
// Write the diff ranges to a JSON file, for action-side alert filtering by the
// upload-lib module.
writeDiffRangesJsonFile(logger, ranges);
return diffRangeDir; return diffRangeDir;
} }
+1 -1
View File
@@ -143,7 +143,7 @@ test("scanArtifactsForTokens handles files without tokens", async (t) => {
if (os.platform() !== "win32") { if (os.platform() !== "win32") {
test("scanArtifactsForTokens finds token in debug artifacts", async (t) => { test("scanArtifactsForTokens finds token in debug artifacts", async (t) => {
t.timeout(15000); // 15 seconds t.timeout(30 * 1000); // 30 seconds
const messages: LoggedMessage[] = []; const messages: LoggedMessage[] = [];
const logger = getRecordingLogger(messages, { logToConsole: false }); const logger = getRecordingLogger(messages, { logToConsole: false });
// The zip here is a regression test based on // The zip here is a regression test based on
+1 -1
View File
@@ -1936,7 +1936,7 @@ test.serial(
"Fallback due to old git version", "Fallback due to old git version",
{ {
overlayDatabaseEnvVar: "overlay", overlayDatabaseEnvVar: "overlay",
gitVersion: new GitVersionInfo("2.30.0", "2.30.0"), // Version below required 2.38.0 gitVersion: new GitVersionInfo("2.10.0", "2.10.0"), // Version below required 2.11.0
}, },
{ {
disabledReason: OverlayDisabledReason.IncompatibleGit, disabledReason: OverlayDisabledReason.IncompatibleGit,
+4 -4
View File
@@ -1,6 +1,6 @@
{ {
"bundleVersion": "codeql-bundle-v2.24.3", "bundleVersion": "codeql-bundle-v2.25.1",
"cliVersion": "2.24.3", "cliVersion": "2.25.1",
"priorBundleVersion": "codeql-bundle-v2.24.2", "priorBundleVersion": "codeql-bundle-v2.24.3",
"priorCliVersion": "2.24.2" "priorCliVersion": "2.24.3"
} }
+10 -8
View File
@@ -1,5 +1,4 @@
import * as fs from "fs"; import * as fs from "fs";
import * as path from "path";
import * as actionsUtil from "./actions-util"; import * as actionsUtil from "./actions-util";
import type { PullRequestBranches } from "./actions-util"; import type { PullRequestBranches } from "./actions-util";
@@ -77,16 +76,12 @@ export interface DiffThunkRange {
endLine: number; endLine: number;
} }
function getDiffRangesJsonFilePath(): string {
return path.join(actionsUtil.getTemporaryDirectory(), "pr-diff-range.json");
}
export function writeDiffRangesJsonFile( export function writeDiffRangesJsonFile(
logger: Logger, logger: Logger,
ranges: DiffThunkRange[], ranges: DiffThunkRange[],
): void { ): void {
const jsonContents = JSON.stringify(ranges, null, 2); const jsonContents = JSON.stringify(ranges, null, 2);
const jsonFilePath = getDiffRangesJsonFilePath(); const jsonFilePath = actionsUtil.getDiffRangesJsonFilePath();
fs.writeFileSync(jsonFilePath, jsonContents); fs.writeFileSync(jsonFilePath, jsonContents);
logger.debug( logger.debug(
`Wrote pr-diff-range JSON file to ${jsonFilePath}:\n${jsonContents}`, `Wrote pr-diff-range JSON file to ${jsonFilePath}:\n${jsonContents}`,
@@ -96,7 +91,7 @@ export function writeDiffRangesJsonFile(
export function readDiffRangesJsonFile( export function readDiffRangesJsonFile(
logger: Logger, logger: Logger,
): DiffThunkRange[] | undefined { ): DiffThunkRange[] | undefined {
const jsonFilePath = getDiffRangesJsonFilePath(); const jsonFilePath = actionsUtil.getDiffRangesJsonFilePath();
if (!fs.existsSync(jsonFilePath)) { if (!fs.existsSync(jsonFilePath)) {
logger.debug(`Diff ranges JSON file does not exist at ${jsonFilePath}`); logger.debug(`Diff ranges JSON file does not exist at ${jsonFilePath}`);
return undefined; return undefined;
@@ -105,7 +100,14 @@ export function readDiffRangesJsonFile(
logger.debug( logger.debug(
`Read pr-diff-range JSON file from ${jsonFilePath}:\n${jsonContents}`, `Read pr-diff-range JSON file from ${jsonFilePath}:\n${jsonContents}`,
); );
return JSON.parse(jsonContents) as DiffThunkRange[]; try {
return JSON.parse(jsonContents) as DiffThunkRange[];
} catch (e) {
logger.warning(
`Failed to parse diff ranges JSON file at ${jsonFilePath}: ${e}`,
);
return undefined;
}
} }
/** /**
+9 -9
View File
@@ -347,9 +347,9 @@ test.serial("getFileOidsUnderPath returns correct file mapping", async (t) => {
const runGitCommandStub = sinon const runGitCommandStub = sinon
.stub(gitUtils as any, "runGitCommand") .stub(gitUtils as any, "runGitCommand")
.resolves( .resolves(
"30d998ded095371488be3a729eb61d86ed721a18_lib/git-utils.js\n" + "100644 30d998ded095371488be3a729eb61d86ed721a18 0\tlib/git-utils.js\n" +
"d89514599a9a99f22b4085766d40af7b99974827_lib/git-utils.js.map\n" + "100644 d89514599a9a99f22b4085766d40af7b99974827 0\tlib/git-utils.js.map\n" +
"a47c11f5bfdca7661942d2c8f1b7209fb0dfdf96_src/git-utils.ts", "100644 a47c11f5bfdca7661942d2c8f1b7209fb0dfdf96 0\tsrc/git-utils.ts",
); );
const result = await gitUtils.getFileOidsUnderPath("/fake/path"); const result = await gitUtils.getFileOidsUnderPath("/fake/path");
@@ -362,7 +362,7 @@ test.serial("getFileOidsUnderPath returns correct file mapping", async (t) => {
t.deepEqual(runGitCommandStub.firstCall.args, [ t.deepEqual(runGitCommandStub.firstCall.args, [
"/fake/path", "/fake/path",
["ls-files", "--recurse-submodules", "--format=%(objectname)_%(path)"], ["ls-files", "--recurse-submodules", "--stage"],
"Cannot list Git OIDs of tracked files.", "Cannot list Git OIDs of tracked files.",
]); ]);
}); });
@@ -371,9 +371,9 @@ test.serial("getFileOidsUnderPath handles quoted paths", async (t) => {
sinon sinon
.stub(gitUtils as any, "runGitCommand") .stub(gitUtils as any, "runGitCommand")
.resolves( .resolves(
"30d998ded095371488be3a729eb61d86ed721a18_lib/normal-file.js\n" + "100644 30d998ded095371488be3a729eb61d86ed721a18 0\tlib/normal-file.js\n" +
'd89514599a9a99f22b4085766d40af7b99974827_"lib/file with spaces.js"\n' + '100644 d89514599a9a99f22b4085766d40af7b99974827 0\t"lib/file with spaces.js"\n' +
'a47c11f5bfdca7661942d2c8f1b7209fb0dfdf96_"lib/file\\twith\\ttabs.js"', '100644 a47c11f5bfdca7661942d2c8f1b7209fb0dfdf96 0\t"lib/file\\twith\\ttabs.js"',
); );
const result = await gitUtils.getFileOidsUnderPath("/fake/path"); const result = await gitUtils.getFileOidsUnderPath("/fake/path");
@@ -398,9 +398,9 @@ test.serial(
sinon sinon
.stub(gitUtils as any, "runGitCommand") .stub(gitUtils as any, "runGitCommand")
.resolves( .resolves(
"30d998ded095371488be3a729eb61d86ed721a18_lib/git-utils.js\n" + "100644 30d998ded095371488be3a729eb61d86ed721a18 0\tlib/git-utils.js\n" +
"invalid-line-format\n" + "invalid-line-format\n" +
"a47c11f5bfdca7661942d2c8f1b7209fb0dfdf96_src/git-utils.ts", "100644 a47c11f5bfdca7661942d2c8f1b7209fb0dfdf96 0\tsrc/git-utils.ts",
); );
await t.throwsAsync( await t.throwsAsync(
+14 -9
View File
@@ -14,10 +14,11 @@ import {
import { ConfigurationError, getRequiredEnvParam } from "./util"; import { ConfigurationError, getRequiredEnvParam } from "./util";
/** /**
* Minimum Git version required for overlay analysis. The `git ls-files --format` * Minimum Git version required for overlay analysis. Support for using the `git ls-files
* option, which is used by `getFileOidsUnderPath`, was introduced in Git 2.38.0. * --recurse-submodules` option with `--stage` was added in Git 2.36.0. For more information, see
* `getFileOidsUnderPath`.
*/ */
export const GIT_MINIMUM_VERSION_FOR_OVERLAY = "2.38.0"; export const GIT_MINIMUM_VERSION_FOR_OVERLAY = "2.36.0";
/** /**
* Git version information * Git version information
@@ -252,24 +253,28 @@ export const getGitRoot = async function (
* *
* @param basePath A path into the Git repository. * @param basePath A path into the Git repository.
* @returns a map from file paths (relative to `basePath`) to Git OIDs. * @returns a map from file paths (relative to `basePath`) to Git OIDs.
* @throws {Error} if "git ls-tree" produces unexpected output. * @throws {Error} if "git ls-files" produces unexpected output.
*/ */
export const getFileOidsUnderPath = async function ( export const getFileOidsUnderPath = async function (
basePath: string, basePath: string,
): Promise<{ [key: string]: string }> { ): Promise<{ [key: string]: string }> {
// Without the --full-name flag, the path is relative to the current working // Without the --full-name flag, the path is relative to the current working
// directory of the git command, which is basePath. // directory of the git command, which is basePath.
//
// We use --stage rather than --format here because --stage has been available since Git 2.36.0,
// while --format was only introduced in Git 2.38.0.
const stdout = await runGitCommand( const stdout = await runGitCommand(
basePath, basePath,
["ls-files", "--recurse-submodules", "--format=%(objectname)_%(path)"], ["ls-files", "--recurse-submodules", "--stage"],
"Cannot list Git OIDs of tracked files.", "Cannot list Git OIDs of tracked files.",
); );
const fileOidMap: { [key: string]: string } = {}; const fileOidMap: { [key: string]: string } = {};
// With --format=%(objectname)_%(path), the output is a list of lines like: // With --stage, the output is a list of lines like:
// 30d998ded095371488be3a729eb61d86ed721a18_lib/git-utils.js // 100644 4c51bc1d9e86cd86e01b0f340cb8ce095c33b283 0\tsrc/git-utils.test.ts
// d89514599a9a99f22b4085766d40af7b99974827_lib/git-utils.js.map // 100644 6b792ea543ce75d7a8a03df591e3c85311ecb64f 0\tsrc/git-utils.ts
const regex = /^([0-9a-f]{40})_(.+)$/; // The fields are: <mode> <oid> <stage>\t<path>
const regex = /^[0-9]+ ([0-9a-f]{40}) [0-9]+\t(.+)$/;
for (const line of stdout.split("\n")) { for (const line of stdout.split("\n")) {
if (line) { if (line) {
const match = line.match(regex); const match = line.match(regex);
+43 -1
View File
@@ -37,6 +37,11 @@ import {
makeDiagnostic, makeDiagnostic,
makeTelemetryDiagnostic, makeTelemetryDiagnostic,
} from "./diagnostics"; } from "./diagnostics";
import {
getDiffInformedAnalysisBranches,
getPullRequestEditedDiffRanges,
writeDiffRangesJsonFile,
} from "./diff-informed-analysis-utils";
import { EnvVar } from "./environment"; import { EnvVar } from "./environment";
import { Feature, FeatureEnablement, initFeatures } from "./feature-flags"; import { Feature, FeatureEnablement, initFeatures } from "./feature-flags";
import { import {
@@ -54,7 +59,7 @@ import {
runDatabaseInitCluster, runDatabaseInitCluster,
} from "./init"; } from "./init";
import { JavaEnvVars, KnownLanguage } from "./languages"; import { JavaEnvVars, KnownLanguage } from "./languages";
import { getActionsLogger, Logger } from "./logging"; import { getActionsLogger, Logger, withGroupAsync } from "./logging";
import { import {
downloadOverlayBaseDatabaseFromCache, downloadOverlayBaseDatabaseFromCache,
OverlayBaseDatabaseDownloadStats, OverlayBaseDatabaseDownloadStats,
@@ -413,6 +418,7 @@ async function run(startedAt: Date) {
} }
await checkInstallPython311(config.languages, codeql); await checkInstallPython311(config.languages, codeql);
await computeAndPersistDiffRanges(codeql, features, logger);
} catch (unwrappedError) { } catch (unwrappedError) {
const error = wrapError(unwrappedError); const error = wrapError(unwrappedError);
core.setFailed(error.message); core.setFailed(error.message);
@@ -833,6 +839,42 @@ async function loadRepositoryProperties(
} }
} }
/**
* Compute and persist diff ranges when diff-informed analysis is enabled
* (feature flag + PR context). This writes the standard pr-diff-range.json
* file for later reuse in the analyze step. Failures are logged but non-fatal.
*/
async function computeAndPersistDiffRanges(
codeql: CodeQL,
features: FeatureEnablement,
logger: Logger,
): Promise<void> {
await withGroupAsync("Computing PR diff ranges", async () => {
try {
const branches = await getDiffInformedAnalysisBranches(
codeql,
features,
logger,
);
if (!branches) {
return;
}
const ranges = await getPullRequestEditedDiffRanges(branches, logger);
if (ranges === undefined) {
return;
}
writeDiffRangesJsonFile(logger, ranges);
const distinctFiles = new Set(ranges.map((r) => r.path)).size;
logger.info(
`Persisted ${ranges.length} diff range(s) across ${distinctFiles} file(s).`,
);
} catch (e) {
logger.warning(
`Failed to compute and persist PR diff ranges: ${getErrorMessage(e)}`,
);
}
});
}
async function recordZstdAvailability( async function recordZstdAvailability(
config: configUtils.Config, config: configUtils.Config,
zstdAvailability: ZstdAvailability, zstdAvailability: ZstdAvailability,
+258 -6
View File
@@ -34,12 +34,14 @@ test.serial(
"writeOverlayChangesFile generates correct changes file", "writeOverlayChangesFile generates correct changes file",
async (t) => { async (t) => {
await withTmpDir(async (tmpDir) => { await withTmpDir(async (tmpDir) => {
const dbLocation = path.join(tmpDir, "db"); const [dbLocation, sourceRoot, tempDir] = ["db", "src", "temp"].map((d) =>
await fs.promises.mkdir(dbLocation, { recursive: true }); path.join(tmpDir, d),
const sourceRoot = path.join(tmpDir, "src"); );
await fs.promises.mkdir(sourceRoot, { recursive: true }); await Promise.all(
const tempDir = path.join(tmpDir, "temp"); [dbLocation, sourceRoot, tempDir].map((d) =>
await fs.promises.mkdir(tempDir, { recursive: true }); fs.promises.mkdir(d, { recursive: true }),
),
);
const logger = getRunnerLogger(true); const logger = getRunnerLogger(true);
const config = createTestConfig({ dbLocation }); const config = createTestConfig({ dbLocation });
@@ -70,9 +72,16 @@ test.serial(
// Write the overlay changes file, which uses the mocked overlay OIDs // Write the overlay changes file, which uses the mocked overlay OIDs
// and the base database OIDs file // and the base database OIDs file
const diffRangeFilePath = path.join(tempDir, "pr-diff-range.json");
const getTempDirStub = sinon const getTempDirStub = sinon
.stub(actionsUtil, "getTemporaryDirectory") .stub(actionsUtil, "getTemporaryDirectory")
.returns(tempDir); .returns(tempDir);
const getDiffRangesStub = sinon
.stub(actionsUtil, "getDiffRangesJsonFilePath")
.returns(diffRangeFilePath);
const getGitRootStub = sinon
.stub(gitUtils, "getGitRoot")
.resolves(sourceRoot);
const changesFilePath = await writeOverlayChangesFile( const changesFilePath = await writeOverlayChangesFile(
config, config,
sourceRoot, sourceRoot,
@@ -80,6 +89,8 @@ test.serial(
); );
getFileOidsStubForOverlay.restore(); getFileOidsStubForOverlay.restore();
getTempDirStub.restore(); getTempDirStub.restore();
getDiffRangesStub.restore();
getGitRootStub.restore();
const fileContent = await fs.promises.readFile(changesFilePath, "utf-8"); const fileContent = await fs.promises.readFile(changesFilePath, "utf-8");
const parsedContent = JSON.parse(fileContent) as { changes: string[] }; const parsedContent = JSON.parse(fileContent) as { changes: string[] };
@@ -93,6 +104,247 @@ test.serial(
}, },
); );
test.serial(
"writeOverlayChangesFile merges additional diff files into overlay changes",
async (t) => {
await withTmpDir(async (tmpDir) => {
const [dbLocation, sourceRoot, tempDir] = ["db", "src", "temp"].map((d) =>
path.join(tmpDir, d),
);
await Promise.all(
[dbLocation, sourceRoot, tempDir].map((d) =>
fs.promises.mkdir(d, { recursive: true }),
),
);
const logger = getRunnerLogger(true);
const config = createTestConfig({ dbLocation });
// Mock the getFileOidsUnderPath function to return base OIDs
// "reverted.js" has the same OID in both base and current, simulating
// a revert PR where the file content matches the overlay-base
const baseOids = {
"unchanged.js": "aaa111",
"modified.js": "bbb222",
"reverted.js": "eee555",
};
const getFileOidsStubForBase = sinon
.stub(gitUtils, "getFileOidsUnderPath")
.resolves(baseOids);
// Write the base database OIDs file
await writeBaseDatabaseOidsFile(config, sourceRoot);
getFileOidsStubForBase.restore();
// Mock the getFileOidsUnderPath function to return overlay OIDs
// "reverted.js" has the same OID as the base -- OID comparison alone
// would NOT include it, only additionalChangedFiles causes it to appear
const currentOids = {
"unchanged.js": "aaa111",
"modified.js": "ddd444", // Changed OID
"reverted.js": "eee555", // Same OID as base -- not detected by OID comparison
};
const getFileOidsStubForOverlay = sinon
.stub(gitUtils, "getFileOidsUnderPath")
.resolves(currentOids);
const diffRangeFilePath = path.join(tempDir, "pr-diff-range.json");
const getTempDirStub = sinon
.stub(actionsUtil, "getTemporaryDirectory")
.returns(tempDir);
const getDiffRangesStub = sinon
.stub(actionsUtil, "getDiffRangesJsonFilePath")
.returns(diffRangeFilePath);
const getGitRootStub = sinon
.stub(gitUtils, "getGitRoot")
.resolves(sourceRoot);
// Write a pr-diff-range.json file with diff ranges including
// "reverted.js" (unchanged OIDs) and "modified.js" (already in OID changes)
await fs.promises.writeFile(
diffRangeFilePath,
JSON.stringify([
{ path: "reverted.js", startLine: 1, endLine: 10 },
{ path: "modified.js", startLine: 1, endLine: 5 },
{ path: "diff-only.js", startLine: 1, endLine: 3 },
]),
);
const changesFilePath = await writeOverlayChangesFile(
config,
sourceRoot,
logger,
);
getFileOidsStubForOverlay.restore();
getTempDirStub.restore();
getDiffRangesStub.restore();
getGitRootStub.restore();
const fileContent = await fs.promises.readFile(changesFilePath, "utf-8");
const parsedContent = JSON.parse(fileContent) as { changes: string[] };
t.deepEqual(
parsedContent.changes.sort(),
["diff-only.js", "modified.js", "reverted.js"],
"Should include OID-changed files, diff-only files, and deduplicate overlapping files",
);
});
},
);
test.serial(
"writeOverlayChangesFile works without additional diff files",
async (t) => {
await withTmpDir(async (tmpDir) => {
const [dbLocation, sourceRoot, tempDir] = ["db", "src", "temp"].map((d) =>
path.join(tmpDir, d),
);
await Promise.all(
[dbLocation, sourceRoot, tempDir].map((d) =>
fs.promises.mkdir(d, { recursive: true }),
),
);
const logger = getRunnerLogger(true);
const config = createTestConfig({ dbLocation });
// Mock the getFileOidsUnderPath function to return base OIDs
const baseOids = {
"unchanged.js": "aaa111",
"modified.js": "bbb222",
};
const getFileOidsStubForBase = sinon
.stub(gitUtils, "getFileOidsUnderPath")
.resolves(baseOids);
await writeBaseDatabaseOidsFile(config, sourceRoot);
getFileOidsStubForBase.restore();
const currentOids = {
"unchanged.js": "aaa111",
"modified.js": "ddd444",
};
const getFileOidsStubForOverlay = sinon
.stub(gitUtils, "getFileOidsUnderPath")
.resolves(currentOids);
const diffRangeFilePath = path.join(tempDir, "pr-diff-range.json");
const getTempDirStub = sinon
.stub(actionsUtil, "getTemporaryDirectory")
.returns(tempDir);
const getDiffRangesStub = sinon
.stub(actionsUtil, "getDiffRangesJsonFilePath")
.returns(diffRangeFilePath);
const getGitRootStub = sinon
.stub(gitUtils, "getGitRoot")
.resolves(sourceRoot);
// No pr-diff-range.json file exists - should work the same as before
const changesFilePath = await writeOverlayChangesFile(
config,
sourceRoot,
logger,
);
getFileOidsStubForOverlay.restore();
getTempDirStub.restore();
getDiffRangesStub.restore();
getGitRootStub.restore();
const fileContent = await fs.promises.readFile(changesFilePath, "utf-8");
const parsedContent = JSON.parse(fileContent) as { changes: string[] };
t.deepEqual(
parsedContent.changes.sort(),
["modified.js"],
"Should only include OID-changed files when no additional files provided",
);
});
},
);
test.serial(
"writeOverlayChangesFile converts diff range paths to sourceRoot-relative when sourceRoot is a subdirectory",
async (t) => {
await withTmpDir(async (tmpDir) => {
// Simulate: repo root = tmpDir, sourceRoot = tmpDir/src
const repoRoot = tmpDir;
const sourceRoot = path.join(tmpDir, "src");
const [dbLocation, tempDir] = ["db", "temp"].map((d) =>
path.join(tmpDir, d),
);
await Promise.all(
[dbLocation, sourceRoot, tempDir].map((d) =>
fs.promises.mkdir(d, { recursive: true }),
),
);
const logger = getRunnerLogger(true);
const config = createTestConfig({ dbLocation });
// Base OIDs (sourceRoot-relative paths)
const baseOids = {
"app.js": "aaa111",
"lib/util.js": "bbb222",
};
const getFileOidsStubForBase = sinon
.stub(gitUtils, "getFileOidsUnderPath")
.resolves(baseOids);
await writeBaseDatabaseOidsFile(config, sourceRoot);
getFileOidsStubForBase.restore();
// Current OIDs — same as base (no OID changes)
const currentOids = {
"app.js": "aaa111",
"lib/util.js": "bbb222",
};
const getFileOidsStubForOverlay = sinon
.stub(gitUtils, "getFileOidsUnderPath")
.resolves(currentOids);
const diffRangeFilePath = path.join(tempDir, "pr-diff-range.json");
const getTempDirStub = sinon
.stub(actionsUtil, "getTemporaryDirectory")
.returns(tempDir);
const getDiffRangesStub = sinon
.stub(actionsUtil, "getDiffRangesJsonFilePath")
.returns(diffRangeFilePath);
// getGitRoot returns the repo root (parent of sourceRoot)
const getGitRootStub = sinon
.stub(gitUtils, "getGitRoot")
.resolves(repoRoot);
// Diff ranges use repo-root-relative paths (as returned by the GitHub compare API)
await fs.promises.writeFile(
diffRangeFilePath,
JSON.stringify([
{ path: "src/app.js", startLine: 1, endLine: 10 },
{ path: "src/lib/util.js", startLine: 5, endLine: 8 },
{ path: "other/outside.js", startLine: 1, endLine: 3 }, // not under sourceRoot
]),
);
const changesFilePath = await writeOverlayChangesFile(
config,
sourceRoot,
logger,
);
getFileOidsStubForOverlay.restore();
getTempDirStub.restore();
getDiffRangesStub.restore();
getGitRootStub.restore();
const fileContent = await fs.promises.readFile(changesFilePath, "utf-8");
const parsedContent = JSON.parse(fileContent) as { changes: string[] };
t.deepEqual(
parsedContent.changes.sort(),
["app.js", "lib/util.js"],
"Should convert repo-root-relative paths to sourceRoot-relative and filter out files outside sourceRoot",
);
});
},
);
interface DownloadOverlayBaseDatabaseTestCase { interface DownloadOverlayBaseDatabaseTestCase {
overlayDatabaseMode: OverlayDatabaseMode; overlayDatabaseMode: OverlayDatabaseMode;
useOverlayDatabaseCaching: boolean; useOverlayDatabaseCaching: boolean;
+74 -3
View File
@@ -3,7 +3,9 @@ import * as path from "path";
import * as actionsCache from "@actions/cache"; import * as actionsCache from "@actions/cache";
import * as actionsUtil from "../actions-util";
import { import {
getOptionalInput,
getRequiredInput, getRequiredInput,
getTemporaryDirectory, getTemporaryDirectory,
getWorkflowRunAttempt, getWorkflowRunAttempt,
@@ -13,7 +15,7 @@ import { getAutomationID } from "../api-client";
import { createCacheKeyHash } from "../caching-utils"; import { createCacheKeyHash } from "../caching-utils";
import { type CodeQL } from "../codeql"; import { type CodeQL } from "../codeql";
import { type Config } from "../config-utils"; import { type Config } from "../config-utils";
import { getCommitOid, getFileOidsUnderPath } from "../git-utils"; import { getCommitOid, getFileOidsUnderPath, getGitRoot } from "../git-utils";
import { Logger, withGroupAsync } from "../logging"; import { Logger, withGroupAsync } from "../logging";
import { import {
CleanupLevel, CleanupLevel,
@@ -130,11 +132,17 @@ export async function writeOverlayChangesFile(
): Promise<string> { ): Promise<string> {
const baseFileOids = await readBaseDatabaseOidsFile(config, logger); const baseFileOids = await readBaseDatabaseOidsFile(config, logger);
const overlayFileOids = await getFileOidsUnderPath(sourceRoot); const overlayFileOids = await getFileOidsUnderPath(sourceRoot);
const changedFiles = computeChangedFiles(baseFileOids, overlayFileOids); const oidChangedFiles = computeChangedFiles(baseFileOids, overlayFileOids);
logger.info( logger.info(
`Found ${changedFiles.length} changed file(s) under ${sourceRoot}.`, `Found ${oidChangedFiles.length} changed file(s) under ${sourceRoot} from OID comparison.`,
); );
// Merge in any file paths from precomputed PR diff ranges to ensure the
// overlay always includes all files from the PR diff, even in edge cases
// like revert PRs where OID comparison shows no change.
const diffRangeFiles = await getDiffRangeFilePaths(sourceRoot, logger);
const changedFiles = [...new Set([...oidChangedFiles, ...diffRangeFiles])];
const changedFilesJson = JSON.stringify({ changes: changedFiles }); const changedFilesJson = JSON.stringify({ changes: changedFiles });
const overlayChangesFile = path.join( const overlayChangesFile = path.join(
getTemporaryDirectory(), getTemporaryDirectory(),
@@ -165,6 +173,69 @@ function computeChangedFiles(
return changes; return changes;
} }
async function getDiffRangeFilePaths(
sourceRoot: string,
logger: Logger,
): Promise<string[]> {
const jsonFilePath = actionsUtil.getDiffRangesJsonFilePath();
if (!fs.existsSync(jsonFilePath)) {
logger.debug(
`No diff ranges JSON file found at ${jsonFilePath}; skipping.`,
);
return [];
}
let contents: string;
try {
contents = await fs.promises.readFile(jsonFilePath, "utf8");
} catch (e) {
logger.warning(
`Failed to read diff ranges JSON file at ${jsonFilePath}: ${e}`,
);
return [];
}
let diffRanges: Array<{ path: string }>;
try {
diffRanges = JSON.parse(contents) as Array<{ path: string }>;
} catch (e) {
logger.warning(
`Failed to parse diff ranges JSON file at ${jsonFilePath}: ${e}`,
);
return [];
}
logger.debug(
`Read ${diffRanges.length} diff range(s) from ${jsonFilePath} for overlay changes.`,
);
// Diff-range paths are relative to the repo root (from the GitHub compare
// API), but overlay changed files must be relative to sourceRoot (to match
// getFileOidsUnderPath output). Convert and filter accordingly.
const repoRoot = await getGitRoot(sourceRoot);
if (repoRoot === undefined) {
if (getOptionalInput("source-root")) {
throw new Error(
"Cannot determine git root to convert diff range paths relative to source-root. " +
"Failing to avoid omitting files from the analysis.",
);
}
logger.warning(
"Cannot determine git root; returning diff range paths as-is.",
);
return [...new Set(diffRanges.map((r) => r.path))];
}
const relativePaths = diffRanges
.map((r) =>
path
.relative(sourceRoot, path.join(repoRoot, r.path))
.replaceAll(path.sep, "/"),
)
.filter((rel) => !rel.startsWith(".."));
return [...new Set(relativePaths)];
}
// Constants for database caching // Constants for database caching
const CACHE_VERSION = 1; const CACHE_VERSION = 1;
const CACHE_PREFIX = "codeql-overlay-base-database"; const CACHE_PREFIX = "codeql-overlay-base-database";
+141 -27
View File
@@ -14,9 +14,9 @@ import * as startProxyExports from "./start-proxy";
import { parseLanguage } from "./start-proxy"; import { parseLanguage } from "./start-proxy";
import * as statusReport from "./status-report"; import * as statusReport from "./status-report";
import { import {
assertNotLogged,
checkExpectedLogMessages, checkExpectedLogMessages,
createFeatures, createFeatures,
getRecordingLogger,
makeTestToken, makeTestToken,
RecordingLogger, RecordingLogger,
setupTests, setupTests,
@@ -439,41 +439,155 @@ test("getCredentials accepts OIDC configurations", (t) => {
t.assert(credentials.some((c) => startProxyExports.isJFrogConfig(c))); t.assert(credentials.some((c) => startProxyExports.isJFrogConfig(c)));
}); });
test("getCredentials logs a warning when a PAT is used without a username", async (t) => { const getCredentialsMacro = test.macro({
const loggedMessages = []; exec: async (
const logger = getRecordingLogger(loggedMessages); t: ExecutionContext<unknown>,
const likelyWrongCredentials = toEncodedJSON([ credentials: startProxyExports.RawCredential[],
checkAccepted: (
t: ExecutionContext<unknown>,
logger: RecordingLogger,
results: startProxyExports.Credential[],
) => void,
) => {
const logger = new RecordingLogger();
const credentialsString = toEncodedJSON(credentials);
const results = startProxyExports.getCredentials(
logger,
undefined,
credentialsString,
undefined,
);
checkAccepted(t, logger, results);
},
title: (providedTitle = "") => `getCredentials - ${providedTitle}`,
});
test(
"warns for PAT-like password without a username",
getCredentialsMacro,
[
{ {
type: "git_server", type: "git_server",
host: "https://github.com/", host: "https://github.com/",
password: `ghp_${makeTestToken()}`, password: `ghp_${makeTestToken()}`,
}, },
]); ],
(t, logger, results) => {
// The configurations should be accepted, despite the likely problem.
t.assert(results);
t.is(results.length, 1);
t.is(results[0].type, "git_server");
t.is(results[0].host, "https://github.com/");
const results = startProxyExports.getCredentials( if (startProxyExports.isUsernamePassword(results[0])) {
logger, t.assert(results[0].password?.startsWith("ghp_"));
undefined, } else {
likelyWrongCredentials, t.fail("Expected a `UsernamePassword`-based credential.");
undefined, }
);
// The configuration should be accepted, despite the likely problem. // A warning should have been logged.
t.assert(results); checkExpectedLogMessages(t, logger.messages, [
t.is(results.length, 1); "using a GitHub Personal Access Token (PAT), but no username was provided",
t.is(results[0].type, "git_server"); ]);
t.is(results[0].host, "https://github.com/"); },
);
if (startProxyExports.isUsernamePassword(results[0])) { test(
t.assert(results[0].password?.startsWith("ghp_")); "no warning for PAT-like password with a username",
} else { getCredentialsMacro,
t.fail("Expected a `UsernamePassword`-based credential."); [
} {
type: "git_server",
host: "https://github.com/",
username: "someone",
password: `ghp_${makeTestToken()}`,
},
],
(t, logger, results) => {
// The configurations should be accepted, despite the likely problem.
t.assert(results);
t.is(results.length, 1);
t.is(results[0].type, "git_server");
t.is(results[0].host, "https://github.com/");
// A warning should have been logged. if (startProxyExports.isUsernamePassword(results[0])) {
checkExpectedLogMessages(t, loggedMessages, [ t.assert(results[0].password?.startsWith("ghp_"));
"using a GitHub Personal Access Token (PAT), but no username was provided", } else {
]); t.fail("Expected a `UsernamePassword`-based credential.");
}); }
assertNotLogged(
t,
logger,
"using a GitHub Personal Access Token (PAT), but no username was provided",
);
},
);
test(
"warns for PAT-like token without a username",
getCredentialsMacro,
[
{
type: "git_server",
host: "https://github.com/",
token: `ghp_${makeTestToken()}`,
},
],
(t, logger, results) => {
// The configurations should be accepted, despite the likely problem.
t.assert(results);
t.is(results.length, 1);
t.is(results[0].type, "git_server");
t.is(results[0].host, "https://github.com/");
if (startProxyExports.isToken(results[0])) {
t.assert(results[0].token?.startsWith("ghp_"));
} else {
t.fail("Expected a `Token`-based credential.");
}
// A warning should have been logged.
checkExpectedLogMessages(t, logger.messages, [
"using a GitHub Personal Access Token (PAT), but no username was provided",
]);
},
);
test(
"no warning for PAT-like token with a username",
getCredentialsMacro,
[
{
type: "git_server",
host: "https://github.com/",
username: "someone",
token: `ghp_${makeTestToken()}`,
},
],
(t, logger, results) => {
// The configurations should be accepted, despite the likely problem.
t.assert(results);
t.is(results.length, 1);
t.is(results[0].type, "git_server");
t.is(results[0].host, "https://github.com/");
if (startProxyExports.isToken(results[0])) {
t.assert(results[0].token?.startsWith("ghp_"));
} else {
t.fail("Expected a `Token`-based credential.");
}
assertNotLogged(
t,
logger,
"using a GitHub Personal Access Token (PAT), but no username was provided",
);
},
);
test("getCredentials returns all credentials for Actions when using LANGUAGE_TO_REGISTRY_TYPE", async (t) => { test("getCredentials returns all credentials for Actions when using LANGUAGE_TO_REGISTRY_TYPE", async (t) => {
const credentialsInput = toEncodedJSON(mixedCredentials); const credentialsInput = toEncodedJSON(mixedCredentials);
+12 -9
View File
@@ -447,15 +447,18 @@ export function getCredentials(
} }
// If the password or token looks like a GitHub PAT, warn if no username is configured. // If the password or token looks like a GitHub PAT, warn if no username is configured.
if ( const noUsername =
((!hasUsername(authConfig) || !isDefined(authConfig.username)) && !hasUsername(authConfig) || !isDefined(authConfig.username);
isUsernamePassword(authConfig) && const passwordIsPAT =
isDefined(authConfig.password) && isUsernamePassword(authConfig) &&
isPAT(authConfig.password)) || isDefined(authConfig.password) &&
(isToken(authConfig) && isPAT(authConfig.password);
isDefined(authConfig.token) && const tokenIsPAT =
isPAT(authConfig.token)) isToken(authConfig) &&
) { isDefined(authConfig.token) &&
isPAT(authConfig.token);
if (noUsername && (passwordIsPAT || tokenIsPAT)) {
logger.warning( logger.warning(
`A ${e.type} private registry is configured for ${e.host || e.url} using a GitHub Personal Access Token (PAT), but no username was provided. ` + `A ${e.type} private registry is configured for ${e.host || e.url} using a GitHub Personal Access Token (PAT), but no username was provided. ` +
`This may not work correctly. When configuring a private registry using a PAT, select "Username and password" and enter the username of the user ` + `This may not work correctly. When configuring a private registry using a PAT, select "Username and password" and enter the username of the user ` +
+59 -42
View File
@@ -185,8 +185,8 @@ export interface LoggedMessage {
export class RecordingLogger implements Logger { export class RecordingLogger implements Logger {
messages: LoggedMessage[] = []; messages: LoggedMessage[] = [];
groups: string[] = []; readonly groups: string[] = [];
unfinishedGroups: Set<string> = new Set(); readonly unfinishedGroups: Set<string> = new Set();
private currentGroup: string | undefined = undefined; private currentGroup: string | undefined = undefined;
constructor(private readonly logToConsole: boolean = true) {} constructor(private readonly logToConsole: boolean = true) {}
@@ -200,6 +200,19 @@ export class RecordingLogger implements Logger {
} }
} }
/**
* Checks whether the logged messages contain `messageOrRegExp`.
*
* If `messageOrRegExp` is a string, this function returns true as long as
* `messageOrRegExp` appears as part of one of the `messages`.
*
* If `messageOrRegExp` is a regular expression, this function returns true as long as
* one of the `messages` matches `messageOrRegExp`.
*/
hasMessage(messageOrRegExp: string | RegExp): boolean {
return hasLoggedMessage(this.messages, messageOrRegExp);
}
isDebug() { isDebug() {
return true; return true;
} }
@@ -238,41 +251,37 @@ export function getRecordingLogger(
messages: LoggedMessage[], messages: LoggedMessage[],
{ logToConsole }: { logToConsole?: boolean } = { logToConsole: true }, { logToConsole }: { logToConsole?: boolean } = { logToConsole: true },
): Logger { ): Logger {
return { const logger = new RecordingLogger(logToConsole);
debug: (message: string) => { logger.messages = messages;
messages.push({ type: "debug", message }); return logger;
if (logToConsole) {
// eslint-disable-next-line no-console
console.debug(message);
}
},
info: (message: string) => {
messages.push({ type: "info", message });
if (logToConsole) {
// eslint-disable-next-line no-console
console.info(message);
}
},
warning: (message: string | Error) => {
messages.push({ type: "warning", message });
if (logToConsole) {
// eslint-disable-next-line no-console
console.warn(message);
}
},
error: (message: string | Error) => {
messages.push({ type: "error", message });
if (logToConsole) {
// eslint-disable-next-line no-console
console.error(message);
}
},
isDebug: () => true,
startGroup: () => undefined,
endGroup: () => undefined,
};
} }
/**
* Checks whether `messages` contains `messageOrRegExp`.
*
* If `messageOrRegExp` is a string, this function returns true as long as
* `messageOrRegExp` appears as part of one of the `messages`.
*
* If `messageOrRegExp` is a regular expression, this function returns true as long as
* one of the `messages` matches `messageOrRegExp`.
*/
function hasLoggedMessage(
messages: LoggedMessage[],
messageOrRegExp: string | RegExp,
): boolean {
const check = (val: string) =>
typeof messageOrRegExp === "string"
? val.includes(messageOrRegExp)
: messageOrRegExp.test(val);
return messages.some(
(msg) => typeof msg.message === "string" && check(msg.message),
);
}
/**
* Checks that `messages` contains all of `expectedMessages`.
*/
export function checkExpectedLogMessages( export function checkExpectedLogMessages(
t: ExecutionContext<any>, t: ExecutionContext<any>,
messages: LoggedMessage[], messages: LoggedMessage[],
@@ -281,13 +290,7 @@ export function checkExpectedLogMessages(
const missingMessages: string[] = []; const missingMessages: string[] = [];
for (const expectedMessage of expectedMessages) { for (const expectedMessage of expectedMessages) {
if ( if (!hasLoggedMessage(messages, expectedMessage)) {
!messages.some(
(msg) =>
typeof msg.message === "string" &&
msg.message.includes(expectedMessage),
)
) {
missingMessages.push(expectedMessage); missingMessages.push(expectedMessage);
} }
} }
@@ -304,6 +307,20 @@ export function checkExpectedLogMessages(
} }
} }
/**
* Asserts that `message` should not have been logged to `logger`.
*/
export function assertNotLogged(
t: ExecutionContext<any>,
logger: RecordingLogger,
message: string | RegExp,
) {
t.false(
logger.hasMessage(message),
`'${message}' should not have been logged, but was.`,
);
}
/** /**
* Initialises a recording logger and calls `body` with it. * Initialises a recording logger and calls `body` with it.
* *