[pull] main from actions:main - #7

Open
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main
Open

[pull] main from actions:main#7
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main

Conversation

@pull

@pullpullBot commented Oct 15, 2024

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot]

Can you help keep this open source service alive? 💖 Please sponsor : )

@sourcery-ai

sourcery-aiBot commented Oct 15, 2024

Copy link
Copy Markdown

Reviewer's Guide by Sourcery

This pull request includes several significant changes across multiple packages in the actions/toolkit repository. The changes primarily focus on updating dependencies, improving error handling, enhancing security, and refactoring code for better performance and maintainability. Key updates include modifications to the artifact upload process, changes to OIDC token handling, improvements to the HTTP client, and updates to the glob and attest packages.

Class diagram for OIDC Token Handling

classDiagram
class OIDCConfig {
string issuer
string jwks_uri
}
class ClaimSet {
string iss
string ref
string sha
string repository
string event_name
string job_workflow_ref
string workflow_ref
string repository_id
string repository_owner_id
}
class OIDC {
+getIDTokenClaims(issuer: string): Promise<ClaimSet>
+decodeOIDCToken(token: string, issuer: string): Promise<JWTPayload>
+getJWKS(issuer: string): Promise<JSONWebKeySet>
+getIssuer(): string
}
OIDC --> OIDCConfig
OIDC --> ClaimSet
Loading

Class diagram for HTTP Client Proxy Handling

classDiagram
class DecodedURL {
string username
string password
string href
}
class HttpClient {
+getProxyUrl(reqUrl: URL): URL | undefined
+getAgent(url: string): any
}
HttpClient --> DecodedURL
Loading

File-Level Changes

ChangeDetailsFiles
Refactored artifact upload process
  • Updated chunk timeout logic
  • Implemented lazy stream to prevent issues with open file limits
  • Fixed a regression with symlinks not being automatically resolved
  • Improved error handling for upload progress stalling
packages/artifact/__tests__/upload-artifact.test.ts
packages/artifact/src/internal/upload/blob-upload.ts
packages/artifact/src/internal/upload/upload-zip-specification.ts
packages/artifact/src/internal/upload/zip.ts
Enhanced OIDC token handling and attestation process
  • Updated OIDC token claim validation
  • Improved handling of enterprise-specific OIDC issuers
  • Added support for custom HTTP headers in attestation requests
  • Updated SLSA provenance predicate generation
packages/attest/src/oidc.ts
packages/attest/src/provenance.ts
packages/attest/src/attest.ts
packages/attest/src/store.ts
Improved HTTP client functionality
  • Fixed handling of proxy usernames and passwords
  • Updated URL decoding for proxy authentication
  • Improved error handling for network requests
packages/http-client/src/index.ts
packages/http-client/src/proxy.ts
Updated glob package with new features
  • Added option to exclude hidden files in glob searches
  • Improved handling of symlinks in glob results
packages/glob/src/internal-glob-options.ts
packages/glob/src/internal-globber.ts
General dependency updates and security improvements
  • Updated various dependencies across packages
  • Replaced uuid package with native crypto.randomUUID()
  • Improved error messages and debugging information
packages/artifact/RELEASES.md
packages/attest/RELEASES.md
packages/core/RELEASES.md
packages/glob/RELEASES.md
packages/http-client/RELEASES.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time. You can also use
    this command to specify where the summary should be inserted.

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have skipped reviewing this pull request. It seems to have been created by a bot (hey, pull[bot]!). We assume it knows what it's doing!

tingx2wangand others added 27 commits December 5, 2025 17:13
…s/attest/tar-7.5.2
Bump tar from 7.5.1 to 7.5.2 in /packages/attest
- Update spawn-wait-for-file.js to use proper stdio inheritance
- Add small delay before exit to ensure child process inherits handles
- Simplify test code to use the helper script instead of shell commands
On Windows, detached:true is needed to properly keep stdio handles
open after the parent process exits.
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
chore: fix npm audit vulnerabilities (glob, js-yaml)
Samiratand others added 30 commits May 1, 2026 17:38
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.0.1 to 10.2.0.
- [Commits](https://github.com/beaugunderson/ip-address/commits)
---
updated-dependencies:
- dependency-name: ip-address
dependency-version: 10.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…_versions
Update minor versions of cache and artifact dependencies
Bumps [fast-xml-builder](https://github.com/NaturalIntelligence/fast-xml-builder) from 1.1.5 to 1.2.0.
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-builder/blob/main/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-builder@v1.1.5...v1.2.0)
---
updated-dependencies:
- dependency-name: fast-xml-builder
dependency-version: 1.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/attest/ip-address-10.2.0
chore(deps): bump ip-address from 10.0.1 to 10.2.0 in /packages/attest
…s/attest/brace-expansion-2.0.3
chore(deps): bump brace-expansion from 2.0.2 to 2.0.3 in /packages/attest
Bumps [markdown-it](https://github.com/markdown-it/markdown-it) from 14.1.1 to 14.2.0.
- [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@14.1.1...14.2.0)
---
updated-dependencies:
- dependency-name: markdown-it
dependency-version: 14.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…TIONS_CACHE_MODE skip) (#2447)
* feat(cache): surface cache read-denied as a distinct restore warning
Mirror the existing cache write-denied handling on the restore path. When
the receiver refuses a download URL because the run's token has no readable
cache scopes, it returns a twirp PermissionDenied (HTTP 403). The twirp
client wraps that 403 in a generic Error, so the stable 'cache read denied:'
prefix is embedded in the message rather than at the start.
- Add CACHE_READ_DENIED_PREFIX and CacheReadDeniedError
- Dispatch on the prefix in the restoreCacheV2 catch block (V2 only), log a
policy-specific warning, and report a cache miss so the run continues
- Add a test mirroring the write-denied coverage
* chore(cache): trim comments, bump to 6.2.0, add RELEASES entry
* refactor(cache): dispatch read-denied by error name to mirror write path
Re-throw CacheReadDeniedError from an inner try/catch around
GetCacheEntryDownloadURL and dispatch on typedError.name in the outer catch,
matching how saveCacheV2 handles CacheWriteDeniedError.
* feat(cache): handle read-denied on the v1 restore path
Extend the read-denied handling to Cache Service v1 so GHES (which forces v1
via _apis/artifactcache) is covered when read-scope enforcement ships there.
- Surface the receiver's error body message from getCacheEntry instead of a
generic status-code error, so the cache read denied: prefix reaches callers
- Re-throw CacheReadDeniedError from restoreCacheV1 and dispatch on it in the
outer catch, mirroring restoreCacheV2 and the write-denied v1 handling
- Add a v1 read-denied test
* refactor(cache): only surface receiver body for read-denied on v1
* test(cache): assert getCacheEntry only surfaces body for read-denied
* test(cache): cover non-read-denied getCacheEntry passthrough on v1
* refactor(cache): share read-denied prefix via constants to avoid drift
* feat(cache): skip restore/save per ACTIONS_CACHE_MODE
* test(cache): expand ACTIONS_CACHE_MODE skip coverage across v1/v2 and unknown modes
* fix copilot pr feedback
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* docs(cache): remove internal reference from cache-mode comment
* test(cache): merge redundant cache-mode skip tests and simplify read-denied handling
Address PR review feedback:
- Merge the duplicate restore/save skip test.each blocks into single blocks parametrized over ACTIONS_CACHE_SERVICE_V2.
- Drop the redundant CacheReadDeniedError catch arms; the typed error is not an HttpClientError so it already falls through to a non-fatal warning.
- Clarify why read-denied classification happens both in getCacheEntry and cache.ts (dependency-free internal module cannot import the typed error).
* refactor(cache): drop redundant CacheWriteDeniedError catch arms
Mirror the read-denied simplification on the save path. CacheWriteDeniedError
is not an HttpClientError and its name does not match the ReserveCacheError
arm, so it falls through to the same non-fatal warning. Logging behavior is
unchanged (warns, never fails the run) and the exported type is still thrown
internally for consumers and tests. Also refresh stale doc wording.
* test(cache): collapse redundant restore getCacheEntry-failure tests
The two restoreCache tests exercised the identical warning + cache-miss path
now that read-denied is no longer reclassified in the catch, so merge them into
one. The read-denied prefix detection that actually branches on the message is
covered by getCacheEntry tests in cacheHttpClient.test.ts.
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* @actions/glob: extend hashFiles options
* improve hashFiles symlink handling
* Improve error handling and messaging in hashFiles function
* apply relative exclude patterns across all roots and use named minimatch import
* format error message
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.6 to 5.0.7.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.6...v5.0.7)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 5.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.10 to 7.5.22.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v7.5.10...v7.5.22)
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.22
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/glob/brace-expansion-5.0.7
chore(deps): bump brace-expansion from 5.0.6 to 5.0.7 in /packages/glob
…s/github/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/github
…s/artifact/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/artifact
…s/artifact/markdown-it-14.2.0
chore(deps): bump markdown-it from 14.1.1 to 14.2.0 in /packages/artifact
Bumps [linkify-it](https://github.com/markdown-it/linkify-it) from 5.0.1 to 5.0.2.
- [Changelog](https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/linkify-it@5.0.1...5.0.2)
---
updated-dependencies:
- dependency-name: linkify-it
dependency-version: 5.0.2
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/artifact/fast-xml-builder-1.2.0
chore(deps): bump fast-xml-builder from 1.1.5 to 1.2.0 in /packages/artifact
…s/attest/tar-7.5.22
chore(deps): bump tar from 7.5.10 to 7.5.22 in /packages/attest
…s/artifact/linkify-it-5.0.2
chore(deps): bump linkify-it from 5.0.1 to 5.0.2 in /packages/artifact
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 2.1.0 to 2.1.4.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v2.1.0...v2.1.4)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 2.1.4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
#2463)
Bumps [undici](https://github.com/nodejs/undici) from 6.23.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.23.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…2330)
Bumps [minimatch](https://github.com/isaacs/minimatch) from 9.0.5 to 9.0.9.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v9.0.5...v9.0.9)
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 9.0.9
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@dwisiswant0@Anytar888@joe345-str@tteo38472@tingx2wang@salmanmkc@malancas@bdehamer@TingluoHuang@GhadimiR@lokesh755@danwkennedy@zaataylor@Link-@shogo82148@aiqiaoy@Samirat@jasongin@philip-gai
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[pull] main from actions:main - #7

Open
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main
Open

[pull] main from actions:main#7
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main

Conversation

@pull

@pullpullBot commented Oct 15, 2024

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot]

Can you help keep this open source service alive? 💖 Please sponsor : )

@sourcery-ai

sourcery-aiBot commented Oct 15, 2024

Copy link
Copy Markdown

Reviewer's Guide by Sourcery

This pull request includes several significant changes across multiple packages in the actions/toolkit repository. The changes primarily focus on updating dependencies, improving error handling, enhancing security, and refactoring code for better performance and maintainability. Key updates include modifications to the artifact upload process, changes to OIDC token handling, improvements to the HTTP client, and updates to the glob and attest packages.

Class diagram for OIDC Token Handling

classDiagram
class OIDCConfig {
string issuer
string jwks_uri
}
class ClaimSet {
string iss
string ref
string sha
string repository
string event_name
string job_workflow_ref
string workflow_ref
string repository_id
string repository_owner_id
}
class OIDC {
+getIDTokenClaims(issuer: string): Promise<ClaimSet>
+decodeOIDCToken(token: string, issuer: string): Promise<JWTPayload>
+getJWKS(issuer: string): Promise<JSONWebKeySet>
+getIssuer(): string
}
OIDC --> OIDCConfig
OIDC --> ClaimSet
Loading

Class diagram for HTTP Client Proxy Handling

classDiagram
class DecodedURL {
string username
string password
string href
}
class HttpClient {
+getProxyUrl(reqUrl: URL): URL | undefined
+getAgent(url: string): any
}
HttpClient --> DecodedURL
Loading

File-Level Changes

ChangeDetailsFiles
Refactored artifact upload process
  • Updated chunk timeout logic
  • Implemented lazy stream to prevent issues with open file limits
  • Fixed a regression with symlinks not being automatically resolved
  • Improved error handling for upload progress stalling
packages/artifact/__tests__/upload-artifact.test.ts
packages/artifact/src/internal/upload/blob-upload.ts
packages/artifact/src/internal/upload/upload-zip-specification.ts
packages/artifact/src/internal/upload/zip.ts
Enhanced OIDC token handling and attestation process
  • Updated OIDC token claim validation
  • Improved handling of enterprise-specific OIDC issuers
  • Added support for custom HTTP headers in attestation requests
  • Updated SLSA provenance predicate generation
packages/attest/src/oidc.ts
packages/attest/src/provenance.ts
packages/attest/src/attest.ts
packages/attest/src/store.ts
Improved HTTP client functionality
  • Fixed handling of proxy usernames and passwords
  • Updated URL decoding for proxy authentication
  • Improved error handling for network requests
packages/http-client/src/index.ts
packages/http-client/src/proxy.ts
Updated glob package with new features
  • Added option to exclude hidden files in glob searches
  • Improved handling of symlinks in glob results
packages/glob/src/internal-glob-options.ts
packages/glob/src/internal-globber.ts
General dependency updates and security improvements
  • Updated various dependencies across packages
  • Replaced uuid package with native crypto.randomUUID()
  • Improved error messages and debugging information
packages/artifact/RELEASES.md
packages/attest/RELEASES.md
packages/core/RELEASES.md
packages/glob/RELEASES.md
packages/http-client/RELEASES.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time. You can also use
    this command to specify where the summary should be inserted.

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have skipped reviewing this pull request. It seems to have been created by a bot (hey, pull[bot]!). We assume it knows what it's doing!

tingx2wangand others added 27 commits December 5, 2025 17:13
…s/attest/tar-7.5.2
Bump tar from 7.5.1 to 7.5.2 in /packages/attest
- Update spawn-wait-for-file.js to use proper stdio inheritance
- Add small delay before exit to ensure child process inherits handles
- Simplify test code to use the helper script instead of shell commands
On Windows, detached:true is needed to properly keep stdio handles
open after the parent process exits.
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
chore: fix npm audit vulnerabilities (glob, js-yaml)
Samiratand others added 30 commits May 1, 2026 17:38
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.0.1 to 10.2.0.
- [Commits](https://github.com/beaugunderson/ip-address/commits)
---
updated-dependencies:
- dependency-name: ip-address
dependency-version: 10.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…_versions
Update minor versions of cache and artifact dependencies
Bumps [fast-xml-builder](https://github.com/NaturalIntelligence/fast-xml-builder) from 1.1.5 to 1.2.0.
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-builder/blob/main/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-builder@v1.1.5...v1.2.0)
---
updated-dependencies:
- dependency-name: fast-xml-builder
dependency-version: 1.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/attest/ip-address-10.2.0
chore(deps): bump ip-address from 10.0.1 to 10.2.0 in /packages/attest
…s/attest/brace-expansion-2.0.3
chore(deps): bump brace-expansion from 2.0.2 to 2.0.3 in /packages/attest
Bumps [markdown-it](https://github.com/markdown-it/markdown-it) from 14.1.1 to 14.2.0.
- [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@14.1.1...14.2.0)
---
updated-dependencies:
- dependency-name: markdown-it
dependency-version: 14.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…TIONS_CACHE_MODE skip) (#2447)
* feat(cache): surface cache read-denied as a distinct restore warning
Mirror the existing cache write-denied handling on the restore path. When
the receiver refuses a download URL because the run's token has no readable
cache scopes, it returns a twirp PermissionDenied (HTTP 403). The twirp
client wraps that 403 in a generic Error, so the stable 'cache read denied:'
prefix is embedded in the message rather than at the start.
- Add CACHE_READ_DENIED_PREFIX and CacheReadDeniedError
- Dispatch on the prefix in the restoreCacheV2 catch block (V2 only), log a
policy-specific warning, and report a cache miss so the run continues
- Add a test mirroring the write-denied coverage
* chore(cache): trim comments, bump to 6.2.0, add RELEASES entry
* refactor(cache): dispatch read-denied by error name to mirror write path
Re-throw CacheReadDeniedError from an inner try/catch around
GetCacheEntryDownloadURL and dispatch on typedError.name in the outer catch,
matching how saveCacheV2 handles CacheWriteDeniedError.
* feat(cache): handle read-denied on the v1 restore path
Extend the read-denied handling to Cache Service v1 so GHES (which forces v1
via _apis/artifactcache) is covered when read-scope enforcement ships there.
- Surface the receiver's error body message from getCacheEntry instead of a
generic status-code error, so the cache read denied: prefix reaches callers
- Re-throw CacheReadDeniedError from restoreCacheV1 and dispatch on it in the
outer catch, mirroring restoreCacheV2 and the write-denied v1 handling
- Add a v1 read-denied test
* refactor(cache): only surface receiver body for read-denied on v1
* test(cache): assert getCacheEntry only surfaces body for read-denied
* test(cache): cover non-read-denied getCacheEntry passthrough on v1
* refactor(cache): share read-denied prefix via constants to avoid drift
* feat(cache): skip restore/save per ACTIONS_CACHE_MODE
* test(cache): expand ACTIONS_CACHE_MODE skip coverage across v1/v2 and unknown modes
* fix copilot pr feedback
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* docs(cache): remove internal reference from cache-mode comment
* test(cache): merge redundant cache-mode skip tests and simplify read-denied handling
Address PR review feedback:
- Merge the duplicate restore/save skip test.each blocks into single blocks parametrized over ACTIONS_CACHE_SERVICE_V2.
- Drop the redundant CacheReadDeniedError catch arms; the typed error is not an HttpClientError so it already falls through to a non-fatal warning.
- Clarify why read-denied classification happens both in getCacheEntry and cache.ts (dependency-free internal module cannot import the typed error).
* refactor(cache): drop redundant CacheWriteDeniedError catch arms
Mirror the read-denied simplification on the save path. CacheWriteDeniedError
is not an HttpClientError and its name does not match the ReserveCacheError
arm, so it falls through to the same non-fatal warning. Logging behavior is
unchanged (warns, never fails the run) and the exported type is still thrown
internally for consumers and tests. Also refresh stale doc wording.
* test(cache): collapse redundant restore getCacheEntry-failure tests
The two restoreCache tests exercised the identical warning + cache-miss path
now that read-denied is no longer reclassified in the catch, so merge them into
one. The read-denied prefix detection that actually branches on the message is
covered by getCacheEntry tests in cacheHttpClient.test.ts.
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* @actions/glob: extend hashFiles options
* improve hashFiles symlink handling
* Improve error handling and messaging in hashFiles function
* apply relative exclude patterns across all roots and use named minimatch import
* format error message
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.6 to 5.0.7.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.6...v5.0.7)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 5.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.10 to 7.5.22.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v7.5.10...v7.5.22)
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.22
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/glob/brace-expansion-5.0.7
chore(deps): bump brace-expansion from 5.0.6 to 5.0.7 in /packages/glob
…s/github/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/github
…s/artifact/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/artifact
…s/artifact/markdown-it-14.2.0
chore(deps): bump markdown-it from 14.1.1 to 14.2.0 in /packages/artifact
Bumps [linkify-it](https://github.com/markdown-it/linkify-it) from 5.0.1 to 5.0.2.
- [Changelog](https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/linkify-it@5.0.1...5.0.2)
---
updated-dependencies:
- dependency-name: linkify-it
dependency-version: 5.0.2
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/artifact/fast-xml-builder-1.2.0
chore(deps): bump fast-xml-builder from 1.1.5 to 1.2.0 in /packages/artifact
…s/attest/tar-7.5.22
chore(deps): bump tar from 7.5.10 to 7.5.22 in /packages/attest
…s/artifact/linkify-it-5.0.2
chore(deps): bump linkify-it from 5.0.1 to 5.0.2 in /packages/artifact
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 2.1.0 to 2.1.4.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v2.1.0...v2.1.4)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 2.1.4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
#2463)
Bumps [undici](https://github.com/nodejs/undici) from 6.23.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.23.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…2330)
Bumps [minimatch](https://github.com/isaacs/minimatch) from 9.0.5 to 9.0.9.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v9.0.5...v9.0.9)
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 9.0.9
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@dwisiswant0@Anytar888@joe345-str@tteo38472@tingx2wang@salmanmkc@malancas@bdehamer@TingluoHuang@GhadimiR@lokesh755@danwkennedy@zaataylor@Link-@shogo82148@aiqiaoy@Samirat@jasongin@philip-gai
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[pull] main from actions:main - #7

Open
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main
Open

[pull] main from actions:main#7
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main

Conversation

@pull

@pullpullBot commented Oct 15, 2024

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot]

Can you help keep this open source service alive? 💖 Please sponsor : )

@sourcery-ai

sourcery-aiBot commented Oct 15, 2024

Copy link
Copy Markdown

Reviewer's Guide by Sourcery

This pull request includes several significant changes across multiple packages in the actions/toolkit repository. The changes primarily focus on updating dependencies, improving error handling, enhancing security, and refactoring code for better performance and maintainability. Key updates include modifications to the artifact upload process, changes to OIDC token handling, improvements to the HTTP client, and updates to the glob and attest packages.

Class diagram for OIDC Token Handling

classDiagram
class OIDCConfig {
string issuer
string jwks_uri
}
class ClaimSet {
string iss
string ref
string sha
string repository
string event_name
string job_workflow_ref
string workflow_ref
string repository_id
string repository_owner_id
}
class OIDC {
+getIDTokenClaims(issuer: string): Promise<ClaimSet>
+decodeOIDCToken(token: string, issuer: string): Promise<JWTPayload>
+getJWKS(issuer: string): Promise<JSONWebKeySet>
+getIssuer(): string
}
OIDC --> OIDCConfig
OIDC --> ClaimSet
Loading

Class diagram for HTTP Client Proxy Handling

classDiagram
class DecodedURL {
string username
string password
string href
}
class HttpClient {
+getProxyUrl(reqUrl: URL): URL | undefined
+getAgent(url: string): any
}
HttpClient --> DecodedURL
Loading

File-Level Changes

ChangeDetailsFiles
Refactored artifact upload process
  • Updated chunk timeout logic
  • Implemented lazy stream to prevent issues with open file limits
  • Fixed a regression with symlinks not being automatically resolved
  • Improved error handling for upload progress stalling
packages/artifact/__tests__/upload-artifact.test.ts
packages/artifact/src/internal/upload/blob-upload.ts
packages/artifact/src/internal/upload/upload-zip-specification.ts
packages/artifact/src/internal/upload/zip.ts
Enhanced OIDC token handling and attestation process
  • Updated OIDC token claim validation
  • Improved handling of enterprise-specific OIDC issuers
  • Added support for custom HTTP headers in attestation requests
  • Updated SLSA provenance predicate generation
packages/attest/src/oidc.ts
packages/attest/src/provenance.ts
packages/attest/src/attest.ts
packages/attest/src/store.ts
Improved HTTP client functionality
  • Fixed handling of proxy usernames and passwords
  • Updated URL decoding for proxy authentication
  • Improved error handling for network requests
packages/http-client/src/index.ts
packages/http-client/src/proxy.ts
Updated glob package with new features
  • Added option to exclude hidden files in glob searches
  • Improved handling of symlinks in glob results
packages/glob/src/internal-glob-options.ts
packages/glob/src/internal-globber.ts
General dependency updates and security improvements
  • Updated various dependencies across packages
  • Replaced uuid package with native crypto.randomUUID()
  • Improved error messages and debugging information
packages/artifact/RELEASES.md
packages/attest/RELEASES.md
packages/core/RELEASES.md
packages/glob/RELEASES.md
packages/http-client/RELEASES.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time. You can also use
    this command to specify where the summary should be inserted.

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have skipped reviewing this pull request. It seems to have been created by a bot (hey, pull[bot]!). We assume it knows what it's doing!

tingx2wangand others added 27 commits December 5, 2025 17:13
…s/attest/tar-7.5.2
Bump tar from 7.5.1 to 7.5.2 in /packages/attest
- Update spawn-wait-for-file.js to use proper stdio inheritance
- Add small delay before exit to ensure child process inherits handles
- Simplify test code to use the helper script instead of shell commands
On Windows, detached:true is needed to properly keep stdio handles
open after the parent process exits.
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
chore: fix npm audit vulnerabilities (glob, js-yaml)
Samiratand others added 30 commits May 1, 2026 17:38
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.0.1 to 10.2.0.
- [Commits](https://github.com/beaugunderson/ip-address/commits)
---
updated-dependencies:
- dependency-name: ip-address
dependency-version: 10.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…_versions
Update minor versions of cache and artifact dependencies
Bumps [fast-xml-builder](https://github.com/NaturalIntelligence/fast-xml-builder) from 1.1.5 to 1.2.0.
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-builder/blob/main/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-builder@v1.1.5...v1.2.0)
---
updated-dependencies:
- dependency-name: fast-xml-builder
dependency-version: 1.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/attest/ip-address-10.2.0
chore(deps): bump ip-address from 10.0.1 to 10.2.0 in /packages/attest
…s/attest/brace-expansion-2.0.3
chore(deps): bump brace-expansion from 2.0.2 to 2.0.3 in /packages/attest
Bumps [markdown-it](https://github.com/markdown-it/markdown-it) from 14.1.1 to 14.2.0.
- [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@14.1.1...14.2.0)
---
updated-dependencies:
- dependency-name: markdown-it
dependency-version: 14.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…TIONS_CACHE_MODE skip) (#2447)
* feat(cache): surface cache read-denied as a distinct restore warning
Mirror the existing cache write-denied handling on the restore path. When
the receiver refuses a download URL because the run's token has no readable
cache scopes, it returns a twirp PermissionDenied (HTTP 403). The twirp
client wraps that 403 in a generic Error, so the stable 'cache read denied:'
prefix is embedded in the message rather than at the start.
- Add CACHE_READ_DENIED_PREFIX and CacheReadDeniedError
- Dispatch on the prefix in the restoreCacheV2 catch block (V2 only), log a
policy-specific warning, and report a cache miss so the run continues
- Add a test mirroring the write-denied coverage
* chore(cache): trim comments, bump to 6.2.0, add RELEASES entry
* refactor(cache): dispatch read-denied by error name to mirror write path
Re-throw CacheReadDeniedError from an inner try/catch around
GetCacheEntryDownloadURL and dispatch on typedError.name in the outer catch,
matching how saveCacheV2 handles CacheWriteDeniedError.
* feat(cache): handle read-denied on the v1 restore path
Extend the read-denied handling to Cache Service v1 so GHES (which forces v1
via _apis/artifactcache) is covered when read-scope enforcement ships there.
- Surface the receiver's error body message from getCacheEntry instead of a
generic status-code error, so the cache read denied: prefix reaches callers
- Re-throw CacheReadDeniedError from restoreCacheV1 and dispatch on it in the
outer catch, mirroring restoreCacheV2 and the write-denied v1 handling
- Add a v1 read-denied test
* refactor(cache): only surface receiver body for read-denied on v1
* test(cache): assert getCacheEntry only surfaces body for read-denied
* test(cache): cover non-read-denied getCacheEntry passthrough on v1
* refactor(cache): share read-denied prefix via constants to avoid drift
* feat(cache): skip restore/save per ACTIONS_CACHE_MODE
* test(cache): expand ACTIONS_CACHE_MODE skip coverage across v1/v2 and unknown modes
* fix copilot pr feedback
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* docs(cache): remove internal reference from cache-mode comment
* test(cache): merge redundant cache-mode skip tests and simplify read-denied handling
Address PR review feedback:
- Merge the duplicate restore/save skip test.each blocks into single blocks parametrized over ACTIONS_CACHE_SERVICE_V2.
- Drop the redundant CacheReadDeniedError catch arms; the typed error is not an HttpClientError so it already falls through to a non-fatal warning.
- Clarify why read-denied classification happens both in getCacheEntry and cache.ts (dependency-free internal module cannot import the typed error).
* refactor(cache): drop redundant CacheWriteDeniedError catch arms
Mirror the read-denied simplification on the save path. CacheWriteDeniedError
is not an HttpClientError and its name does not match the ReserveCacheError
arm, so it falls through to the same non-fatal warning. Logging behavior is
unchanged (warns, never fails the run) and the exported type is still thrown
internally for consumers and tests. Also refresh stale doc wording.
* test(cache): collapse redundant restore getCacheEntry-failure tests
The two restoreCache tests exercised the identical warning + cache-miss path
now that read-denied is no longer reclassified in the catch, so merge them into
one. The read-denied prefix detection that actually branches on the message is
covered by getCacheEntry tests in cacheHttpClient.test.ts.
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* @actions/glob: extend hashFiles options
* improve hashFiles symlink handling
* Improve error handling and messaging in hashFiles function
* apply relative exclude patterns across all roots and use named minimatch import
* format error message
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.6 to 5.0.7.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.6...v5.0.7)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 5.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.10 to 7.5.22.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v7.5.10...v7.5.22)
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.22
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/glob/brace-expansion-5.0.7
chore(deps): bump brace-expansion from 5.0.6 to 5.0.7 in /packages/glob
…s/github/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/github
…s/artifact/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/artifact
…s/artifact/markdown-it-14.2.0
chore(deps): bump markdown-it from 14.1.1 to 14.2.0 in /packages/artifact
Bumps [linkify-it](https://github.com/markdown-it/linkify-it) from 5.0.1 to 5.0.2.
- [Changelog](https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/linkify-it@5.0.1...5.0.2)
---
updated-dependencies:
- dependency-name: linkify-it
dependency-version: 5.0.2
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/artifact/fast-xml-builder-1.2.0
chore(deps): bump fast-xml-builder from 1.1.5 to 1.2.0 in /packages/artifact
…s/attest/tar-7.5.22
chore(deps): bump tar from 7.5.10 to 7.5.22 in /packages/attest
…s/artifact/linkify-it-5.0.2
chore(deps): bump linkify-it from 5.0.1 to 5.0.2 in /packages/artifact
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 2.1.0 to 2.1.4.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v2.1.0...v2.1.4)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 2.1.4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
#2463)
Bumps [undici](https://github.com/nodejs/undici) from 6.23.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.23.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…2330)
Bumps [minimatch](https://github.com/isaacs/minimatch) from 9.0.5 to 9.0.9.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v9.0.5...v9.0.9)
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 9.0.9
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@dwisiswant0@Anytar888@joe345-str@tteo38472@tingx2wang@salmanmkc@malancas@bdehamer@TingluoHuang@GhadimiR@lokesh755@danwkennedy@zaataylor@Link-@shogo82148@aiqiaoy@Samirat@jasongin@philip-gai
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[pull] main from actions:main - #7

Open
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main
Open

[pull] main from actions:main#7
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main

Conversation

@pull

@pullpullBot commented Oct 15, 2024

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot]

Can you help keep this open source service alive? 💖 Please sponsor : )

@sourcery-ai

sourcery-aiBot commented Oct 15, 2024

Copy link
Copy Markdown

Reviewer's Guide by Sourcery

This pull request includes several significant changes across multiple packages in the actions/toolkit repository. The changes primarily focus on updating dependencies, improving error handling, enhancing security, and refactoring code for better performance and maintainability. Key updates include modifications to the artifact upload process, changes to OIDC token handling, improvements to the HTTP client, and updates to the glob and attest packages.

Class diagram for OIDC Token Handling

classDiagram
class OIDCConfig {
string issuer
string jwks_uri
}
class ClaimSet {
string iss
string ref
string sha
string repository
string event_name
string job_workflow_ref
string workflow_ref
string repository_id
string repository_owner_id
}
class OIDC {
+getIDTokenClaims(issuer: string): Promise<ClaimSet>
+decodeOIDCToken(token: string, issuer: string): Promise<JWTPayload>
+getJWKS(issuer: string): Promise<JSONWebKeySet>
+getIssuer(): string
}
OIDC --> OIDCConfig
OIDC --> ClaimSet
Loading

Class diagram for HTTP Client Proxy Handling

classDiagram
class DecodedURL {
string username
string password
string href
}
class HttpClient {
+getProxyUrl(reqUrl: URL): URL | undefined
+getAgent(url: string): any
}
HttpClient --> DecodedURL
Loading

File-Level Changes

ChangeDetailsFiles
Refactored artifact upload process
  • Updated chunk timeout logic
  • Implemented lazy stream to prevent issues with open file limits
  • Fixed a regression with symlinks not being automatically resolved
  • Improved error handling for upload progress stalling
packages/artifact/__tests__/upload-artifact.test.ts
packages/artifact/src/internal/upload/blob-upload.ts
packages/artifact/src/internal/upload/upload-zip-specification.ts
packages/artifact/src/internal/upload/zip.ts
Enhanced OIDC token handling and attestation process
  • Updated OIDC token claim validation
  • Improved handling of enterprise-specific OIDC issuers
  • Added support for custom HTTP headers in attestation requests
  • Updated SLSA provenance predicate generation
packages/attest/src/oidc.ts
packages/attest/src/provenance.ts
packages/attest/src/attest.ts
packages/attest/src/store.ts
Improved HTTP client functionality
  • Fixed handling of proxy usernames and passwords
  • Updated URL decoding for proxy authentication
  • Improved error handling for network requests
packages/http-client/src/index.ts
packages/http-client/src/proxy.ts
Updated glob package with new features
  • Added option to exclude hidden files in glob searches
  • Improved handling of symlinks in glob results
packages/glob/src/internal-glob-options.ts
packages/glob/src/internal-globber.ts
General dependency updates and security improvements
  • Updated various dependencies across packages
  • Replaced uuid package with native crypto.randomUUID()
  • Improved error messages and debugging information
packages/artifact/RELEASES.md
packages/attest/RELEASES.md
packages/core/RELEASES.md
packages/glob/RELEASES.md
packages/http-client/RELEASES.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time. You can also use
    this command to specify where the summary should be inserted.

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have skipped reviewing this pull request. It seems to have been created by a bot (hey, pull[bot]!). We assume it knows what it's doing!

tingx2wangand others added 27 commits December 5, 2025 17:13
…s/attest/tar-7.5.2
Bump tar from 7.5.1 to 7.5.2 in /packages/attest
- Update spawn-wait-for-file.js to use proper stdio inheritance
- Add small delay before exit to ensure child process inherits handles
- Simplify test code to use the helper script instead of shell commands
On Windows, detached:true is needed to properly keep stdio handles
open after the parent process exits.
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
chore: fix npm audit vulnerabilities (glob, js-yaml)
Samiratand others added 30 commits May 1, 2026 17:38
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.0.1 to 10.2.0.
- [Commits](https://github.com/beaugunderson/ip-address/commits)
---
updated-dependencies:
- dependency-name: ip-address
dependency-version: 10.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…_versions
Update minor versions of cache and artifact dependencies
Bumps [fast-xml-builder](https://github.com/NaturalIntelligence/fast-xml-builder) from 1.1.5 to 1.2.0.
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-builder/blob/main/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-builder@v1.1.5...v1.2.0)
---
updated-dependencies:
- dependency-name: fast-xml-builder
dependency-version: 1.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/attest/ip-address-10.2.0
chore(deps): bump ip-address from 10.0.1 to 10.2.0 in /packages/attest
…s/attest/brace-expansion-2.0.3
chore(deps): bump brace-expansion from 2.0.2 to 2.0.3 in /packages/attest
Bumps [markdown-it](https://github.com/markdown-it/markdown-it) from 14.1.1 to 14.2.0.
- [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@14.1.1...14.2.0)
---
updated-dependencies:
- dependency-name: markdown-it
dependency-version: 14.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…TIONS_CACHE_MODE skip) (#2447)
* feat(cache): surface cache read-denied as a distinct restore warning
Mirror the existing cache write-denied handling on the restore path. When
the receiver refuses a download URL because the run's token has no readable
cache scopes, it returns a twirp PermissionDenied (HTTP 403). The twirp
client wraps that 403 in a generic Error, so the stable 'cache read denied:'
prefix is embedded in the message rather than at the start.
- Add CACHE_READ_DENIED_PREFIX and CacheReadDeniedError
- Dispatch on the prefix in the restoreCacheV2 catch block (V2 only), log a
policy-specific warning, and report a cache miss so the run continues
- Add a test mirroring the write-denied coverage
* chore(cache): trim comments, bump to 6.2.0, add RELEASES entry
* refactor(cache): dispatch read-denied by error name to mirror write path
Re-throw CacheReadDeniedError from an inner try/catch around
GetCacheEntryDownloadURL and dispatch on typedError.name in the outer catch,
matching how saveCacheV2 handles CacheWriteDeniedError.
* feat(cache): handle read-denied on the v1 restore path
Extend the read-denied handling to Cache Service v1 so GHES (which forces v1
via _apis/artifactcache) is covered when read-scope enforcement ships there.
- Surface the receiver's error body message from getCacheEntry instead of a
generic status-code error, so the cache read denied: prefix reaches callers
- Re-throw CacheReadDeniedError from restoreCacheV1 and dispatch on it in the
outer catch, mirroring restoreCacheV2 and the write-denied v1 handling
- Add a v1 read-denied test
* refactor(cache): only surface receiver body for read-denied on v1
* test(cache): assert getCacheEntry only surfaces body for read-denied
* test(cache): cover non-read-denied getCacheEntry passthrough on v1
* refactor(cache): share read-denied prefix via constants to avoid drift
* feat(cache): skip restore/save per ACTIONS_CACHE_MODE
* test(cache): expand ACTIONS_CACHE_MODE skip coverage across v1/v2 and unknown modes
* fix copilot pr feedback
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* docs(cache): remove internal reference from cache-mode comment
* test(cache): merge redundant cache-mode skip tests and simplify read-denied handling
Address PR review feedback:
- Merge the duplicate restore/save skip test.each blocks into single blocks parametrized over ACTIONS_CACHE_SERVICE_V2.
- Drop the redundant CacheReadDeniedError catch arms; the typed error is not an HttpClientError so it already falls through to a non-fatal warning.
- Clarify why read-denied classification happens both in getCacheEntry and cache.ts (dependency-free internal module cannot import the typed error).
* refactor(cache): drop redundant CacheWriteDeniedError catch arms
Mirror the read-denied simplification on the save path. CacheWriteDeniedError
is not an HttpClientError and its name does not match the ReserveCacheError
arm, so it falls through to the same non-fatal warning. Logging behavior is
unchanged (warns, never fails the run) and the exported type is still thrown
internally for consumers and tests. Also refresh stale doc wording.
* test(cache): collapse redundant restore getCacheEntry-failure tests
The two restoreCache tests exercised the identical warning + cache-miss path
now that read-denied is no longer reclassified in the catch, so merge them into
one. The read-denied prefix detection that actually branches on the message is
covered by getCacheEntry tests in cacheHttpClient.test.ts.
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* @actions/glob: extend hashFiles options
* improve hashFiles symlink handling
* Improve error handling and messaging in hashFiles function
* apply relative exclude patterns across all roots and use named minimatch import
* format error message
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.6 to 5.0.7.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.6...v5.0.7)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 5.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.10 to 7.5.22.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v7.5.10...v7.5.22)
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.22
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/glob/brace-expansion-5.0.7
chore(deps): bump brace-expansion from 5.0.6 to 5.0.7 in /packages/glob
…s/github/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/github
…s/artifact/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/artifact
…s/artifact/markdown-it-14.2.0
chore(deps): bump markdown-it from 14.1.1 to 14.2.0 in /packages/artifact
Bumps [linkify-it](https://github.com/markdown-it/linkify-it) from 5.0.1 to 5.0.2.
- [Changelog](https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/linkify-it@5.0.1...5.0.2)
---
updated-dependencies:
- dependency-name: linkify-it
dependency-version: 5.0.2
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/artifact/fast-xml-builder-1.2.0
chore(deps): bump fast-xml-builder from 1.1.5 to 1.2.0 in /packages/artifact
…s/attest/tar-7.5.22
chore(deps): bump tar from 7.5.10 to 7.5.22 in /packages/attest
…s/artifact/linkify-it-5.0.2
chore(deps): bump linkify-it from 5.0.1 to 5.0.2 in /packages/artifact
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 2.1.0 to 2.1.4.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v2.1.0...v2.1.4)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 2.1.4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
#2463)
Bumps [undici](https://github.com/nodejs/undici) from 6.23.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.23.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…2330)
Bumps [minimatch](https://github.com/isaacs/minimatch) from 9.0.5 to 9.0.9.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v9.0.5...v9.0.9)
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 9.0.9
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@dwisiswant0@Anytar888@joe345-str@tteo38472@tingx2wang@salmanmkc@malancas@bdehamer@TingluoHuang@GhadimiR@lokesh755@danwkennedy@zaataylor@Link-@shogo82148@aiqiaoy@Samirat@jasongin@philip-gai
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[pull] main from actions:main - #7

Open
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main
Open

[pull] main from actions:main#7
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main

Conversation

@pull

@pullpullBot commented Oct 15, 2024

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot]

Can you help keep this open source service alive? 💖 Please sponsor : )

@sourcery-ai

sourcery-aiBot commented Oct 15, 2024

Copy link
Copy Markdown

Reviewer's Guide by Sourcery

This pull request includes several significant changes across multiple packages in the actions/toolkit repository. The changes primarily focus on updating dependencies, improving error handling, enhancing security, and refactoring code for better performance and maintainability. Key updates include modifications to the artifact upload process, changes to OIDC token handling, improvements to the HTTP client, and updates to the glob and attest packages.

Class diagram for OIDC Token Handling

classDiagram
class OIDCConfig {
string issuer
string jwks_uri
}
class ClaimSet {
string iss
string ref
string sha
string repository
string event_name
string job_workflow_ref
string workflow_ref
string repository_id
string repository_owner_id
}
class OIDC {
+getIDTokenClaims(issuer: string): Promise<ClaimSet>
+decodeOIDCToken(token: string, issuer: string): Promise<JWTPayload>
+getJWKS(issuer: string): Promise<JSONWebKeySet>
+getIssuer(): string
}
OIDC --> OIDCConfig
OIDC --> ClaimSet
Loading

Class diagram for HTTP Client Proxy Handling

classDiagram
class DecodedURL {
string username
string password
string href
}
class HttpClient {
+getProxyUrl(reqUrl: URL): URL | undefined
+getAgent(url: string): any
}
HttpClient --> DecodedURL
Loading

File-Level Changes

ChangeDetailsFiles
Refactored artifact upload process
  • Updated chunk timeout logic
  • Implemented lazy stream to prevent issues with open file limits
  • Fixed a regression with symlinks not being automatically resolved
  • Improved error handling for upload progress stalling
packages/artifact/__tests__/upload-artifact.test.ts
packages/artifact/src/internal/upload/blob-upload.ts
packages/artifact/src/internal/upload/upload-zip-specification.ts
packages/artifact/src/internal/upload/zip.ts
Enhanced OIDC token handling and attestation process
  • Updated OIDC token claim validation
  • Improved handling of enterprise-specific OIDC issuers
  • Added support for custom HTTP headers in attestation requests
  • Updated SLSA provenance predicate generation
packages/attest/src/oidc.ts
packages/attest/src/provenance.ts
packages/attest/src/attest.ts
packages/attest/src/store.ts
Improved HTTP client functionality
  • Fixed handling of proxy usernames and passwords
  • Updated URL decoding for proxy authentication
  • Improved error handling for network requests
packages/http-client/src/index.ts
packages/http-client/src/proxy.ts
Updated glob package with new features
  • Added option to exclude hidden files in glob searches
  • Improved handling of symlinks in glob results
packages/glob/src/internal-glob-options.ts
packages/glob/src/internal-globber.ts
General dependency updates and security improvements
  • Updated various dependencies across packages
  • Replaced uuid package with native crypto.randomUUID()
  • Improved error messages and debugging information
packages/artifact/RELEASES.md
packages/attest/RELEASES.md
packages/core/RELEASES.md
packages/glob/RELEASES.md
packages/http-client/RELEASES.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time. You can also use
    this command to specify where the summary should be inserted.

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have skipped reviewing this pull request. It seems to have been created by a bot (hey, pull[bot]!). We assume it knows what it's doing!

tingx2wangand others added 27 commits December 5, 2025 17:13
…s/attest/tar-7.5.2
Bump tar from 7.5.1 to 7.5.2 in /packages/attest
- Update spawn-wait-for-file.js to use proper stdio inheritance
- Add small delay before exit to ensure child process inherits handles
- Simplify test code to use the helper script instead of shell commands
On Windows, detached:true is needed to properly keep stdio handles
open after the parent process exits.
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
chore: fix npm audit vulnerabilities (glob, js-yaml)
Samiratand others added 30 commits May 1, 2026 17:38
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.0.1 to 10.2.0.
- [Commits](https://github.com/beaugunderson/ip-address/commits)
---
updated-dependencies:
- dependency-name: ip-address
dependency-version: 10.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…_versions
Update minor versions of cache and artifact dependencies
Bumps [fast-xml-builder](https://github.com/NaturalIntelligence/fast-xml-builder) from 1.1.5 to 1.2.0.
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-builder/blob/main/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-builder@v1.1.5...v1.2.0)
---
updated-dependencies:
- dependency-name: fast-xml-builder
dependency-version: 1.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/attest/ip-address-10.2.0
chore(deps): bump ip-address from 10.0.1 to 10.2.0 in /packages/attest
…s/attest/brace-expansion-2.0.3
chore(deps): bump brace-expansion from 2.0.2 to 2.0.3 in /packages/attest
Bumps [markdown-it](https://github.com/markdown-it/markdown-it) from 14.1.1 to 14.2.0.
- [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@14.1.1...14.2.0)
---
updated-dependencies:
- dependency-name: markdown-it
dependency-version: 14.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…TIONS_CACHE_MODE skip) (#2447)
* feat(cache): surface cache read-denied as a distinct restore warning
Mirror the existing cache write-denied handling on the restore path. When
the receiver refuses a download URL because the run's token has no readable
cache scopes, it returns a twirp PermissionDenied (HTTP 403). The twirp
client wraps that 403 in a generic Error, so the stable 'cache read denied:'
prefix is embedded in the message rather than at the start.
- Add CACHE_READ_DENIED_PREFIX and CacheReadDeniedError
- Dispatch on the prefix in the restoreCacheV2 catch block (V2 only), log a
policy-specific warning, and report a cache miss so the run continues
- Add a test mirroring the write-denied coverage
* chore(cache): trim comments, bump to 6.2.0, add RELEASES entry
* refactor(cache): dispatch read-denied by error name to mirror write path
Re-throw CacheReadDeniedError from an inner try/catch around
GetCacheEntryDownloadURL and dispatch on typedError.name in the outer catch,
matching how saveCacheV2 handles CacheWriteDeniedError.
* feat(cache): handle read-denied on the v1 restore path
Extend the read-denied handling to Cache Service v1 so GHES (which forces v1
via _apis/artifactcache) is covered when read-scope enforcement ships there.
- Surface the receiver's error body message from getCacheEntry instead of a
generic status-code error, so the cache read denied: prefix reaches callers
- Re-throw CacheReadDeniedError from restoreCacheV1 and dispatch on it in the
outer catch, mirroring restoreCacheV2 and the write-denied v1 handling
- Add a v1 read-denied test
* refactor(cache): only surface receiver body for read-denied on v1
* test(cache): assert getCacheEntry only surfaces body for read-denied
* test(cache): cover non-read-denied getCacheEntry passthrough on v1
* refactor(cache): share read-denied prefix via constants to avoid drift
* feat(cache): skip restore/save per ACTIONS_CACHE_MODE
* test(cache): expand ACTIONS_CACHE_MODE skip coverage across v1/v2 and unknown modes
* fix copilot pr feedback
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* docs(cache): remove internal reference from cache-mode comment
* test(cache): merge redundant cache-mode skip tests and simplify read-denied handling
Address PR review feedback:
- Merge the duplicate restore/save skip test.each blocks into single blocks parametrized over ACTIONS_CACHE_SERVICE_V2.
- Drop the redundant CacheReadDeniedError catch arms; the typed error is not an HttpClientError so it already falls through to a non-fatal warning.
- Clarify why read-denied classification happens both in getCacheEntry and cache.ts (dependency-free internal module cannot import the typed error).
* refactor(cache): drop redundant CacheWriteDeniedError catch arms
Mirror the read-denied simplification on the save path. CacheWriteDeniedError
is not an HttpClientError and its name does not match the ReserveCacheError
arm, so it falls through to the same non-fatal warning. Logging behavior is
unchanged (warns, never fails the run) and the exported type is still thrown
internally for consumers and tests. Also refresh stale doc wording.
* test(cache): collapse redundant restore getCacheEntry-failure tests
The two restoreCache tests exercised the identical warning + cache-miss path
now that read-denied is no longer reclassified in the catch, so merge them into
one. The read-denied prefix detection that actually branches on the message is
covered by getCacheEntry tests in cacheHttpClient.test.ts.
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* @actions/glob: extend hashFiles options
* improve hashFiles symlink handling
* Improve error handling and messaging in hashFiles function
* apply relative exclude patterns across all roots and use named minimatch import
* format error message
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.6 to 5.0.7.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.6...v5.0.7)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 5.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.10 to 7.5.22.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v7.5.10...v7.5.22)
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.22
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/glob/brace-expansion-5.0.7
chore(deps): bump brace-expansion from 5.0.6 to 5.0.7 in /packages/glob
…s/github/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/github
…s/artifact/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/artifact
…s/artifact/markdown-it-14.2.0
chore(deps): bump markdown-it from 14.1.1 to 14.2.0 in /packages/artifact
Bumps [linkify-it](https://github.com/markdown-it/linkify-it) from 5.0.1 to 5.0.2.
- [Changelog](https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/linkify-it@5.0.1...5.0.2)
---
updated-dependencies:
- dependency-name: linkify-it
dependency-version: 5.0.2
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/artifact/fast-xml-builder-1.2.0
chore(deps): bump fast-xml-builder from 1.1.5 to 1.2.0 in /packages/artifact
…s/attest/tar-7.5.22
chore(deps): bump tar from 7.5.10 to 7.5.22 in /packages/attest
…s/artifact/linkify-it-5.0.2
chore(deps): bump linkify-it from 5.0.1 to 5.0.2 in /packages/artifact
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 2.1.0 to 2.1.4.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v2.1.0...v2.1.4)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 2.1.4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
#2463)
Bumps [undici](https://github.com/nodejs/undici) from 6.23.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.23.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…2330)
Bumps [minimatch](https://github.com/isaacs/minimatch) from 9.0.5 to 9.0.9.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v9.0.5...v9.0.9)
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 9.0.9
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@dwisiswant0@Anytar888@joe345-str@tteo38472@tingx2wang@salmanmkc@malancas@bdehamer@TingluoHuang@GhadimiR@lokesh755@danwkennedy@zaataylor@Link-@shogo82148@aiqiaoy@Samirat@jasongin@philip-gai
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[pull] main from actions:main - #7

Open
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main
Open

[pull] main from actions:main#7
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main

Conversation

@pull

@pullpullBot commented Oct 15, 2024

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot]

Can you help keep this open source service alive? 💖 Please sponsor : )

@sourcery-ai

sourcery-aiBot commented Oct 15, 2024

Copy link
Copy Markdown

Reviewer's Guide by Sourcery

This pull request includes several significant changes across multiple packages in the actions/toolkit repository. The changes primarily focus on updating dependencies, improving error handling, enhancing security, and refactoring code for better performance and maintainability. Key updates include modifications to the artifact upload process, changes to OIDC token handling, improvements to the HTTP client, and updates to the glob and attest packages.

Class diagram for OIDC Token Handling

classDiagram
class OIDCConfig {
string issuer
string jwks_uri
}
class ClaimSet {
string iss
string ref
string sha
string repository
string event_name
string job_workflow_ref
string workflow_ref
string repository_id
string repository_owner_id
}
class OIDC {
+getIDTokenClaims(issuer: string): Promise<ClaimSet>
+decodeOIDCToken(token: string, issuer: string): Promise<JWTPayload>
+getJWKS(issuer: string): Promise<JSONWebKeySet>
+getIssuer(): string
}
OIDC --> OIDCConfig
OIDC --> ClaimSet
Loading

Class diagram for HTTP Client Proxy Handling

classDiagram
class DecodedURL {
string username
string password
string href
}
class HttpClient {
+getProxyUrl(reqUrl: URL): URL | undefined
+getAgent(url: string): any
}
HttpClient --> DecodedURL
Loading

File-Level Changes

ChangeDetailsFiles
Refactored artifact upload process
  • Updated chunk timeout logic
  • Implemented lazy stream to prevent issues with open file limits
  • Fixed a regression with symlinks not being automatically resolved
  • Improved error handling for upload progress stalling
packages/artifact/__tests__/upload-artifact.test.ts
packages/artifact/src/internal/upload/blob-upload.ts
packages/artifact/src/internal/upload/upload-zip-specification.ts
packages/artifact/src/internal/upload/zip.ts
Enhanced OIDC token handling and attestation process
  • Updated OIDC token claim validation
  • Improved handling of enterprise-specific OIDC issuers
  • Added support for custom HTTP headers in attestation requests
  • Updated SLSA provenance predicate generation
packages/attest/src/oidc.ts
packages/attest/src/provenance.ts
packages/attest/src/attest.ts
packages/attest/src/store.ts
Improved HTTP client functionality
  • Fixed handling of proxy usernames and passwords
  • Updated URL decoding for proxy authentication
  • Improved error handling for network requests
packages/http-client/src/index.ts
packages/http-client/src/proxy.ts
Updated glob package with new features
  • Added option to exclude hidden files in glob searches
  • Improved handling of symlinks in glob results
packages/glob/src/internal-glob-options.ts
packages/glob/src/internal-globber.ts
General dependency updates and security improvements
  • Updated various dependencies across packages
  • Replaced uuid package with native crypto.randomUUID()
  • Improved error messages and debugging information
packages/artifact/RELEASES.md
packages/attest/RELEASES.md
packages/core/RELEASES.md
packages/glob/RELEASES.md
packages/http-client/RELEASES.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time. You can also use
    this command to specify where the summary should be inserted.

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have skipped reviewing this pull request. It seems to have been created by a bot (hey, pull[bot]!). We assume it knows what it's doing!

tingx2wangand others added 27 commits December 5, 2025 17:13
…s/attest/tar-7.5.2
Bump tar from 7.5.1 to 7.5.2 in /packages/attest
- Update spawn-wait-for-file.js to use proper stdio inheritance
- Add small delay before exit to ensure child process inherits handles
- Simplify test code to use the helper script instead of shell commands
On Windows, detached:true is needed to properly keep stdio handles
open after the parent process exits.
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
chore: fix npm audit vulnerabilities (glob, js-yaml)
Samiratand others added 30 commits May 1, 2026 17:38
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.0.1 to 10.2.0.
- [Commits](https://github.com/beaugunderson/ip-address/commits)
---
updated-dependencies:
- dependency-name: ip-address
dependency-version: 10.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…_versions
Update minor versions of cache and artifact dependencies
Bumps [fast-xml-builder](https://github.com/NaturalIntelligence/fast-xml-builder) from 1.1.5 to 1.2.0.
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-builder/blob/main/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-builder@v1.1.5...v1.2.0)
---
updated-dependencies:
- dependency-name: fast-xml-builder
dependency-version: 1.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/attest/ip-address-10.2.0
chore(deps): bump ip-address from 10.0.1 to 10.2.0 in /packages/attest
…s/attest/brace-expansion-2.0.3
chore(deps): bump brace-expansion from 2.0.2 to 2.0.3 in /packages/attest
Bumps [markdown-it](https://github.com/markdown-it/markdown-it) from 14.1.1 to 14.2.0.
- [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@14.1.1...14.2.0)
---
updated-dependencies:
- dependency-name: markdown-it
dependency-version: 14.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…TIONS_CACHE_MODE skip) (#2447)
* feat(cache): surface cache read-denied as a distinct restore warning
Mirror the existing cache write-denied handling on the restore path. When
the receiver refuses a download URL because the run's token has no readable
cache scopes, it returns a twirp PermissionDenied (HTTP 403). The twirp
client wraps that 403 in a generic Error, so the stable 'cache read denied:'
prefix is embedded in the message rather than at the start.
- Add CACHE_READ_DENIED_PREFIX and CacheReadDeniedError
- Dispatch on the prefix in the restoreCacheV2 catch block (V2 only), log a
policy-specific warning, and report a cache miss so the run continues
- Add a test mirroring the write-denied coverage
* chore(cache): trim comments, bump to 6.2.0, add RELEASES entry
* refactor(cache): dispatch read-denied by error name to mirror write path
Re-throw CacheReadDeniedError from an inner try/catch around
GetCacheEntryDownloadURL and dispatch on typedError.name in the outer catch,
matching how saveCacheV2 handles CacheWriteDeniedError.
* feat(cache): handle read-denied on the v1 restore path
Extend the read-denied handling to Cache Service v1 so GHES (which forces v1
via _apis/artifactcache) is covered when read-scope enforcement ships there.
- Surface the receiver's error body message from getCacheEntry instead of a
generic status-code error, so the cache read denied: prefix reaches callers
- Re-throw CacheReadDeniedError from restoreCacheV1 and dispatch on it in the
outer catch, mirroring restoreCacheV2 and the write-denied v1 handling
- Add a v1 read-denied test
* refactor(cache): only surface receiver body for read-denied on v1
* test(cache): assert getCacheEntry only surfaces body for read-denied
* test(cache): cover non-read-denied getCacheEntry passthrough on v1
* refactor(cache): share read-denied prefix via constants to avoid drift
* feat(cache): skip restore/save per ACTIONS_CACHE_MODE
* test(cache): expand ACTIONS_CACHE_MODE skip coverage across v1/v2 and unknown modes
* fix copilot pr feedback
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* docs(cache): remove internal reference from cache-mode comment
* test(cache): merge redundant cache-mode skip tests and simplify read-denied handling
Address PR review feedback:
- Merge the duplicate restore/save skip test.each blocks into single blocks parametrized over ACTIONS_CACHE_SERVICE_V2.
- Drop the redundant CacheReadDeniedError catch arms; the typed error is not an HttpClientError so it already falls through to a non-fatal warning.
- Clarify why read-denied classification happens both in getCacheEntry and cache.ts (dependency-free internal module cannot import the typed error).
* refactor(cache): drop redundant CacheWriteDeniedError catch arms
Mirror the read-denied simplification on the save path. CacheWriteDeniedError
is not an HttpClientError and its name does not match the ReserveCacheError
arm, so it falls through to the same non-fatal warning. Logging behavior is
unchanged (warns, never fails the run) and the exported type is still thrown
internally for consumers and tests. Also refresh stale doc wording.
* test(cache): collapse redundant restore getCacheEntry-failure tests
The two restoreCache tests exercised the identical warning + cache-miss path
now that read-denied is no longer reclassified in the catch, so merge them into
one. The read-denied prefix detection that actually branches on the message is
covered by getCacheEntry tests in cacheHttpClient.test.ts.
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* @actions/glob: extend hashFiles options
* improve hashFiles symlink handling
* Improve error handling and messaging in hashFiles function
* apply relative exclude patterns across all roots and use named minimatch import
* format error message
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.6 to 5.0.7.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.6...v5.0.7)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 5.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.10 to 7.5.22.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v7.5.10...v7.5.22)
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.22
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/glob/brace-expansion-5.0.7
chore(deps): bump brace-expansion from 5.0.6 to 5.0.7 in /packages/glob
…s/github/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/github
…s/artifact/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/artifact
…s/artifact/markdown-it-14.2.0
chore(deps): bump markdown-it from 14.1.1 to 14.2.0 in /packages/artifact
Bumps [linkify-it](https://github.com/markdown-it/linkify-it) from 5.0.1 to 5.0.2.
- [Changelog](https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/linkify-it@5.0.1...5.0.2)
---
updated-dependencies:
- dependency-name: linkify-it
dependency-version: 5.0.2
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/artifact/fast-xml-builder-1.2.0
chore(deps): bump fast-xml-builder from 1.1.5 to 1.2.0 in /packages/artifact
…s/attest/tar-7.5.22
chore(deps): bump tar from 7.5.10 to 7.5.22 in /packages/attest
…s/artifact/linkify-it-5.0.2
chore(deps): bump linkify-it from 5.0.1 to 5.0.2 in /packages/artifact
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 2.1.0 to 2.1.4.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v2.1.0...v2.1.4)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 2.1.4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
#2463)
Bumps [undici](https://github.com/nodejs/undici) from 6.23.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.23.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…2330)
Bumps [minimatch](https://github.com/isaacs/minimatch) from 9.0.5 to 9.0.9.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v9.0.5...v9.0.9)
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 9.0.9
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@dwisiswant0@Anytar888@joe345-str@tteo38472@tingx2wang@salmanmkc@malancas@bdehamer@TingluoHuang@GhadimiR@lokesh755@danwkennedy@zaataylor@Link-@shogo82148@aiqiaoy@Samirat@jasongin@philip-gai
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[pull] main from actions:main - #7

Open
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main
Open

[pull] main from actions:main#7
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main

Conversation

@pull

@pullpullBot commented Oct 15, 2024

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot]

Can you help keep this open source service alive? 💖 Please sponsor : )

@sourcery-ai

sourcery-aiBot commented Oct 15, 2024

Copy link
Copy Markdown

Reviewer's Guide by Sourcery

This pull request includes several significant changes across multiple packages in the actions/toolkit repository. The changes primarily focus on updating dependencies, improving error handling, enhancing security, and refactoring code for better performance and maintainability. Key updates include modifications to the artifact upload process, changes to OIDC token handling, improvements to the HTTP client, and updates to the glob and attest packages.

Class diagram for OIDC Token Handling

classDiagram
class OIDCConfig {
string issuer
string jwks_uri
}
class ClaimSet {
string iss
string ref
string sha
string repository
string event_name
string job_workflow_ref
string workflow_ref
string repository_id
string repository_owner_id
}
class OIDC {
+getIDTokenClaims(issuer: string): Promise<ClaimSet>
+decodeOIDCToken(token: string, issuer: string): Promise<JWTPayload>
+getJWKS(issuer: string): Promise<JSONWebKeySet>
+getIssuer(): string
}
OIDC --> OIDCConfig
OIDC --> ClaimSet
Loading

Class diagram for HTTP Client Proxy Handling

classDiagram
class DecodedURL {
string username
string password
string href
}
class HttpClient {
+getProxyUrl(reqUrl: URL): URL | undefined
+getAgent(url: string): any
}
HttpClient --> DecodedURL
Loading

File-Level Changes

ChangeDetailsFiles
Refactored artifact upload process
  • Updated chunk timeout logic
  • Implemented lazy stream to prevent issues with open file limits
  • Fixed a regression with symlinks not being automatically resolved
  • Improved error handling for upload progress stalling
packages/artifact/__tests__/upload-artifact.test.ts
packages/artifact/src/internal/upload/blob-upload.ts
packages/artifact/src/internal/upload/upload-zip-specification.ts
packages/artifact/src/internal/upload/zip.ts
Enhanced OIDC token handling and attestation process
  • Updated OIDC token claim validation
  • Improved handling of enterprise-specific OIDC issuers
  • Added support for custom HTTP headers in attestation requests
  • Updated SLSA provenance predicate generation
packages/attest/src/oidc.ts
packages/attest/src/provenance.ts
packages/attest/src/attest.ts
packages/attest/src/store.ts
Improved HTTP client functionality
  • Fixed handling of proxy usernames and passwords
  • Updated URL decoding for proxy authentication
  • Improved error handling for network requests
packages/http-client/src/index.ts
packages/http-client/src/proxy.ts
Updated glob package with new features
  • Added option to exclude hidden files in glob searches
  • Improved handling of symlinks in glob results
packages/glob/src/internal-glob-options.ts
packages/glob/src/internal-globber.ts
General dependency updates and security improvements
  • Updated various dependencies across packages
  • Replaced uuid package with native crypto.randomUUID()
  • Improved error messages and debugging information
packages/artifact/RELEASES.md
packages/attest/RELEASES.md
packages/core/RELEASES.md
packages/glob/RELEASES.md
packages/http-client/RELEASES.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time. You can also use
    this command to specify where the summary should be inserted.

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have skipped reviewing this pull request. It seems to have been created by a bot (hey, pull[bot]!). We assume it knows what it's doing!

tingx2wangand others added 27 commits December 5, 2025 17:13
…s/attest/tar-7.5.2
Bump tar from 7.5.1 to 7.5.2 in /packages/attest
- Update spawn-wait-for-file.js to use proper stdio inheritance
- Add small delay before exit to ensure child process inherits handles
- Simplify test code to use the helper script instead of shell commands
On Windows, detached:true is needed to properly keep stdio handles
open after the parent process exits.
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
chore: fix npm audit vulnerabilities (glob, js-yaml)
Samiratand others added 30 commits May 1, 2026 17:38
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.0.1 to 10.2.0.
- [Commits](https://github.com/beaugunderson/ip-address/commits)
---
updated-dependencies:
- dependency-name: ip-address
dependency-version: 10.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…_versions
Update minor versions of cache and artifact dependencies
Bumps [fast-xml-builder](https://github.com/NaturalIntelligence/fast-xml-builder) from 1.1.5 to 1.2.0.
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-builder/blob/main/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-builder@v1.1.5...v1.2.0)
---
updated-dependencies:
- dependency-name: fast-xml-builder
dependency-version: 1.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/attest/ip-address-10.2.0
chore(deps): bump ip-address from 10.0.1 to 10.2.0 in /packages/attest
…s/attest/brace-expansion-2.0.3
chore(deps): bump brace-expansion from 2.0.2 to 2.0.3 in /packages/attest
Bumps [markdown-it](https://github.com/markdown-it/markdown-it) from 14.1.1 to 14.2.0.
- [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@14.1.1...14.2.0)
---
updated-dependencies:
- dependency-name: markdown-it
dependency-version: 14.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…TIONS_CACHE_MODE skip) (#2447)
* feat(cache): surface cache read-denied as a distinct restore warning
Mirror the existing cache write-denied handling on the restore path. When
the receiver refuses a download URL because the run's token has no readable
cache scopes, it returns a twirp PermissionDenied (HTTP 403). The twirp
client wraps that 403 in a generic Error, so the stable 'cache read denied:'
prefix is embedded in the message rather than at the start.
- Add CACHE_READ_DENIED_PREFIX and CacheReadDeniedError
- Dispatch on the prefix in the restoreCacheV2 catch block (V2 only), log a
policy-specific warning, and report a cache miss so the run continues
- Add a test mirroring the write-denied coverage
* chore(cache): trim comments, bump to 6.2.0, add RELEASES entry
* refactor(cache): dispatch read-denied by error name to mirror write path
Re-throw CacheReadDeniedError from an inner try/catch around
GetCacheEntryDownloadURL and dispatch on typedError.name in the outer catch,
matching how saveCacheV2 handles CacheWriteDeniedError.
* feat(cache): handle read-denied on the v1 restore path
Extend the read-denied handling to Cache Service v1 so GHES (which forces v1
via _apis/artifactcache) is covered when read-scope enforcement ships there.
- Surface the receiver's error body message from getCacheEntry instead of a
generic status-code error, so the cache read denied: prefix reaches callers
- Re-throw CacheReadDeniedError from restoreCacheV1 and dispatch on it in the
outer catch, mirroring restoreCacheV2 and the write-denied v1 handling
- Add a v1 read-denied test
* refactor(cache): only surface receiver body for read-denied on v1
* test(cache): assert getCacheEntry only surfaces body for read-denied
* test(cache): cover non-read-denied getCacheEntry passthrough on v1
* refactor(cache): share read-denied prefix via constants to avoid drift
* feat(cache): skip restore/save per ACTIONS_CACHE_MODE
* test(cache): expand ACTIONS_CACHE_MODE skip coverage across v1/v2 and unknown modes
* fix copilot pr feedback
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* docs(cache): remove internal reference from cache-mode comment
* test(cache): merge redundant cache-mode skip tests and simplify read-denied handling
Address PR review feedback:
- Merge the duplicate restore/save skip test.each blocks into single blocks parametrized over ACTIONS_CACHE_SERVICE_V2.
- Drop the redundant CacheReadDeniedError catch arms; the typed error is not an HttpClientError so it already falls through to a non-fatal warning.
- Clarify why read-denied classification happens both in getCacheEntry and cache.ts (dependency-free internal module cannot import the typed error).
* refactor(cache): drop redundant CacheWriteDeniedError catch arms
Mirror the read-denied simplification on the save path. CacheWriteDeniedError
is not an HttpClientError and its name does not match the ReserveCacheError
arm, so it falls through to the same non-fatal warning. Logging behavior is
unchanged (warns, never fails the run) and the exported type is still thrown
internally for consumers and tests. Also refresh stale doc wording.
* test(cache): collapse redundant restore getCacheEntry-failure tests
The two restoreCache tests exercised the identical warning + cache-miss path
now that read-denied is no longer reclassified in the catch, so merge them into
one. The read-denied prefix detection that actually branches on the message is
covered by getCacheEntry tests in cacheHttpClient.test.ts.
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* @actions/glob: extend hashFiles options
* improve hashFiles symlink handling
* Improve error handling and messaging in hashFiles function
* apply relative exclude patterns across all roots and use named minimatch import
* format error message
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.6 to 5.0.7.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.6...v5.0.7)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 5.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.10 to 7.5.22.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v7.5.10...v7.5.22)
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.22
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/glob/brace-expansion-5.0.7
chore(deps): bump brace-expansion from 5.0.6 to 5.0.7 in /packages/glob
…s/github/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/github
…s/artifact/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/artifact
…s/artifact/markdown-it-14.2.0
chore(deps): bump markdown-it from 14.1.1 to 14.2.0 in /packages/artifact
Bumps [linkify-it](https://github.com/markdown-it/linkify-it) from 5.0.1 to 5.0.2.
- [Changelog](https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/linkify-it@5.0.1...5.0.2)
---
updated-dependencies:
- dependency-name: linkify-it
dependency-version: 5.0.2
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/artifact/fast-xml-builder-1.2.0
chore(deps): bump fast-xml-builder from 1.1.5 to 1.2.0 in /packages/artifact
…s/attest/tar-7.5.22
chore(deps): bump tar from 7.5.10 to 7.5.22 in /packages/attest
…s/artifact/linkify-it-5.0.2
chore(deps): bump linkify-it from 5.0.1 to 5.0.2 in /packages/artifact
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 2.1.0 to 2.1.4.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v2.1.0...v2.1.4)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 2.1.4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
#2463)
Bumps [undici](https://github.com/nodejs/undici) from 6.23.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.23.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…2330)
Bumps [minimatch](https://github.com/isaacs/minimatch) from 9.0.5 to 9.0.9.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v9.0.5...v9.0.9)
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 9.0.9
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@dwisiswant0@Anytar888@joe345-str@tteo38472@tingx2wang@salmanmkc@malancas@bdehamer@TingluoHuang@GhadimiR@lokesh755@danwkennedy@zaataylor@Link-@shogo82148@aiqiaoy@Samirat@jasongin@philip-gai
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[pull] main from actions:main - #7

Open
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main
Open

[pull] main from actions:main#7
pull[bot] wants to merge 684 commits into
Graybar-codespace:mainfrom
actions:main

Conversation

@pull

@pullpullBot commented Oct 15, 2024

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot]

Can you help keep this open source service alive? 💖 Please sponsor : )

@sourcery-ai

sourcery-aiBot commented Oct 15, 2024

Copy link
Copy Markdown

Reviewer's Guide by Sourcery

This pull request includes several significant changes across multiple packages in the actions/toolkit repository. The changes primarily focus on updating dependencies, improving error handling, enhancing security, and refactoring code for better performance and maintainability. Key updates include modifications to the artifact upload process, changes to OIDC token handling, improvements to the HTTP client, and updates to the glob and attest packages.

Class diagram for OIDC Token Handling

classDiagram
class OIDCConfig {
string issuer
string jwks_uri
}
class ClaimSet {
string iss
string ref
string sha
string repository
string event_name
string job_workflow_ref
string workflow_ref
string repository_id
string repository_owner_id
}
class OIDC {
+getIDTokenClaims(issuer: string): Promise<ClaimSet>
+decodeOIDCToken(token: string, issuer: string): Promise<JWTPayload>
+getJWKS(issuer: string): Promise<JSONWebKeySet>
+getIssuer(): string
}
OIDC --> OIDCConfig
OIDC --> ClaimSet
Loading

Class diagram for HTTP Client Proxy Handling

classDiagram
class DecodedURL {
string username
string password
string href
}
class HttpClient {
+getProxyUrl(reqUrl: URL): URL | undefined
+getAgent(url: string): any
}
HttpClient --> DecodedURL
Loading

File-Level Changes

ChangeDetailsFiles
Refactored artifact upload process
  • Updated chunk timeout logic
  • Implemented lazy stream to prevent issues with open file limits
  • Fixed a regression with symlinks not being automatically resolved
  • Improved error handling for upload progress stalling
packages/artifact/__tests__/upload-artifact.test.ts
packages/artifact/src/internal/upload/blob-upload.ts
packages/artifact/src/internal/upload/upload-zip-specification.ts
packages/artifact/src/internal/upload/zip.ts
Enhanced OIDC token handling and attestation process
  • Updated OIDC token claim validation
  • Improved handling of enterprise-specific OIDC issuers
  • Added support for custom HTTP headers in attestation requests
  • Updated SLSA provenance predicate generation
packages/attest/src/oidc.ts
packages/attest/src/provenance.ts
packages/attest/src/attest.ts
packages/attest/src/store.ts
Improved HTTP client functionality
  • Fixed handling of proxy usernames and passwords
  • Updated URL decoding for proxy authentication
  • Improved error handling for network requests
packages/http-client/src/index.ts
packages/http-client/src/proxy.ts
Updated glob package with new features
  • Added option to exclude hidden files in glob searches
  • Improved handling of symlinks in glob results
packages/glob/src/internal-glob-options.ts
packages/glob/src/internal-globber.ts
General dependency updates and security improvements
  • Updated various dependencies across packages
  • Replaced uuid package with native crypto.randomUUID()
  • Improved error messages and debugging information
packages/artifact/RELEASES.md
packages/attest/RELEASES.md
packages/core/RELEASES.md
packages/glob/RELEASES.md
packages/http-client/RELEASES.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time. You can also use
    this command to specify where the summary should be inserted.

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have skipped reviewing this pull request. It seems to have been created by a bot (hey, pull[bot]!). We assume it knows what it's doing!

tingx2wangand others added 27 commits December 5, 2025 17:13
…s/attest/tar-7.5.2
Bump tar from 7.5.1 to 7.5.2 in /packages/attest
- Update spawn-wait-for-file.js to use proper stdio inheritance
- Add small delay before exit to ensure child process inherits handles
- Simplify test code to use the helper script instead of shell commands
On Windows, detached:true is needed to properly keep stdio handles
open after the parent process exits.
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
Signed-off-by: Meredith Lancaster <malancas@github.com>
chore: fix npm audit vulnerabilities (glob, js-yaml)
Samiratand others added 30 commits May 1, 2026 17:38
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.0.1 to 10.2.0.
- [Commits](https://github.com/beaugunderson/ip-address/commits)
---
updated-dependencies:
- dependency-name: ip-address
dependency-version: 10.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…_versions
Update minor versions of cache and artifact dependencies
Bumps [fast-xml-builder](https://github.com/NaturalIntelligence/fast-xml-builder) from 1.1.5 to 1.2.0.
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-builder/blob/main/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-builder@v1.1.5...v1.2.0)
---
updated-dependencies:
- dependency-name: fast-xml-builder
dependency-version: 1.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/attest/ip-address-10.2.0
chore(deps): bump ip-address from 10.0.1 to 10.2.0 in /packages/attest
…s/attest/brace-expansion-2.0.3
chore(deps): bump brace-expansion from 2.0.2 to 2.0.3 in /packages/attest
Bumps [markdown-it](https://github.com/markdown-it/markdown-it) from 14.1.1 to 14.2.0.
- [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@14.1.1...14.2.0)
---
updated-dependencies:
- dependency-name: markdown-it
dependency-version: 14.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…TIONS_CACHE_MODE skip) (#2447)
* feat(cache): surface cache read-denied as a distinct restore warning
Mirror the existing cache write-denied handling on the restore path. When
the receiver refuses a download URL because the run's token has no readable
cache scopes, it returns a twirp PermissionDenied (HTTP 403). The twirp
client wraps that 403 in a generic Error, so the stable 'cache read denied:'
prefix is embedded in the message rather than at the start.
- Add CACHE_READ_DENIED_PREFIX and CacheReadDeniedError
- Dispatch on the prefix in the restoreCacheV2 catch block (V2 only), log a
policy-specific warning, and report a cache miss so the run continues
- Add a test mirroring the write-denied coverage
* chore(cache): trim comments, bump to 6.2.0, add RELEASES entry
* refactor(cache): dispatch read-denied by error name to mirror write path
Re-throw CacheReadDeniedError from an inner try/catch around
GetCacheEntryDownloadURL and dispatch on typedError.name in the outer catch,
matching how saveCacheV2 handles CacheWriteDeniedError.
* feat(cache): handle read-denied on the v1 restore path
Extend the read-denied handling to Cache Service v1 so GHES (which forces v1
via _apis/artifactcache) is covered when read-scope enforcement ships there.
- Surface the receiver's error body message from getCacheEntry instead of a
generic status-code error, so the cache read denied: prefix reaches callers
- Re-throw CacheReadDeniedError from restoreCacheV1 and dispatch on it in the
outer catch, mirroring restoreCacheV2 and the write-denied v1 handling
- Add a v1 read-denied test
* refactor(cache): only surface receiver body for read-denied on v1
* test(cache): assert getCacheEntry only surfaces body for read-denied
* test(cache): cover non-read-denied getCacheEntry passthrough on v1
* refactor(cache): share read-denied prefix via constants to avoid drift
* feat(cache): skip restore/save per ACTIONS_CACHE_MODE
* test(cache): expand ACTIONS_CACHE_MODE skip coverage across v1/v2 and unknown modes
* fix copilot pr feedback
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* docs(cache): remove internal reference from cache-mode comment
* test(cache): merge redundant cache-mode skip tests and simplify read-denied handling
Address PR review feedback:
- Merge the duplicate restore/save skip test.each blocks into single blocks parametrized over ACTIONS_CACHE_SERVICE_V2.
- Drop the redundant CacheReadDeniedError catch arms; the typed error is not an HttpClientError so it already falls through to a non-fatal warning.
- Clarify why read-denied classification happens both in getCacheEntry and cache.ts (dependency-free internal module cannot import the typed error).
* refactor(cache): drop redundant CacheWriteDeniedError catch arms
Mirror the read-denied simplification on the save path. CacheWriteDeniedError
is not an HttpClientError and its name does not match the ReserveCacheError
arm, so it falls through to the same non-fatal warning. Logging behavior is
unchanged (warns, never fails the run) and the exported type is still thrown
internally for consumers and tests. Also refresh stale doc wording.
* test(cache): collapse redundant restore getCacheEntry-failure tests
The two restoreCache tests exercised the identical warning + cache-miss path
now that read-denied is no longer reclassified in the catch, so merge them into
one. The read-denied prefix detection that actually branches on the message is
covered by getCacheEntry tests in cacheHttpClient.test.ts.
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* @actions/glob: extend hashFiles options
* improve hashFiles symlink handling
* Improve error handling and messaging in hashFiles function
* apply relative exclude patterns across all roots and use named minimatch import
* format error message
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.6 to 5.0.7.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.6...v5.0.7)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 5.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.10 to 7.5.22.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v7.5.10...v7.5.22)
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.22
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/glob/brace-expansion-5.0.7
chore(deps): bump brace-expansion from 5.0.6 to 5.0.7 in /packages/glob
…s/github/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/github
…s/artifact/undici-6.28.0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/artifact
…s/artifact/markdown-it-14.2.0
chore(deps): bump markdown-it from 14.1.1 to 14.2.0 in /packages/artifact
Bumps [linkify-it](https://github.com/markdown-it/linkify-it) from 5.0.1 to 5.0.2.
- [Changelog](https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/linkify-it@5.0.1...5.0.2)
---
updated-dependencies:
- dependency-name: linkify-it
dependency-version: 5.0.2
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
…s/artifact/fast-xml-builder-1.2.0
chore(deps): bump fast-xml-builder from 1.1.5 to 1.2.0 in /packages/artifact
…s/attest/tar-7.5.22
chore(deps): bump tar from 7.5.10 to 7.5.22 in /packages/attest
…s/artifact/linkify-it-5.0.2
chore(deps): bump linkify-it from 5.0.1 to 5.0.2 in /packages/artifact
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 2.1.0 to 2.1.4.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v2.1.0...v2.1.4)
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 2.1.4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
#2463)
Bumps [undici](https://github.com/nodejs/undici) from 6.23.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.23.0...v6.28.0)
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…2330)
Bumps [minimatch](https://github.com/isaacs/minimatch) from 9.0.5 to 9.0.9.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v9.0.5...v9.0.9)
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 9.0.9
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@dwisiswant0@Anytar888@joe345-str@tteo38472@tingx2wang@salmanmkc@malancas@bdehamer@TingluoHuang@GhadimiR@lokesh755@danwkennedy@zaataylor@Link-@shogo82148@aiqiaoy@Samirat@jasongin@philip-gai