Compare commits

..
Author SHA1 Message Date
Brian DeHamer 700b0a9962 wip
Signed-off-by: Brian DeHamer <[email protected]>
2025-02-13 08:47:10 -08:00
Brian DeHamer f41311b4cd bump undici from 5.28.4 to 5.28.5
Signed-off-by: Brian DeHamer <[email protected]>
2025-01-27 14:44:37 -08:00
16 changed files with 6191 additions and 8785 deletions
+1 -7
View File
@@ -1,7 +1,6 @@
import eslint from '@eslint/js' import eslint from '@eslint/js'
import importplugin from 'eslint-plugin-import' import importplugin from 'eslint-plugin-import'
import jestplugin from 'eslint-plugin-jest' import jestplugin from 'eslint-plugin-jest'
import path from 'node:path'
import tseslint from 'typescript-eslint' import tseslint from 'typescript-eslint'
export default tseslint.config( export default tseslint.config(
@@ -22,12 +21,7 @@ export default tseslint.config(
languageOptions: { languageOptions: {
ecmaVersion: 2023, ecmaVersion: 2023,
parserOptions: { parserOptions: {
project: [ project: ['./.github/linters/tsconfig.json', './tsconfig.json']
path.resolve(
path.dirname(new URL(import.meta.url).pathname),
'./tsconfig.json'
)
]
} }
}, },
rules: { rules: {
+1 -1
View File
@@ -28,7 +28,7 @@ jobs:
steps: steps:
- name: Checkout - name: Checkout
id: checkout id: checkout
uses: actions/checkout@v5 uses: actions/checkout@v4
- name: Setup Node.js - name: Setup Node.js
id: setup-node id: setup-node
+2 -2
View File
@@ -21,7 +21,7 @@ jobs:
steps: steps:
- name: Checkout - name: Checkout
id: checkout id: checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
- name: Setup Node.js - name: Setup Node.js
id: setup-node id: setup-node
@@ -58,7 +58,7 @@ jobs:
steps: steps:
- name: Checkout - name: Checkout
id: checkout id: checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
- name: Calculate subject digest - name: Calculate subject digest
id: subject id: subject
env: env:
+1 -1
View File
@@ -32,7 +32,7 @@ jobs:
steps: steps:
- name: Checkout - name: Checkout
id: checkout id: checkout
uses: actions/checkout@v5 uses: actions/checkout@v4
- name: Initialize CodeQL - name: Initialize CodeQL
id: initialize id: initialize
+2 -6
View File
@@ -21,7 +21,7 @@ jobs:
steps: steps:
- name: Checkout - name: Checkout
id: checkout id: checkout
uses: actions/checkout@v5 uses: actions/checkout@v4
with: with:
fetch-depth: 0 fetch-depth: 0
@@ -38,7 +38,7 @@ jobs:
- name: Lint Codebase - name: Lint Codebase
id: super-linter id: super-linter
uses: super-linter/super-linter/slim@v8.0.0 uses: super-linter/super-linter/slim@v7
env: env:
DEFAULT_BRANCH: main DEFAULT_BRANCH: main
FILTER_REGEX_EXCLUDE: dist/**/* FILTER_REGEX_EXCLUDE: dist/**/*
@@ -47,8 +47,4 @@ jobs:
VALIDATE_ALL_CODEBASE: true VALIDATE_ALL_CODEBASE: true
VALIDATE_JAVASCRIPT_STANDARD: false VALIDATE_JAVASCRIPT_STANDARD: false
VALIDATE_TYPESCRIPT_STANDARD: false VALIDATE_TYPESCRIPT_STANDARD: false
VALIDATE_TYPESCRIPT_ES: false
VALIDATE_JSCPD: false VALIDATE_JSCPD: false
- name: Run eslint
run: npm run lint:eslint
@@ -16,7 +16,7 @@ jobs:
steps: steps:
- name: Checking out - name: Checking out
uses: actions/checkout@v5 uses: actions/checkout@v4
- name: Publish - name: Publish
id: publish id: publish
uses: actions/[email protected] uses: actions/[email protected]
+1 -7
View File
@@ -18,12 +18,6 @@ Once the attestation has been created and signed, it will be uploaded to the GH
attestations API and associated with the repository from which the workflow was attestations API and associated with the repository from which the workflow was
initiated. initiated.
When an attestation is created, the attestation is stored on the local
filesystem used by the runner. For each attestation created, the filesystem path
will be appended to the file `${RUNNER_TEMP}/created_attestation_paths.txt`.
This can be used to gather all attestations created by all jobs during a the
workflow.
Attestations can be verified using the [`attestation` command in the GitHub Attestations can be verified using the [`attestation` command in the GitHub
CLI][5]. CLI][5].
@@ -71,7 +65,7 @@ attest:
The `subject-path` parameter should identify the artifact for which you want The `subject-path` parameter should identify the artifact for which you want
to generate an attestation. The `predicate-type` can be any of the the to generate an attestation. The `predicate-type` can be any of the the
[vetted predicate types][3] or a custom value. The `predicate-path` [vetted predicate types][3] or a custom value. The `predicate-path`
identifies a file containing the JSON-encoded predicate parameters. identifies a file containg the JSON-encoded predicate parameters.
### Inputs ### Inputs
+1 -1
View File
@@ -99,7 +99,7 @@ describe('subjectFromInputs', () => {
}) })
}) })
describe('when the algorithm is not supported', () => { describe('when the alogrithm is not supported', () => {
it('throws an error', async () => { it('throws an error', async () => {
const inputs: SubjectInputs = { const inputs: SubjectInputs = {
...blankInputs, ...blankInputs,
+1 -1
View File
@@ -73,5 +73,5 @@ outputs:
description: 'The URL for the attestation summary.' description: 'The URL for the attestation summary.'
runs: runs:
using: node24 using: node20
main: ./dist/index.js main: ./dist/index.js
Generated Vendored
+2528 -3318
View File
File diff suppressed because it is too large Load Diff
+3610 -5389
View File
File diff suppressed because it is too large Load Diff
+18 -18
View File
@@ -1,7 +1,7 @@
{ {
"name": "actions/attest", "name": "actions/attest",
"description": "Generate signed attestations for workflow artifacts", "description": "Generate signed attestations for workflow artifacts",
"version": "2.4.0", "version": "2.2.0",
"author": "", "author": "",
"private": true, "private": true,
"homepage": "https://github.com/actions/attest", "homepage": "https://github.com/actions/attest",
@@ -69,31 +69,31 @@
] ]
}, },
"dependencies": { "dependencies": {
"@actions/attest": "^1.6.0", "@actions/attest": "^1.5.0",
"@actions/core": "^1.11.1", "@actions/core": "^1.11.1",
"@actions/github": "^6.0.1", "@actions/github": "^6.0.0",
"@actions/glob": "^0.5.0", "@actions/glob": "^0.5.0",
"@sigstore/oci": "^0.6.0", "@sigstore/oci": "^0.4.0",
"csv-parse": "^5.6.0" "csv-parse": "^5.6.0"
}, },
"devDependencies": { "devDependencies": {
"@eslint/js": "^9.33.0", "@eslint/js": "^9.19.0",
"@sigstore/mock": "^0.11.0", "@sigstore/mock": "^0.9.0",
"@types/jest": "^30.0.0", "@types/jest": "^29.5.14",
"@types/make-fetch-happen": "^10.0.4", "@types/make-fetch-happen": "^10.0.4",
"@types/node": "^24.2.1", "@types/node": "^22.10.10",
"@vercel/ncc": "^0.38.3", "@vercel/ncc": "^0.38.3",
"eslint": "^9.33.0", "eslint": "^9.19.0",
"eslint-plugin-import": "^2.32.0", "eslint-plugin-import": "^2.31.0",
"eslint-plugin-jest": "^29.0.1", "eslint-plugin-jest": "^28.11.0",
"jest": "^30.0.5", "jest": "^29.7.0",
"js-yaml": "^4.1.0", "js-yaml": "^4.1.0",
"markdownlint-cli": "^0.45.0", "markdownlint-cli": "^0.44.0",
"nock": "^13.5.6", "nock": "^13.5.6",
"prettier": "^3.6.2", "prettier": "^3.4.2",
"ts-jest": "^29.4.1", "ts-jest": "^29.2.5",
"typescript": "^5.9.2", "typescript": "^5.7.3",
"typescript-eslint": "^8.39.1", "typescript-eslint": "^8.22.0",
"undici": "^5.29.0" "undici": "^5.28.5"
} }
} }
+4 -1
View File
@@ -25,9 +25,12 @@ export const createAttestation = async (
predicateType: predicate.type, predicateType: predicate.type,
predicate: predicate.params, predicate: predicate.params,
sigstore: opts.sigstoreInstance, sigstore: opts.sigstoreInstance,
token: opts.githubToken token: opts.githubToken,
skipWrite: true
}) })
console.log(JSON.stringify(attestation.bundle))
const result: AttestResult = attestation const result: AttestResult = attestation
if (subjects.length === 1 && opts.pushToRegistry) { if (subjects.length === 1 && opts.pushToRegistry) {
-20
View File
@@ -16,7 +16,6 @@ import {
import type { Subject } from '@actions/attest' import type { Subject } from '@actions/attest'
const ATTESTATION_FILE_NAME = 'attestation.json' const ATTESTATION_FILE_NAME = 'attestation.json'
const ATTESTATION_PATHS_FILE_NAME = 'created_attestation_paths.txt'
export type RunInputs = SubjectInputs & export type RunInputs = SubjectInputs &
PredicateInputs & { PredicateInputs & {
@@ -80,28 +79,11 @@ export async function run(inputs: RunInputs): Promise<void> {
flag: 'a' flag: 'a'
}) })
const baseDir = process.env.RUNNER_TEMP
/* istanbul ignore else */
if (baseDir) {
const outputSummaryPath = path.join(baseDir, ATTESTATION_PATHS_FILE_NAME)
// Append the output path to the attestations paths file
fs.appendFileSync(outputSummaryPath, outputPath + os.EOL, {
encoding: 'utf-8',
flag: 'a'
})
} else {
core.warning(
'RUNNER_TEMP environment variable is not set. Cannot write attestation paths file.'
)
}
/* istanbul ignore else */
if (att.attestationID) { if (att.attestationID) {
core.setOutput('attestation-id', att.attestationID) core.setOutput('attestation-id', att.attestationID)
core.setOutput('attestation-url', attestationURL(att.attestationID)) core.setOutput('attestation-url', attestationURL(att.attestationID))
} }
/* istanbul ignore else */
if (inputs.showSummary) { if (inputs.showSummary) {
await logSummary(att) await logSummary(att)
} }
@@ -159,7 +141,6 @@ const logAttestation = (
core.info(`${SEARCH_PUBLIC_GOOD_URL}?logIndex=${attestation.tlogID}`) core.info(`${SEARCH_PUBLIC_GOOD_URL}?logIndex=${attestation.tlogID}`)
} }
/* istanbul ignore else */
if (attestation.attestationID) { if (attestation.attestationID) {
core.info(style.highlight('Attestation uploaded to repository')) core.info(style.highlight('Attestation uploaded to repository'))
core.info(attestationURL(attestation.attestationID)) core.info(attestationURL(attestation.attestationID))
@@ -175,7 +156,6 @@ const logAttestation = (
const logSummary = async (attestation: AttestResult): Promise<void> => { const logSummary = async (attestation: AttestResult): Promise<void> => {
const { attestationID } = attestation const { attestationID } = attestation
/* istanbul ignore else */
if (attestationID) { if (attestationID) {
const url = attestationURL(attestationID) const url = attestationURL(attestationID)
core.summary.addHeading('Attestation Created', 3) core.summary.addHeading('Attestation Created', 3)
+9
View File
@@ -189,11 +189,18 @@ const getSubjectFromChecksumsString = (checksums: string): Subject[] => {
throw new Error(`Invalid digest: ${digest}`) throw new Error(`Invalid digest: ${digest}`)
} }
if (digestAlgorithm(digest) === 'sha1') {
subjects.push({
uri: name,
digest: { [digestAlgorithm(digest)]: digest }
} as any)
} else {
subjects.push({ subjects.push({
name, name,
digest: { [digestAlgorithm(digest)]: digest } digest: { [digestAlgorithm(digest)]: digest }
}) })
} }
}
return subjects return subjects
} }
@@ -233,6 +240,8 @@ const parseSubjectPathList = (input: string): string[] => {
const digestAlgorithm = (digest: string): string => { const digestAlgorithm = (digest: string): string => {
switch (digest.length) { switch (digest.length) {
case 40:
return 'sha1'
case 64: case 64:
return 'sha256' return 'sha256'
case 128: case 128:
-1
View File
@@ -5,7 +5,6 @@
"module": "NodeNext", "module": "NodeNext",
"rootDir": "./src", "rootDir": "./src",
"moduleResolution": "NodeNext", "moduleResolution": "NodeNext",
"isolatedModules": true,
"baseUrl": "./", "baseUrl": "./",
"sourceMap": true, "sourceMap": true,
"outDir": "./dist", "outDir": "./dist",