mirror of
https://github.com/actions/setup-java.git
synced 2026-10-02 09:06:05 +03:00
* Fix import-safe checks when scripts are run from a path with symlinks In v6, setup-java was made "import-safe" to facilitate testing. This prevents setup-java & cleanup-java from doing anything when their sources get imported. This works fine in the general case, but actually invoking the script (`node setup-java/index.js`) when the path to the script contains symlinks led to the script incorrectly believing it was imported, and refuse to actually run. To fix this, we pass `process.argv[1]` through `fs.realpathSync`, which resolves symlinks in the path. Fixes #1264 * Preserve import safety when resolving symlink entrypoints Share entrypoint detection between setup and cleanup, handle non-file entrypoints safely, and normalize both paths for preserved symlinks. Add real-process regression coverage and rebuild action bundles. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 831c32f2-a275-45bd-a92b-c387372a1554 * Update js-yaml to fix merge-source denial of service Bump the transitive development dependency from 3.15.1 to 3.15.2 to address GHSA-2883-xcg3-v3hh without changing dependency ranges or CI checks. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 831c32f2-a275-45bd-a92b-c387372a1554 --------- Co-authored-by: Bruno Borges <brborges@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 831c32f2-a275-45bd-a92b-c387372a1554
86 lines
2.3 KiB
TypeScript
86 lines
2.3 KiB
TypeScript
import * as core from '@actions/core';
|
|
import * as gpg from './gpg.js';
|
|
import * as constants from './constants.js';
|
|
import {
|
|
getBooleanInput,
|
|
isJdkCacheEnabled,
|
|
isJobStatusSuccess
|
|
} from './util.js';
|
|
import {isMainModule} from './is-main-module.js';
|
|
|
|
async function removeGpgHome() {
|
|
const gpgHome = core.getState(constants.STATE_GPG_HOME);
|
|
if (!gpgHome) {
|
|
return;
|
|
}
|
|
|
|
core.info('Removing private key from isolated GPG home');
|
|
try {
|
|
await gpg.removeGpgHome(gpgHome);
|
|
} catch (error) {
|
|
core.setFailed(
|
|
`Failed to remove isolated GPG home due to: ${(error as Error).message}`
|
|
);
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Check given input and run a save process for the specified package manager
|
|
* @returns Promise that will be resolved when the save process finishes
|
|
*/
|
|
async function saveCaches() {
|
|
const jobStatus = isJobStatusSuccess();
|
|
const cache = core.getInput(constants.INPUT_CACHE);
|
|
const cacheJdk = isJdkCacheEnabled(cache);
|
|
if (!jobStatus || (!cache && !cacheJdk)) {
|
|
return;
|
|
}
|
|
|
|
if (getBooleanInput(constants.INPUT_CACHE_READ_ONLY, false)) {
|
|
core.info('Cache saving is skipped because cache-read-only is enabled.');
|
|
return;
|
|
}
|
|
|
|
const saves: Promise<void>[] = [];
|
|
if (cache) {
|
|
const {save} = await import('./cache.js');
|
|
saves.push(save(cache));
|
|
}
|
|
if (cacheJdk) {
|
|
const {saveJdkCaches} = await import('./jdk-cache.js');
|
|
const {saveJdkResolutionCaches} = await import('./jdk-resolution-cache.js');
|
|
saves.push(saveJdkCaches());
|
|
saves.push(saveJdkResolutionCaches());
|
|
}
|
|
await Promise.all(saves);
|
|
}
|
|
|
|
/**
|
|
* The save process is best-effort, and it should not make the workflow fail
|
|
* even though this process throws an error.
|
|
* @param promise the promise to ignore error from
|
|
* @returns Promise that will ignore error reported by the given promise
|
|
*/
|
|
async function ignoreError(promise: Promise<void>) {
|
|
return new Promise(resolve => {
|
|
promise
|
|
.catch(error => {
|
|
core.warning(error);
|
|
resolve(void 0);
|
|
})
|
|
.then(resolve);
|
|
});
|
|
}
|
|
|
|
export async function run() {
|
|
await removeGpgHome();
|
|
await ignoreError(saveCaches());
|
|
}
|
|
|
|
if (isMainModule(import.meta.url)) {
|
|
run();
|
|
} else {
|
|
// https://nodejs.org/api/modules.html#modules_accessing_the_main_module
|
|
core.info('the script is loaded as a module, so skipping the execution');
|
|
}
|