fix command escaping - #302

Merged
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command
Jan 19, 2020
Merged

fix command escaping#302
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command

Conversation

@ericsciple

Copy link
Copy Markdown
Contributor

fixes#301

@ericsciple

Copy link
Copy Markdown
ContributorAuthor

also related to actions/runner#267

tjamet added a commit to actions-go/toolkit that referenced this pull request Jan 17, 2020
There is a fix in actions toolkit: actions/toolkit#302, apply it here as well
// safely append the val - avoid blowing up when attempting to
// call .replace() if message is not a string for some reason
cmdStr += `${key}=${escape(`${val || ''}`)}`
cmdStr += `${key}=${escapeProperty(val)}`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was reading it and thinking that eventually, the function being exported, it is diable for users to run issueCommand('some-command', {'key,1': 'value'}, 'message') that would break the ::name key1=value1,key2=value2::message formatting. would it be something worth taking into account?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is a limitation of the command format - defined by the runner - that commas are not allowed within a key name.

Today this limitation does not present a problem. All commands (and keys) are first party - not extensible.

We can relax this constraint in the future needed. But not required for any current scenarios.

@ericsciple
ericsciple merged commit 8b03001 into masterJan 19, 2020
@ericsciple
ericsciple deleted the users/ericsciple/m164command branch January 19, 2020 04:52
shogo82148 added a commit to shogo82148/go-actions-toolkit that referenced this pull request Oct 3, 2020
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix command escaping to match runner

3 participants

@ericsciple@TingluoHuang@tjamet
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix command escaping - #302

Merged
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command
Jan 19, 2020
Merged

fix command escaping#302
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command

Conversation

@ericsciple

Copy link
Copy Markdown
Contributor

fixes#301

@ericsciple

Copy link
Copy Markdown
ContributorAuthor

also related to actions/runner#267

tjamet added a commit to actions-go/toolkit that referenced this pull request Jan 17, 2020
There is a fix in actions toolkit: actions/toolkit#302, apply it here as well
// safely append the val - avoid blowing up when attempting to
// call .replace() if message is not a string for some reason
cmdStr += `${key}=${escape(`${val || ''}`)}`
cmdStr += `${key}=${escapeProperty(val)}`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was reading it and thinking that eventually, the function being exported, it is diable for users to run issueCommand('some-command', {'key,1': 'value'}, 'message') that would break the ::name key1=value1,key2=value2::message formatting. would it be something worth taking into account?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is a limitation of the command format - defined by the runner - that commas are not allowed within a key name.

Today this limitation does not present a problem. All commands (and keys) are first party - not extensible.

We can relax this constraint in the future needed. But not required for any current scenarios.

@ericsciple
ericsciple merged commit 8b03001 into masterJan 19, 2020
@ericsciple
ericsciple deleted the users/ericsciple/m164command branch January 19, 2020 04:52
shogo82148 added a commit to shogo82148/go-actions-toolkit that referenced this pull request Oct 3, 2020
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix command escaping to match runner

3 participants

@ericsciple@TingluoHuang@tjamet
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix command escaping - #302

Merged
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command
Jan 19, 2020
Merged

fix command escaping#302
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command

Conversation

@ericsciple

Copy link
Copy Markdown
Contributor

fixes#301

@ericsciple

Copy link
Copy Markdown
ContributorAuthor

also related to actions/runner#267

tjamet added a commit to actions-go/toolkit that referenced this pull request Jan 17, 2020
There is a fix in actions toolkit: actions/toolkit#302, apply it here as well
// safely append the val - avoid blowing up when attempting to
// call .replace() if message is not a string for some reason
cmdStr += `${key}=${escape(`${val || ''}`)}`
cmdStr += `${key}=${escapeProperty(val)}`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was reading it and thinking that eventually, the function being exported, it is diable for users to run issueCommand('some-command', {'key,1': 'value'}, 'message') that would break the ::name key1=value1,key2=value2::message formatting. would it be something worth taking into account?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is a limitation of the command format - defined by the runner - that commas are not allowed within a key name.

Today this limitation does not present a problem. All commands (and keys) are first party - not extensible.

We can relax this constraint in the future needed. But not required for any current scenarios.

@ericsciple
ericsciple merged commit 8b03001 into masterJan 19, 2020
@ericsciple
ericsciple deleted the users/ericsciple/m164command branch January 19, 2020 04:52
shogo82148 added a commit to shogo82148/go-actions-toolkit that referenced this pull request Oct 3, 2020
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix command escaping to match runner

3 participants

@ericsciple@TingluoHuang@tjamet
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix command escaping - #302

Merged
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command
Jan 19, 2020
Merged

fix command escaping#302
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command

Conversation

@ericsciple

Copy link
Copy Markdown
Contributor

fixes#301

@ericsciple

Copy link
Copy Markdown
ContributorAuthor

also related to actions/runner#267

tjamet added a commit to actions-go/toolkit that referenced this pull request Jan 17, 2020
There is a fix in actions toolkit: actions/toolkit#302, apply it here as well
// safely append the val - avoid blowing up when attempting to
// call .replace() if message is not a string for some reason
cmdStr += `${key}=${escape(`${val || ''}`)}`
cmdStr += `${key}=${escapeProperty(val)}`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was reading it and thinking that eventually, the function being exported, it is diable for users to run issueCommand('some-command', {'key,1': 'value'}, 'message') that would break the ::name key1=value1,key2=value2::message formatting. would it be something worth taking into account?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is a limitation of the command format - defined by the runner - that commas are not allowed within a key name.

Today this limitation does not present a problem. All commands (and keys) are first party - not extensible.

We can relax this constraint in the future needed. But not required for any current scenarios.

@ericsciple
ericsciple merged commit 8b03001 into masterJan 19, 2020
@ericsciple
ericsciple deleted the users/ericsciple/m164command branch January 19, 2020 04:52
shogo82148 added a commit to shogo82148/go-actions-toolkit that referenced this pull request Oct 3, 2020
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix command escaping to match runner

3 participants

@ericsciple@TingluoHuang@tjamet
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix command escaping - #302

Merged
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command
Jan 19, 2020
Merged

fix command escaping#302
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command

Conversation

@ericsciple

Copy link
Copy Markdown
Contributor

fixes#301

@ericsciple

Copy link
Copy Markdown
ContributorAuthor

also related to actions/runner#267

tjamet added a commit to actions-go/toolkit that referenced this pull request Jan 17, 2020
There is a fix in actions toolkit: actions/toolkit#302, apply it here as well
// safely append the val - avoid blowing up when attempting to
// call .replace() if message is not a string for some reason
cmdStr += `${key}=${escape(`${val || ''}`)}`
cmdStr += `${key}=${escapeProperty(val)}`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was reading it and thinking that eventually, the function being exported, it is diable for users to run issueCommand('some-command', {'key,1': 'value'}, 'message') that would break the ::name key1=value1,key2=value2::message formatting. would it be something worth taking into account?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is a limitation of the command format - defined by the runner - that commas are not allowed within a key name.

Today this limitation does not present a problem. All commands (and keys) are first party - not extensible.

We can relax this constraint in the future needed. But not required for any current scenarios.

@ericsciple
ericsciple merged commit 8b03001 into masterJan 19, 2020
@ericsciple
ericsciple deleted the users/ericsciple/m164command branch January 19, 2020 04:52
shogo82148 added a commit to shogo82148/go-actions-toolkit that referenced this pull request Oct 3, 2020
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix command escaping to match runner

3 participants

@ericsciple@TingluoHuang@tjamet
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix command escaping - #302

Merged
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command
Jan 19, 2020
Merged

fix command escaping#302
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command

Conversation

@ericsciple

Copy link
Copy Markdown
Contributor

fixes#301

@ericsciple

Copy link
Copy Markdown
ContributorAuthor

also related to actions/runner#267

tjamet added a commit to actions-go/toolkit that referenced this pull request Jan 17, 2020
There is a fix in actions toolkit: actions/toolkit#302, apply it here as well
// safely append the val - avoid blowing up when attempting to
// call .replace() if message is not a string for some reason
cmdStr += `${key}=${escape(`${val || ''}`)}`
cmdStr += `${key}=${escapeProperty(val)}`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was reading it and thinking that eventually, the function being exported, it is diable for users to run issueCommand('some-command', {'key,1': 'value'}, 'message') that would break the ::name key1=value1,key2=value2::message formatting. would it be something worth taking into account?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is a limitation of the command format - defined by the runner - that commas are not allowed within a key name.

Today this limitation does not present a problem. All commands (and keys) are first party - not extensible.

We can relax this constraint in the future needed. But not required for any current scenarios.

@ericsciple
ericsciple merged commit 8b03001 into masterJan 19, 2020
@ericsciple
ericsciple deleted the users/ericsciple/m164command branch January 19, 2020 04:52
shogo82148 added a commit to shogo82148/go-actions-toolkit that referenced this pull request Oct 3, 2020
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix command escaping to match runner

3 participants

@ericsciple@TingluoHuang@tjamet
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix command escaping - #302

Merged
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command
Jan 19, 2020
Merged

fix command escaping#302
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command

Conversation

@ericsciple

Copy link
Copy Markdown
Contributor

fixes#301

@ericsciple

Copy link
Copy Markdown
ContributorAuthor

also related to actions/runner#267

tjamet added a commit to actions-go/toolkit that referenced this pull request Jan 17, 2020
There is a fix in actions toolkit: actions/toolkit#302, apply it here as well
// safely append the val - avoid blowing up when attempting to
// call .replace() if message is not a string for some reason
cmdStr += `${key}=${escape(`${val || ''}`)}`
cmdStr += `${key}=${escapeProperty(val)}`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was reading it and thinking that eventually, the function being exported, it is diable for users to run issueCommand('some-command', {'key,1': 'value'}, 'message') that would break the ::name key1=value1,key2=value2::message formatting. would it be something worth taking into account?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is a limitation of the command format - defined by the runner - that commas are not allowed within a key name.

Today this limitation does not present a problem. All commands (and keys) are first party - not extensible.

We can relax this constraint in the future needed. But not required for any current scenarios.

@ericsciple
ericsciple merged commit 8b03001 into masterJan 19, 2020
@ericsciple
ericsciple deleted the users/ericsciple/m164command branch January 19, 2020 04:52
shogo82148 added a commit to shogo82148/go-actions-toolkit that referenced this pull request Oct 3, 2020
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix command escaping to match runner

3 participants

@ericsciple@TingluoHuang@tjamet
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix command escaping - #302

Merged
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command
Jan 19, 2020
Merged

fix command escaping#302
ericsciple merged 1 commit into
masterfrom
users/ericsciple/m164command

Conversation

@ericsciple

Copy link
Copy Markdown
Contributor

fixes#301

@ericsciple

Copy link
Copy Markdown
ContributorAuthor

also related to actions/runner#267

tjamet added a commit to actions-go/toolkit that referenced this pull request Jan 17, 2020
There is a fix in actions toolkit: actions/toolkit#302, apply it here as well
// safely append the val - avoid blowing up when attempting to
// call .replace() if message is not a string for some reason
cmdStr += `${key}=${escape(`${val || ''}`)}`
cmdStr += `${key}=${escapeProperty(val)}`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was reading it and thinking that eventually, the function being exported, it is diable for users to run issueCommand('some-command', {'key,1': 'value'}, 'message') that would break the ::name key1=value1,key2=value2::message formatting. would it be something worth taking into account?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is a limitation of the command format - defined by the runner - that commas are not allowed within a key name.

Today this limitation does not present a problem. All commands (and keys) are first party - not extensible.

We can relax this constraint in the future needed. But not required for any current scenarios.

@ericsciple
ericsciple merged commit 8b03001 into masterJan 19, 2020
@ericsciple
ericsciple deleted the users/ericsciple/m164command branch January 19, 2020 04:52
shogo82148 added a commit to shogo82148/go-actions-toolkit that referenced this pull request Oct 3, 2020
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix command escaping to match runner

3 participants

@ericsciple@TingluoHuang@tjamet