Merge branch 'main' into fix/comment-warn-only
This commit is contained in:
@@ -15,9 +15,12 @@ jobs:
|
|||||||
- uses: actions/[email protected]
|
- uses: actions/[email protected]
|
||||||
name: Clean up stale PRs and Issues
|
name: Clean up stale PRs and Issues
|
||||||
with:
|
with:
|
||||||
stale-pr-message: "👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the `Keep` label to hold stale off permanently, or do nothing. If you do nothing, this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details."
|
stale-pr-message: "👋 This pull request has been marked as stale because it has been open with no activity for 180 days. You can: comment on the PR or remove the stale label to hold stalebot off for a while, add the `Keep` label to hold stale off permanently, or do nothing. If you do nothing, this pull request will be closed eventually by the stalebot. Please see CONTRIBUTING.md for more policy details."
|
||||||
stale-pr-label: "Stale"
|
stale-pr-label: "Stale"
|
||||||
|
close-pr-message: "👋 This pull request has been closed by stalebot because it has been open with no activity for over 180 days. Please see CONTRIBUTING.md for more policy details."
|
||||||
stale-issue-label: "Stale"
|
stale-issue-label: "Stale"
|
||||||
|
stale-issue-message: "👋 This issue has been marked as stale because it has been open with no activity for 180 days. You can: comment on the issue or remove the stale label to hold stalebot off for a while, add the `Keep` label to hold stale off permanently, or do nothing. If you do nothing, this issue will be closed eventually by the stalebot. Please see CONTRIBUTING.md for more policy details."
|
||||||
|
close-issue-message: "👋 This issue has been closed by stalebot because it has been open with no activity for over 180 days. Please see CONTRIBUTING.md for more policy details."
|
||||||
exempt-pr-labels: "Keep" # a "Keep" label will keep the PR from being closed as stale
|
exempt-pr-labels: "Keep" # a "Keep" label will keep the PR from being closed as stale
|
||||||
exempt-issue-labels: "Keep" # a "Keep" label will keep the issue from being closed as stale
|
exempt-issue-labels: "Keep" # a "Keep" label will keep the issue from being closed as stale
|
||||||
days-before-pr-stale: 180 # when the PR is considered stale
|
days-before-pr-stale: 180 # when the PR is considered stale
|
||||||
|
|||||||
@@ -124,11 +124,7 @@ test('it raises an error when no refs are provided and the event is not a pull r
|
|||||||
).toThrow()
|
).toThrow()
|
||||||
})
|
})
|
||||||
|
|
||||||
const pullRequestLikeEvents = [
|
const pullRequestLikeEvents = ['pull_request', 'pull_request_target']
|
||||||
'pull_request',
|
|
||||||
'pull_request_target',
|
|
||||||
'merge_group'
|
|
||||||
]
|
|
||||||
|
|
||||||
test.each(pullRequestLikeEvents)(
|
test.each(pullRequestLikeEvents)(
|
||||||
'it uses the given refs even when the event is %s',
|
'it uses the given refs even when the event is %s',
|
||||||
@@ -152,7 +148,7 @@ test.each(pullRequestLikeEvents)(
|
|||||||
)
|
)
|
||||||
|
|
||||||
test.each(pullRequestLikeEvents)(
|
test.each(pullRequestLikeEvents)(
|
||||||
'it uses the event refs when the event is %s and the no refs are input',
|
'it uses the event refs when the event is %s and no refs are provided in config',
|
||||||
async eventName => {
|
async eventName => {
|
||||||
const refs = getRefs(await readConfig(), {
|
const refs = getRefs(await readConfig(), {
|
||||||
payload: {
|
payload: {
|
||||||
@@ -169,6 +165,37 @@ test.each(pullRequestLikeEvents)(
|
|||||||
}
|
}
|
||||||
)
|
)
|
||||||
|
|
||||||
|
test('it uses the given refs even when the event is merge_group', async () => {
|
||||||
|
setInput('base-ref', 'a-custom-base-ref')
|
||||||
|
setInput('head-ref', 'a-custom-head-ref')
|
||||||
|
|
||||||
|
const refs = getRefs(await readConfig(), {
|
||||||
|
payload: {
|
||||||
|
merge_group: {
|
||||||
|
base_sha: 'pr-base-ref',
|
||||||
|
head_sha: 'pr-head-ref'
|
||||||
|
}
|
||||||
|
},
|
||||||
|
eventName: 'merge_group'
|
||||||
|
})
|
||||||
|
expect(refs.base).toEqual('a-custom-base-ref')
|
||||||
|
expect(refs.head).toEqual('a-custom-head-ref')
|
||||||
|
})
|
||||||
|
|
||||||
|
test('it uses the event refs when the event is merge_group and no refs are provided in config', async () => {
|
||||||
|
const refs = getRefs(await readConfig(), {
|
||||||
|
payload: {
|
||||||
|
merge_group: {
|
||||||
|
base_sha: 'pr-base-ref',
|
||||||
|
head_sha: 'pr-head-ref'
|
||||||
|
}
|
||||||
|
},
|
||||||
|
eventName: 'merge_group'
|
||||||
|
})
|
||||||
|
expect(refs.base).toEqual('pr-base-ref')
|
||||||
|
expect(refs.head).toEqual('pr-head-ref')
|
||||||
|
})
|
||||||
|
|
||||||
test('it defaults to runtime scope', async () => {
|
test('it defaults to runtime scope', async () => {
|
||||||
const config = await readConfig()
|
const config = await readConfig()
|
||||||
expect(config.fail_on_scopes).toEqual(['runtime'])
|
expect(config.fail_on_scopes).toEqual(['runtime'])
|
||||||
|
|||||||
@@ -109,42 +109,6 @@ test('prints headline as h1', () => {
|
|||||||
expect(text).toContain('<h1>Dependency Review</h1>')
|
expect(text).toContain('<h1>Dependency Review</h1>')
|
||||||
})
|
})
|
||||||
|
|
||||||
test('returns minimal summary in case the core.summary is too large for a PR comment', () => {
|
|
||||||
let changes: Changes = [
|
|
||||||
createTestChange({name: 'lodash', version: '1.2.3'}),
|
|
||||||
createTestChange({name: 'colors', version: '2.3.4'}),
|
|
||||||
createTestChange({name: '@foo/bar', version: '*'})
|
|
||||||
]
|
|
||||||
|
|
||||||
let minSummary: string = summary.addSummaryToSummary(
|
|
||||||
changes,
|
|
||||||
emptyInvalidLicenseChanges,
|
|
||||||
emptyChanges,
|
|
||||||
scorecard,
|
|
||||||
defaultConfig
|
|
||||||
)
|
|
||||||
|
|
||||||
// side effect DR report into core.summary as happens in main.ts
|
|
||||||
summary.addScannedDependencies(changes)
|
|
||||||
const text = core.summary.stringify()
|
|
||||||
|
|
||||||
expect(text).toContain('<h1>Dependency Review</h1>')
|
|
||||||
expect(minSummary).toContain('# Dependency Review')
|
|
||||||
|
|
||||||
expect(text).toContain('❌ 3 vulnerable package(s)')
|
|
||||||
expect(text).not.toContain('* ❌ 3 vulnerable package(s)')
|
|
||||||
expect(text).toContain('lodash')
|
|
||||||
expect(text).toContain('colors')
|
|
||||||
expect(text).toContain('@foo/bar')
|
|
||||||
|
|
||||||
expect(minSummary).toContain('* ❌ 3 vulnerable package(s)')
|
|
||||||
expect(minSummary).not.toContain('lodash')
|
|
||||||
expect(minSummary).not.toContain('colors')
|
|
||||||
expect(minSummary).not.toContain('@foo/bar')
|
|
||||||
|
|
||||||
expect(text.length).toBeGreaterThan(minSummary.length)
|
|
||||||
})
|
|
||||||
|
|
||||||
test('returns minimal summary formatted for posting as a PR comment', () => {
|
test('returns minimal summary formatted for posting as a PR comment', () => {
|
||||||
const OLD_ENV = process.env
|
const OLD_ENV = process.env
|
||||||
|
|
||||||
@@ -232,14 +196,10 @@ test('groups dependencies with empty manifest paths together', () => {
|
|||||||
emptyScorecard,
|
emptyScorecard,
|
||||||
defaultConfig
|
defaultConfig
|
||||||
)
|
)
|
||||||
summary.addScannedDependencies(changesWithEmptyManifests)
|
summary.addScannedFiles(changesWithEmptyManifests)
|
||||||
const text = core.summary.stringify()
|
const text = core.summary.stringify()
|
||||||
|
expect(text).toContain('Unnamed Manifest')
|
||||||
expect(text).toContain('<summary>Unnamed Manifest</summary>')
|
expect(text).toContain('python/dist-info/METADATA')
|
||||||
expect(text).toContain('castore')
|
|
||||||
expect(text).toContain('connection')
|
|
||||||
expect(text).toContain('<summary>python/dist-info/METADATA</summary>')
|
|
||||||
expect(text).toContain('pygments')
|
|
||||||
})
|
})
|
||||||
|
|
||||||
test('does not include status section if nothing was found', () => {
|
test('does not include status section if nothing was found', () => {
|
||||||
|
|||||||
+45
-20
@@ -307,12 +307,18 @@ function getRefs(config, context) {
|
|||||||
let head_ref = config.head_ref;
|
let head_ref = config.head_ref;
|
||||||
// If possible, source default base & head refs from the GitHub event.
|
// If possible, source default base & head refs from the GitHub event.
|
||||||
// The base/head ref from the config take priority, if provided.
|
// The base/head ref from the config take priority, if provided.
|
||||||
if (context.eventName === 'pull_request' ||
|
if (!base_ref && !head_ref) {
|
||||||
context.eventName === 'pull_request_target' ||
|
if (context.eventName === 'pull_request' ||
|
||||||
context.eventName === 'merge_group') {
|
context.eventName === 'pull_request_target') {
|
||||||
const pull_request = schemas_1.PullRequestSchema.parse(context.payload.pull_request);
|
const pull_request = schemas_1.PullRequestSchema.parse(context.payload.pull_request);
|
||||||
base_ref = base_ref || pull_request.base.sha;
|
base_ref = base_ref || pull_request.base.sha;
|
||||||
head_ref = head_ref || pull_request.head.sha;
|
head_ref = head_ref || pull_request.head.sha;
|
||||||
|
}
|
||||||
|
else if (context.eventName === 'merge_group') {
|
||||||
|
const merge_group = schemas_1.MergeGroupSchema.parse(context.payload.merge_group);
|
||||||
|
base_ref = base_ref || merge_group.base_sha;
|
||||||
|
head_ref = head_ref || merge_group.head_sha;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
if (!base_ref && !head_ref) {
|
if (!base_ref && !head_ref) {
|
||||||
throw new Error('Both a base ref and head ref must be provided, either via the `base_ref`/`head_ref` ' +
|
throw new Error('Both a base ref and head ref must be provided, either via the `base_ref`/`head_ref` ' +
|
||||||
@@ -699,7 +705,7 @@ function run() {
|
|||||||
createScorecardWarnings(scorecard, config);
|
createScorecardWarnings(scorecard, config);
|
||||||
}
|
}
|
||||||
core.setOutput('dependency-changes', JSON.stringify(changes));
|
core.setOutput('dependency-changes', JSON.stringify(changes));
|
||||||
summary.addScannedDependencies(changes);
|
summary.addScannedFiles(changes);
|
||||||
printScannedDependencies(changes);
|
printScannedDependencies(changes);
|
||||||
// include full summary in output; Actions will truncate if oversized
|
// include full summary in output; Actions will truncate if oversized
|
||||||
let rendered = core.summary.stringify();
|
let rendered = core.summary.stringify();
|
||||||
@@ -1029,7 +1035,7 @@ var __importStar = (this && this.__importStar) || function (mod) {
|
|||||||
return result;
|
return result;
|
||||||
};
|
};
|
||||||
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
||||||
exports.ScorecardSchema = exports.ScorecardApiSchema = exports.ComparisonResponseSchema = exports.ChangesSchema = exports.ConfigurationOptionsSchema = exports.PullRequestSchema = exports.ChangeSchema = exports.SeveritySchema = exports.SCOPES = exports.SEVERITIES = void 0;
|
exports.ScorecardSchema = exports.ScorecardApiSchema = exports.ComparisonResponseSchema = exports.ChangesSchema = exports.ConfigurationOptionsSchema = exports.MergeGroupSchema = exports.PullRequestSchema = exports.ChangeSchema = exports.SeveritySchema = exports.SCOPES = exports.SEVERITIES = void 0;
|
||||||
const z = __importStar(__nccwpck_require__(3301));
|
const z = __importStar(__nccwpck_require__(3301));
|
||||||
const purl_1 = __nccwpck_require__(3609);
|
const purl_1 = __nccwpck_require__(3609);
|
||||||
exports.SEVERITIES = ['critical', 'high', 'moderate', 'low'];
|
exports.SEVERITIES = ['critical', 'high', 'moderate', 'low'];
|
||||||
@@ -1113,6 +1119,10 @@ exports.PullRequestSchema = z.object({
|
|||||||
base: z.object({ sha: z.string() }),
|
base: z.object({ sha: z.string() }),
|
||||||
head: z.object({ sha: z.string() })
|
head: z.object({ sha: z.string() })
|
||||||
});
|
});
|
||||||
|
exports.MergeGroupSchema = z.object({
|
||||||
|
base_sha: z.string(),
|
||||||
|
head_sha: z.string()
|
||||||
|
});
|
||||||
exports.ConfigurationOptionsSchema = z
|
exports.ConfigurationOptionsSchema = z
|
||||||
.object({
|
.object({
|
||||||
fail_on_severity: exports.SeveritySchema,
|
fail_on_severity: exports.SeveritySchema,
|
||||||
@@ -1448,7 +1458,7 @@ var __importStar = (this && this.__importStar) || function (mod) {
|
|||||||
return result;
|
return result;
|
||||||
};
|
};
|
||||||
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
||||||
exports.addDeniedToSummary = exports.addSnapshotWarnings = exports.addScorecardToSummary = exports.addScannedDependencies = exports.addLicensesToSummary = exports.addChangeVulnerabilitiesToSummary = exports.addSummaryToSummary = void 0;
|
exports.addDeniedToSummary = exports.addSnapshotWarnings = exports.addScorecardToSummary = exports.addScannedFiles = exports.addLicensesToSummary = exports.addChangeVulnerabilitiesToSummary = exports.addSummaryToSummary = void 0;
|
||||||
const core = __importStar(__nccwpck_require__(2186));
|
const core = __importStar(__nccwpck_require__(2186));
|
||||||
const utils_1 = __nccwpck_require__(918);
|
const utils_1 = __nccwpck_require__(918);
|
||||||
const icons = {
|
const icons = {
|
||||||
@@ -1456,6 +1466,7 @@ const icons = {
|
|||||||
cross: '❌',
|
cross: '❌',
|
||||||
warning: '⚠️'
|
warning: '⚠️'
|
||||||
};
|
};
|
||||||
|
const MAX_SCANNED_FILES_BYTES = 1048576;
|
||||||
// generates the DR report summmary and caches it to the Action's core.summary.
|
// generates the DR report summmary and caches it to the Action's core.summary.
|
||||||
// returns the DR summary string, ready to be posted as a PR comment if the
|
// returns the DR summary string, ready to be posted as a PR comment if the
|
||||||
// final DR report is too large
|
// final DR report is too large
|
||||||
@@ -1637,19 +1648,29 @@ function formatLicense(license) {
|
|||||||
}
|
}
|
||||||
return license;
|
return license;
|
||||||
}
|
}
|
||||||
function addScannedDependencies(changes) {
|
function addScannedFiles(changes) {
|
||||||
const dependencies = (0, utils_1.groupDependenciesByManifest)(changes);
|
const manifests = Array.from((0, utils_1.groupDependenciesByManifest)(changes).keys()).sort();
|
||||||
const manifests = dependencies.keys();
|
let sf_size = 0;
|
||||||
const summary = core.summary.addHeading('Scanned Manifest Files', 2);
|
let trunc_at = -1;
|
||||||
for (const manifest of manifests) {
|
for (const [index, entry] of manifests.entries()) {
|
||||||
const deps = dependencies.get(manifest);
|
if (sf_size + entry.length >= MAX_SCANNED_FILES_BYTES) {
|
||||||
if (deps) {
|
trunc_at = index;
|
||||||
const dependencyNames = deps.map(dependency => `<li>${dependency.name}@${dependency.version}</li>`);
|
break;
|
||||||
summary.addDetails(manifest, `<ul>${dependencyNames.join('')}</ul>`);
|
}
|
||||||
|
sf_size += entry.length;
|
||||||
|
}
|
||||||
|
if (trunc_at >= 0) {
|
||||||
|
// truncate the manifests list if it will overflow the summary output
|
||||||
|
manifests.slice(0, trunc_at);
|
||||||
|
// if there's room between cutoff size and list size, add a warning
|
||||||
|
const size_diff = MAX_SCANNED_FILES_BYTES - sf_size;
|
||||||
|
if (size_diff < 12) {
|
||||||
|
manifests.push('(truncated)');
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
core.summary.addHeading('Scanned Files', 2).addList(manifests);
|
||||||
}
|
}
|
||||||
exports.addScannedDependencies = addScannedDependencies;
|
exports.addScannedFiles = addScannedFiles;
|
||||||
function snapshotWarningRecommendation(config, warnings) {
|
function snapshotWarningRecommendation(config, warnings) {
|
||||||
const no_pr_snaps = warnings.includes('No snapshots were found for the head SHA');
|
const no_pr_snaps = warnings.includes('No snapshots were found for the head SHA');
|
||||||
const retries_disabled = !config.retry_on_snapshot_warnings;
|
const retries_disabled = !config.retry_on_snapshot_warnings;
|
||||||
@@ -50634,7 +50655,7 @@ var __importStar = (this && this.__importStar) || function (mod) {
|
|||||||
return result;
|
return result;
|
||||||
};
|
};
|
||||||
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
||||||
exports.ScorecardSchema = exports.ScorecardApiSchema = exports.ComparisonResponseSchema = exports.ChangesSchema = exports.ConfigurationOptionsSchema = exports.PullRequestSchema = exports.ChangeSchema = exports.SeveritySchema = exports.SCOPES = exports.SEVERITIES = void 0;
|
exports.ScorecardSchema = exports.ScorecardApiSchema = exports.ComparisonResponseSchema = exports.ChangesSchema = exports.ConfigurationOptionsSchema = exports.MergeGroupSchema = exports.PullRequestSchema = exports.ChangeSchema = exports.SeveritySchema = exports.SCOPES = exports.SEVERITIES = void 0;
|
||||||
const z = __importStar(__nccwpck_require__(3301));
|
const z = __importStar(__nccwpck_require__(3301));
|
||||||
const purl_1 = __nccwpck_require__(4498);
|
const purl_1 = __nccwpck_require__(4498);
|
||||||
exports.SEVERITIES = ['critical', 'high', 'moderate', 'low'];
|
exports.SEVERITIES = ['critical', 'high', 'moderate', 'low'];
|
||||||
@@ -50718,6 +50739,10 @@ exports.PullRequestSchema = z.object({
|
|||||||
base: z.object({ sha: z.string() }),
|
base: z.object({ sha: z.string() }),
|
||||||
head: z.object({ sha: z.string() })
|
head: z.object({ sha: z.string() })
|
||||||
});
|
});
|
||||||
|
exports.MergeGroupSchema = z.object({
|
||||||
|
base_sha: z.string(),
|
||||||
|
head_sha: z.string()
|
||||||
|
});
|
||||||
exports.ConfigurationOptionsSchema = z
|
exports.ConfigurationOptionsSchema = z
|
||||||
.object({
|
.object({
|
||||||
fail_on_severity: exports.SeveritySchema,
|
fail_on_severity: exports.SeveritySchema,
|
||||||
|
|||||||
+1
-1
File diff suppressed because one or more lines are too long
Generated
+127
-223
@@ -1,12 +1,12 @@
|
|||||||
{
|
{
|
||||||
"name": "dependency-review-action",
|
"name": "dependency-review-action",
|
||||||
"version": "4.3.4",
|
"version": "4.3.5",
|
||||||
"lockfileVersion": 3,
|
"lockfileVersion": 3,
|
||||||
"requires": true,
|
"requires": true,
|
||||||
"packages": {
|
"packages": {
|
||||||
"": {
|
"": {
|
||||||
"name": "dependency-review-action",
|
"name": "dependency-review-action",
|
||||||
"version": "4.3.4",
|
"version": "4.3.5",
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/core": "^1.10.1",
|
"@actions/core": "^1.10.1",
|
||||||
@@ -15,12 +15,12 @@
|
|||||||
"@octokit/request-error": "^5.0.1",
|
"@octokit/request-error": "^5.0.1",
|
||||||
"@onebeyond/spdx-license-satisfies": "^1.0.1",
|
"@onebeyond/spdx-license-satisfies": "^1.0.1",
|
||||||
"ansi-styles": "^6.2.1",
|
"ansi-styles": "^6.2.1",
|
||||||
"got": "^14.4.1",
|
"got": "^14.4.3",
|
||||||
"jest": "^29.7.0",
|
"jest": "^29.7.0",
|
||||||
"octokit": "^3.1.2",
|
"octokit": "^3.1.2",
|
||||||
"spdx-expression-parse": "^3.0.1",
|
"spdx-expression-parse": "^3.0.1",
|
||||||
"spdx-satisfies": "^5.0.1",
|
"spdx-satisfies": "^5.0.1",
|
||||||
"ts-jest": "^29.1.2",
|
"ts-jest": "^29.2.5",
|
||||||
"yaml": "^2.3.4",
|
"yaml": "^2.3.4",
|
||||||
"zod": "^3.23.8"
|
"zod": "^3.23.8"
|
||||||
},
|
},
|
||||||
@@ -31,14 +31,14 @@
|
|||||||
"@types/spdx-satisfies": "^0.1.1",
|
"@types/spdx-satisfies": "^0.1.1",
|
||||||
"@typescript-eslint/eslint-plugin": "^6.21.0",
|
"@typescript-eslint/eslint-plugin": "^6.21.0",
|
||||||
"@typescript-eslint/parser": "^6.21.0",
|
"@typescript-eslint/parser": "^6.21.0",
|
||||||
"@vercel/ncc": "^0.38.0",
|
"@vercel/ncc": "^0.38.3",
|
||||||
"esbuild-register": "^3.5.0",
|
"esbuild-register": "^3.5.0",
|
||||||
"eslint": "^8.57.0",
|
"eslint": "^8.57.0",
|
||||||
"eslint-plugin-github": "^4.10.2",
|
"eslint-plugin-github": "^4.10.2",
|
||||||
"eslint-plugin-jest": "^27.9.0",
|
"eslint-plugin-jest": "^28.8.3",
|
||||||
"eslint-plugin-prettier": "^5.1.3",
|
"eslint-plugin-prettier": "^5.1.3",
|
||||||
"js-yaml": "^4.1.0",
|
"js-yaml": "^4.1.0",
|
||||||
"nodemon": "^3.1.0",
|
"nodemon": "^3.1.7",
|
||||||
"prettier": "3.2.5",
|
"prettier": "3.2.5",
|
||||||
"typescript": "^5.4.5"
|
"typescript": "^5.4.5"
|
||||||
}
|
}
|
||||||
@@ -1956,11 +1956,11 @@
|
|||||||
"integrity": "sha512-+Fj43pSMwJs4KRrH/938Uf+uAELIgVBmQzg/q1YG10djyfA3TnrU8N8XzqCh/okZdszqBQTZf96idMfE5lnwTA=="
|
"integrity": "sha512-+Fj43pSMwJs4KRrH/938Uf+uAELIgVBmQzg/q1YG10djyfA3TnrU8N8XzqCh/okZdszqBQTZf96idMfE5lnwTA=="
|
||||||
},
|
},
|
||||||
"node_modules/@sindresorhus/is": {
|
"node_modules/@sindresorhus/is": {
|
||||||
"version": "6.3.1",
|
"version": "7.0.1",
|
||||||
"resolved": "https://registry.npmjs.org/@sindresorhus/is/-/is-6.3.1.tgz",
|
"resolved": "https://registry.npmjs.org/@sindresorhus/is/-/is-7.0.1.tgz",
|
||||||
"integrity": "sha512-FX4MfcifwJyFOI2lPoX7PQxCqx8BG1HCho7WdiXwpEQx1Ycij0JxkfYtGK7yqNScrZGSlt6RE6sw8QYoH7eKnQ==",
|
"integrity": "sha512-QWLl2P+rsCJeofkDNIT3WFmb6NrRud1SUYW8dIhXK/46XFV8Q/g7Bsvib0Askb0reRLe+WYPeeE+l5cH7SlkuQ==",
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=16"
|
"node": ">=18"
|
||||||
},
|
},
|
||||||
"funding": {
|
"funding": {
|
||||||
"url": "https://github.com/sindresorhus/is?sponsor=1"
|
"url": "https://github.com/sindresorhus/is?sponsor=1"
|
||||||
@@ -2369,9 +2369,9 @@
|
|||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"node_modules/@vercel/ncc": {
|
"node_modules/@vercel/ncc": {
|
||||||
"version": "0.38.1",
|
"version": "0.38.3",
|
||||||
"resolved": "https://registry.npmjs.org/@vercel/ncc/-/ncc-0.38.1.tgz",
|
"resolved": "https://registry.npmjs.org/@vercel/ncc/-/ncc-0.38.3.tgz",
|
||||||
"integrity": "sha512-IBBb+iI2NLu4VQn3Vwldyi2QwaXt5+hTyh58ggAMoCGE6DJmPvwL3KPBWcJl1m9LYPChBLE980Jw+CS4Wokqxw==",
|
"integrity": "sha512-rnK6hJBS6mwc+Bkab+PGPs9OiS0i/3kdTO+CkI8V0/VrW3vmz7O2Pxjw/owOlmo6PKEIxRSeZKv/kuL9itnpYA==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"bin": {
|
"bin": {
|
||||||
"ncc": "dist/ncc/cli.js"
|
"ncc": "dist/ncc/cli.js"
|
||||||
@@ -2634,6 +2634,12 @@
|
|||||||
"integrity": "sha512-OH/2E5Fg20h2aPrbe+QL8JZQFko0YZaF+j4mnQ7BGhfavO7OpSLa8a0y9sBwomHdSbkhTS8TQNayBfnW5DwbvQ==",
|
"integrity": "sha512-OH/2E5Fg20h2aPrbe+QL8JZQFko0YZaF+j4mnQ7BGhfavO7OpSLa8a0y9sBwomHdSbkhTS8TQNayBfnW5DwbvQ==",
|
||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
|
"node_modules/async": {
|
||||||
|
"version": "3.2.6",
|
||||||
|
"resolved": "https://registry.npmjs.org/async/-/async-3.2.6.tgz",
|
||||||
|
"integrity": "sha512-htCUDlxyyCLMgaM3xXg0C0LW2xqfuQ6p05pCEIsXuyQ+a1koYKTuBMzRNwmybfLgvJDMd0r1LTn4+E0Ti6C2AA==",
|
||||||
|
"license": "MIT"
|
||||||
|
},
|
||||||
"node_modules/asynciterator.prototype": {
|
"node_modules/asynciterator.prototype": {
|
||||||
"version": "1.0.0",
|
"version": "1.0.0",
|
||||||
"resolved": "https://registry.npmjs.org/asynciterator.prototype/-/asynciterator.prototype-1.0.0.tgz",
|
"resolved": "https://registry.npmjs.org/asynciterator.prototype/-/asynciterator.prototype-1.0.0.tgz",
|
||||||
@@ -3368,6 +3374,21 @@
|
|||||||
"safe-buffer": "^5.0.1"
|
"safe-buffer": "^5.0.1"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"node_modules/ejs": {
|
||||||
|
"version": "3.1.10",
|
||||||
|
"resolved": "https://registry.npmjs.org/ejs/-/ejs-3.1.10.tgz",
|
||||||
|
"integrity": "sha512-UeJmFfOrAQS8OJWPZ4qtgHyWExa088/MtK5UEyoJGFH67cDEXkZSviOiKRCZ4Xij0zxI3JECgYs3oKx+AizQBA==",
|
||||||
|
"license": "Apache-2.0",
|
||||||
|
"dependencies": {
|
||||||
|
"jake": "^10.8.5"
|
||||||
|
},
|
||||||
|
"bin": {
|
||||||
|
"ejs": "bin/cli.js"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=0.10.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
"node_modules/electron-to-chromium": {
|
"node_modules/electron-to-chromium": {
|
||||||
"version": "1.4.578",
|
"version": "1.4.578",
|
||||||
"resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.4.578.tgz",
|
"resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.4.578.tgz",
|
||||||
@@ -4067,19 +4088,20 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/eslint-plugin-jest": {
|
"node_modules/eslint-plugin-jest": {
|
||||||
"version": "27.9.0",
|
"version": "28.8.3",
|
||||||
"resolved": "https://registry.npmjs.org/eslint-plugin-jest/-/eslint-plugin-jest-27.9.0.tgz",
|
"resolved": "https://registry.npmjs.org/eslint-plugin-jest/-/eslint-plugin-jest-28.8.3.tgz",
|
||||||
"integrity": "sha512-QIT7FH7fNmd9n4se7FFKHbsLKGQiw885Ds6Y/sxKgCZ6natwCsXdgPOADnYVxN2QrRweF0FZWbJ6S7Rsn7llug==",
|
"integrity": "sha512-HIQ3t9hASLKm2IhIOqnu+ifw7uLZkIlR7RYNv7fMcEi/p0CIiJmfriStQS2LDkgtY4nyLbIZAD+JL347Yc2ETQ==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@typescript-eslint/utils": "^5.10.0"
|
"@typescript-eslint/utils": "^6.0.0 || ^7.0.0 || ^8.0.0"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": "^14.15.0 || ^16.10.0 || >=18.0.0"
|
"node": "^16.10.0 || ^18.12.0 || >=20.0.0"
|
||||||
},
|
},
|
||||||
"peerDependencies": {
|
"peerDependencies": {
|
||||||
"@typescript-eslint/eslint-plugin": "^5.0.0 || ^6.0.0 || ^7.0.0",
|
"@typescript-eslint/eslint-plugin": "^6.0.0 || ^7.0.0 || ^8.0.0",
|
||||||
"eslint": "^7.0.0 || ^8.0.0",
|
"eslint": "^7.0.0 || ^8.0.0 || ^9.0.0",
|
||||||
"jest": "*"
|
"jest": "*"
|
||||||
},
|
},
|
||||||
"peerDependenciesMeta": {
|
"peerDependenciesMeta": {
|
||||||
@@ -4091,128 +4113,6 @@
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/eslint-plugin-jest/node_modules/@typescript-eslint/scope-manager": {
|
|
||||||
"version": "5.62.0",
|
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/scope-manager/-/scope-manager-5.62.0.tgz",
|
|
||||||
"integrity": "sha512-VXuvVvZeQCQb5Zgf4HAxc04q5j+WrNAtNh9OwCsCgpKqESMTu3tF/jhZ3xG6T4NZwWl65Bg8KuS2uEvhSfLl0w==",
|
|
||||||
"dev": true,
|
|
||||||
"dependencies": {
|
|
||||||
"@typescript-eslint/types": "5.62.0",
|
|
||||||
"@typescript-eslint/visitor-keys": "5.62.0"
|
|
||||||
},
|
|
||||||
"engines": {
|
|
||||||
"node": "^12.22.0 || ^14.17.0 || >=16.0.0"
|
|
||||||
},
|
|
||||||
"funding": {
|
|
||||||
"type": "opencollective",
|
|
||||||
"url": "https://opencollective.com/typescript-eslint"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"node_modules/eslint-plugin-jest/node_modules/@typescript-eslint/types": {
|
|
||||||
"version": "5.62.0",
|
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/types/-/types-5.62.0.tgz",
|
|
||||||
"integrity": "sha512-87NVngcbVXUahrRTqIK27gD2t5Cu1yuCXxbLcFtCzZGlfyVWWh8mLHkoxzjsB6DDNnvdL+fW8MiwPEJyGJQDgQ==",
|
|
||||||
"dev": true,
|
|
||||||
"engines": {
|
|
||||||
"node": "^12.22.0 || ^14.17.0 || >=16.0.0"
|
|
||||||
},
|
|
||||||
"funding": {
|
|
||||||
"type": "opencollective",
|
|
||||||
"url": "https://opencollective.com/typescript-eslint"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"node_modules/eslint-plugin-jest/node_modules/@typescript-eslint/typescript-estree": {
|
|
||||||
"version": "5.62.0",
|
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/typescript-estree/-/typescript-estree-5.62.0.tgz",
|
|
||||||
"integrity": "sha512-CmcQ6uY7b9y694lKdRB8FEel7JbU/40iSAPomu++SjLMntB+2Leay2LO6i8VnJk58MtE9/nQSFIH6jpyRWyYzA==",
|
|
||||||
"dev": true,
|
|
||||||
"dependencies": {
|
|
||||||
"@typescript-eslint/types": "5.62.0",
|
|
||||||
"@typescript-eslint/visitor-keys": "5.62.0",
|
|
||||||
"debug": "^4.3.4",
|
|
||||||
"globby": "^11.1.0",
|
|
||||||
"is-glob": "^4.0.3",
|
|
||||||
"semver": "^7.3.7",
|
|
||||||
"tsutils": "^3.21.0"
|
|
||||||
},
|
|
||||||
"engines": {
|
|
||||||
"node": "^12.22.0 || ^14.17.0 || >=16.0.0"
|
|
||||||
},
|
|
||||||
"funding": {
|
|
||||||
"type": "opencollective",
|
|
||||||
"url": "https://opencollective.com/typescript-eslint"
|
|
||||||
},
|
|
||||||
"peerDependenciesMeta": {
|
|
||||||
"typescript": {
|
|
||||||
"optional": true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"node_modules/eslint-plugin-jest/node_modules/@typescript-eslint/utils": {
|
|
||||||
"version": "5.62.0",
|
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/utils/-/utils-5.62.0.tgz",
|
|
||||||
"integrity": "sha512-n8oxjeb5aIbPFEtmQxQYOLI0i9n5ySBEY/ZEHHZqKQSFnxio1rv6dthascc9dLuwrL0RC5mPCxB7vnAVGAYWAQ==",
|
|
||||||
"dev": true,
|
|
||||||
"dependencies": {
|
|
||||||
"@eslint-community/eslint-utils": "^4.2.0",
|
|
||||||
"@types/json-schema": "^7.0.9",
|
|
||||||
"@types/semver": "^7.3.12",
|
|
||||||
"@typescript-eslint/scope-manager": "5.62.0",
|
|
||||||
"@typescript-eslint/types": "5.62.0",
|
|
||||||
"@typescript-eslint/typescript-estree": "5.62.0",
|
|
||||||
"eslint-scope": "^5.1.1",
|
|
||||||
"semver": "^7.3.7"
|
|
||||||
},
|
|
||||||
"engines": {
|
|
||||||
"node": "^12.22.0 || ^14.17.0 || >=16.0.0"
|
|
||||||
},
|
|
||||||
"funding": {
|
|
||||||
"type": "opencollective",
|
|
||||||
"url": "https://opencollective.com/typescript-eslint"
|
|
||||||
},
|
|
||||||
"peerDependencies": {
|
|
||||||
"eslint": "^6.0.0 || ^7.0.0 || ^8.0.0"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"node_modules/eslint-plugin-jest/node_modules/@typescript-eslint/visitor-keys": {
|
|
||||||
"version": "5.62.0",
|
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/visitor-keys/-/visitor-keys-5.62.0.tgz",
|
|
||||||
"integrity": "sha512-07ny+LHRzQXepkGg6w0mFY41fVUNBrL2Roj/++7V1txKugfjm/Ci/qSND03r2RhlJhJYMcTn9AhhSSqQp0Ysyw==",
|
|
||||||
"dev": true,
|
|
||||||
"dependencies": {
|
|
||||||
"@typescript-eslint/types": "5.62.0",
|
|
||||||
"eslint-visitor-keys": "^3.3.0"
|
|
||||||
},
|
|
||||||
"engines": {
|
|
||||||
"node": "^12.22.0 || ^14.17.0 || >=16.0.0"
|
|
||||||
},
|
|
||||||
"funding": {
|
|
||||||
"type": "opencollective",
|
|
||||||
"url": "https://opencollective.com/typescript-eslint"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"node_modules/eslint-plugin-jest/node_modules/eslint-scope": {
|
|
||||||
"version": "5.1.1",
|
|
||||||
"resolved": "https://registry.npmjs.org/eslint-scope/-/eslint-scope-5.1.1.tgz",
|
|
||||||
"integrity": "sha512-2NxwbF/hZ0KpepYN0cNbo+FN6XoK7GaHlQhgx/hIZl6Va0bF45RQOOwhLIy8lQDbuCiadSLCBnH2CFYquit5bw==",
|
|
||||||
"dev": true,
|
|
||||||
"dependencies": {
|
|
||||||
"esrecurse": "^4.3.0",
|
|
||||||
"estraverse": "^4.1.1"
|
|
||||||
},
|
|
||||||
"engines": {
|
|
||||||
"node": ">=8.0.0"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"node_modules/eslint-plugin-jest/node_modules/estraverse": {
|
|
||||||
"version": "4.3.0",
|
|
||||||
"resolved": "https://registry.npmjs.org/estraverse/-/estraverse-4.3.0.tgz",
|
|
||||||
"integrity": "sha512-39nnKffWz8xN1BU/2c79n9nB9HDzo0niYUqx6xyqUnyoAnQyyWpOTdZEeiCch8BBu515t4wp9ZmgVfVhn9EBpw==",
|
|
||||||
"dev": true,
|
|
||||||
"engines": {
|
|
||||||
"node": ">=4.0"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"node_modules/eslint-plugin-jsx-a11y": {
|
"node_modules/eslint-plugin-jsx-a11y": {
|
||||||
"version": "6.8.0",
|
"version": "6.8.0",
|
||||||
"resolved": "https://registry.npmjs.org/eslint-plugin-jsx-a11y/-/eslint-plugin-jsx-a11y-6.8.0.tgz",
|
"resolved": "https://registry.npmjs.org/eslint-plugin-jsx-a11y/-/eslint-plugin-jsx-a11y-6.8.0.tgz",
|
||||||
@@ -4515,6 +4415,36 @@
|
|||||||
"node": "^10.12.0 || >=12.0.0"
|
"node": "^10.12.0 || >=12.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"node_modules/filelist": {
|
||||||
|
"version": "1.0.4",
|
||||||
|
"resolved": "https://registry.npmjs.org/filelist/-/filelist-1.0.4.tgz",
|
||||||
|
"integrity": "sha512-w1cEuf3S+DrLCQL7ET6kz+gmlJdbq9J7yXCSjK/OZCPA+qEN1WyF4ZAf0YYJa4/shHJra2t/d/r8SV4Ji+x+8Q==",
|
||||||
|
"license": "Apache-2.0",
|
||||||
|
"dependencies": {
|
||||||
|
"minimatch": "^5.0.1"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/filelist/node_modules/brace-expansion": {
|
||||||
|
"version": "2.0.1",
|
||||||
|
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.1.tgz",
|
||||||
|
"integrity": "sha512-XnAIvQ8eM+kC6aULx6wuQiwVsnzsi9d3WxzV3FpWTGA19F621kwdbsAcFKXgKUHZWsy+mY6iL1sHTxWEFCytDA==",
|
||||||
|
"license": "MIT",
|
||||||
|
"dependencies": {
|
||||||
|
"balanced-match": "^1.0.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/filelist/node_modules/minimatch": {
|
||||||
|
"version": "5.1.6",
|
||||||
|
"resolved": "https://registry.npmjs.org/minimatch/-/minimatch-5.1.6.tgz",
|
||||||
|
"integrity": "sha512-lKwV/1brpG6mBUFHtb7NUmtABCb2WZZmm2wNiOA5hAb8VdCS4B3dtMWyvcoViccwAW/COERjXLt0zP1zXUN26g==",
|
||||||
|
"license": "ISC",
|
||||||
|
"dependencies": {
|
||||||
|
"brace-expansion": "^2.0.1"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=10"
|
||||||
|
}
|
||||||
|
},
|
||||||
"node_modules/fill-range": {
|
"node_modules/fill-range": {
|
||||||
"version": "7.1.1",
|
"version": "7.1.1",
|
||||||
"resolved": "https://registry.npmjs.org/fill-range/-/fill-range-7.1.1.tgz",
|
"resolved": "https://registry.npmjs.org/fill-range/-/fill-range-7.1.1.tgz",
|
||||||
@@ -4792,22 +4722,21 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/got": {
|
"node_modules/got": {
|
||||||
"version": "14.4.1",
|
"version": "14.4.3",
|
||||||
"resolved": "https://registry.npmjs.org/got/-/got-14.4.1.tgz",
|
"resolved": "https://registry.npmjs.org/got/-/got-14.4.3.tgz",
|
||||||
"integrity": "sha512-IvDJbJBUeexX74xNQuMIVgCRRuNOm5wuK+OC3Dc2pnSoh1AOmgc7JVj7WC+cJ4u0aPcO9KZ2frTXcqK4W/5qTQ==",
|
"integrity": "sha512-iTC0Z87yxSijWTh/IpvGpwOhIQK7+GgWkYrMRoN/hB9qeRj9RPuLGODwevs0p5idUf7nrxCVa5IlOmK3b8z+KA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@sindresorhus/is": "^6.3.1",
|
"@sindresorhus/is": "^7.0.1",
|
||||||
"@szmarczak/http-timer": "^5.0.1",
|
"@szmarczak/http-timer": "^5.0.1",
|
||||||
"cacheable-lookup": "^7.0.0",
|
"cacheable-lookup": "^7.0.0",
|
||||||
"cacheable-request": "^12.0.1",
|
"cacheable-request": "^12.0.1",
|
||||||
"decompress-response": "^6.0.0",
|
"decompress-response": "^6.0.0",
|
||||||
"form-data-encoder": "^4.0.2",
|
"form-data-encoder": "^4.0.2",
|
||||||
"get-stream": "^8.0.1",
|
|
||||||
"http2-wrapper": "^2.2.1",
|
"http2-wrapper": "^2.2.1",
|
||||||
"lowercase-keys": "^3.0.0",
|
"lowercase-keys": "^3.0.0",
|
||||||
"p-cancelable": "^4.0.1",
|
"p-cancelable": "^4.0.1",
|
||||||
"responselike": "^3.0.0",
|
"responselike": "^3.0.0",
|
||||||
"type-fest": "^4.19.0"
|
"type-fest": "^4.26.1"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=20"
|
"node": ">=20"
|
||||||
@@ -4816,21 +4745,10 @@
|
|||||||
"url": "https://github.com/sindresorhus/got?sponsor=1"
|
"url": "https://github.com/sindresorhus/got?sponsor=1"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/got/node_modules/get-stream": {
|
|
||||||
"version": "8.0.1",
|
|
||||||
"resolved": "https://registry.npmjs.org/get-stream/-/get-stream-8.0.1.tgz",
|
|
||||||
"integrity": "sha512-VaUJspBffn/LMCJVoMvSAdmscJyS1auj5Zulnn5UoYcY531UWmdwhRWkcGKnGU93m5HSXP9LP2usOryrBtQowA==",
|
|
||||||
"engines": {
|
|
||||||
"node": ">=16"
|
|
||||||
},
|
|
||||||
"funding": {
|
|
||||||
"url": "https://github.com/sponsors/sindresorhus"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"node_modules/got/node_modules/type-fest": {
|
"node_modules/got/node_modules/type-fest": {
|
||||||
"version": "4.20.0",
|
"version": "4.26.1",
|
||||||
"resolved": "https://registry.npmjs.org/type-fest/-/type-fest-4.20.0.tgz",
|
"resolved": "https://registry.npmjs.org/type-fest/-/type-fest-4.26.1.tgz",
|
||||||
"integrity": "sha512-MBh+PHUHHisjXf4tlx0CFWoMdjx8zCMLJHOjnV1prABYZFHqtFOyauCIK2/7w4oIfwkF8iNhLtnJEfVY2vn3iw==",
|
"integrity": "sha512-yOGpmOAL7CkKe/91I5O3gPICmJNLJ1G4zFYVAsRHg7M64biSnPtRj0WNQt++bRkjYOqjWXrhnUw1utzmVErAdg==",
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=16"
|
"node": ">=16"
|
||||||
},
|
},
|
||||||
@@ -5492,6 +5410,24 @@
|
|||||||
"set-function-name": "^2.0.1"
|
"set-function-name": "^2.0.1"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"node_modules/jake": {
|
||||||
|
"version": "10.9.2",
|
||||||
|
"resolved": "https://registry.npmjs.org/jake/-/jake-10.9.2.tgz",
|
||||||
|
"integrity": "sha512-2P4SQ0HrLQ+fw6llpLnOaGAvN2Zu6778SJMrCUwns4fOoG9ayrTiZk3VV8sCPkVZF8ab0zksVpS8FDY5pRCNBA==",
|
||||||
|
"license": "Apache-2.0",
|
||||||
|
"dependencies": {
|
||||||
|
"async": "^3.2.3",
|
||||||
|
"chalk": "^4.0.2",
|
||||||
|
"filelist": "^1.0.4",
|
||||||
|
"minimatch": "^3.1.2"
|
||||||
|
},
|
||||||
|
"bin": {
|
||||||
|
"jake": "bin/cli.js"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=10"
|
||||||
|
}
|
||||||
|
},
|
||||||
"node_modules/jest": {
|
"node_modules/jest": {
|
||||||
"version": "29.7.0",
|
"version": "29.7.0",
|
||||||
"resolved": "https://registry.npmjs.org/jest/-/jest-29.7.0.tgz",
|
"resolved": "https://registry.npmjs.org/jest/-/jest-29.7.0.tgz",
|
||||||
@@ -6341,11 +6277,12 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/micromatch": {
|
"node_modules/micromatch": {
|
||||||
"version": "4.0.5",
|
"version": "4.0.8",
|
||||||
"resolved": "https://registry.npmjs.org/micromatch/-/micromatch-4.0.5.tgz",
|
"resolved": "https://registry.npmjs.org/micromatch/-/micromatch-4.0.8.tgz",
|
||||||
"integrity": "sha512-DMy+ERcEW2q8Z2Po+WNXuw3c5YaUSFjAO5GsJqfEl7UjvtIuFKO6ZrKvcItdy98dwFI2N1tg3zNIdKaQT+aNdA==",
|
"integrity": "sha512-PXwfBhYu0hBCPw8Dn0E+WDYb7af3dSLVWKi3HGv84IdF4TyFoC0ysxFd0Goxw7nSv4T/PzEJQxsYsEiFCKo2BA==",
|
||||||
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"braces": "^3.0.2",
|
"braces": "^3.0.3",
|
||||||
"picomatch": "^2.3.1"
|
"picomatch": "^2.3.1"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
@@ -6412,9 +6349,9 @@
|
|||||||
"integrity": "sha512-uYr7J37ae/ORWdZeQ1xxMJe3NtdmqMC/JZK+geofDrkLUApKRHPd18/TxtBOJ4A0/+uUIliorNrfYV6s1b02eQ=="
|
"integrity": "sha512-uYr7J37ae/ORWdZeQ1xxMJe3NtdmqMC/JZK+geofDrkLUApKRHPd18/TxtBOJ4A0/+uUIliorNrfYV6s1b02eQ=="
|
||||||
},
|
},
|
||||||
"node_modules/nodemon": {
|
"node_modules/nodemon": {
|
||||||
"version": "3.1.0",
|
"version": "3.1.7",
|
||||||
"resolved": "https://registry.npmjs.org/nodemon/-/nodemon-3.1.0.tgz",
|
"resolved": "https://registry.npmjs.org/nodemon/-/nodemon-3.1.7.tgz",
|
||||||
"integrity": "sha512-xqlktYlDMCepBJd43ZQhjWwMw2obW/JRvkrLxq5RCNcuDDX1DbcPT+qT1IlIIdf+DhnWs90JpTMe+Y5KxOchvA==",
|
"integrity": "sha512-hLj7fuMow6f0lbB0cD14Lz2xNjwsyruH251Pk4t/yIitCFJbmY1myuLlHm/q06aST4jg6EgAh74PIBBrRqpVAQ==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"chokidar": "^3.5.2",
|
"chokidar": "^3.5.2",
|
||||||
@@ -7227,12 +7164,10 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/semver": {
|
"node_modules/semver": {
|
||||||
"version": "7.5.4",
|
"version": "7.6.3",
|
||||||
"resolved": "https://registry.npmjs.org/semver/-/semver-7.5.4.tgz",
|
"resolved": "https://registry.npmjs.org/semver/-/semver-7.6.3.tgz",
|
||||||
"integrity": "sha512-1bCSESV6Pv+i21Hvpxp3Dx+pSD8lIPt8uVjRrxAUt/nbswYc+tK6Y2btiULjd4+fnq15PX+nqQDC7Oft7WkwcA==",
|
"integrity": "sha512-oVekP1cKtI+CTDvHWYFUcMtsK/00wmAEfyqKfNdARm8u1wNVhSgaX7A8d4UuIlUI5e84iEwOhs7ZPYRmzU9U6A==",
|
||||||
"dependencies": {
|
"license": "ISC",
|
||||||
"lru-cache": "^6.0.0"
|
|
||||||
},
|
|
||||||
"bin": {
|
"bin": {
|
||||||
"semver": "bin/semver.js"
|
"semver": "bin/semver.js"
|
||||||
},
|
},
|
||||||
@@ -7240,22 +7175,6 @@
|
|||||||
"node": ">=10"
|
"node": ">=10"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/semver/node_modules/lru-cache": {
|
|
||||||
"version": "6.0.0",
|
|
||||||
"resolved": "https://registry.npmjs.org/lru-cache/-/lru-cache-6.0.0.tgz",
|
|
||||||
"integrity": "sha512-Jo6dJ04CmSjuznwJSS3pUeWmd/H0ffTlkXXgwZi+eq1UCmqQwCh+eLsYOYCwY991i2Fah4h1BEMCx4qThGbsiA==",
|
|
||||||
"dependencies": {
|
|
||||||
"yallist": "^4.0.0"
|
|
||||||
},
|
|
||||||
"engines": {
|
|
||||||
"node": ">=10"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"node_modules/semver/node_modules/yallist": {
|
|
||||||
"version": "4.0.0",
|
|
||||||
"resolved": "https://registry.npmjs.org/yallist/-/yallist-4.0.0.tgz",
|
|
||||||
"integrity": "sha512-3wdGidZyq5PB084XLES5TpOSRA3wjXAlIWMhum2kRcv/41Sn2emQ0dycQW4uZXLejwKvg6EsvbdlVL+FYEct7A=="
|
|
||||||
},
|
|
||||||
"node_modules/set-function-length": {
|
"node_modules/set-function-length": {
|
||||||
"version": "1.1.1",
|
"version": "1.1.1",
|
||||||
"resolved": "https://registry.npmjs.org/set-function-length/-/set-function-length-1.1.1.tgz",
|
"resolved": "https://registry.npmjs.org/set-function-length/-/set-function-length-1.1.1.tgz",
|
||||||
@@ -7662,27 +7581,30 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/ts-jest": {
|
"node_modules/ts-jest": {
|
||||||
"version": "29.1.2",
|
"version": "29.2.5",
|
||||||
"resolved": "https://registry.npmjs.org/ts-jest/-/ts-jest-29.1.2.tgz",
|
"resolved": "https://registry.npmjs.org/ts-jest/-/ts-jest-29.2.5.tgz",
|
||||||
"integrity": "sha512-br6GJoH/WUX4pu7FbZXuWGKGNDuU7b8Uj77g/Sp7puZV6EXzuByl6JrECvm0MzVzSTkSHWTihsXt+5XYER5b+g==",
|
"integrity": "sha512-KD8zB2aAZrcKIdGk4OwpJggeLcH1FgrICqDSROWqlnJXGCXK4Mn6FcdK2B6670Xr73lHMG1kHw8R87A0ecZ+vA==",
|
||||||
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"bs-logger": "0.x",
|
"bs-logger": "^0.2.6",
|
||||||
"fast-json-stable-stringify": "2.x",
|
"ejs": "^3.1.10",
|
||||||
|
"fast-json-stable-stringify": "^2.1.0",
|
||||||
"jest-util": "^29.0.0",
|
"jest-util": "^29.0.0",
|
||||||
"json5": "^2.2.3",
|
"json5": "^2.2.3",
|
||||||
"lodash.memoize": "4.x",
|
"lodash.memoize": "^4.1.2",
|
||||||
"make-error": "1.x",
|
"make-error": "^1.3.6",
|
||||||
"semver": "^7.5.3",
|
"semver": "^7.6.3",
|
||||||
"yargs-parser": "^21.0.1"
|
"yargs-parser": "^21.1.1"
|
||||||
},
|
},
|
||||||
"bin": {
|
"bin": {
|
||||||
"ts-jest": "cli.js"
|
"ts-jest": "cli.js"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": "^16.10.0 || ^18.0.0 || >=20.0.0"
|
"node": "^14.15.0 || ^16.10.0 || ^18.0.0 || >=20.0.0"
|
||||||
},
|
},
|
||||||
"peerDependencies": {
|
"peerDependencies": {
|
||||||
"@babel/core": ">=7.0.0-beta.0 <8",
|
"@babel/core": ">=7.0.0-beta.0 <8",
|
||||||
|
"@jest/transform": "^29.0.0",
|
||||||
"@jest/types": "^29.0.0",
|
"@jest/types": "^29.0.0",
|
||||||
"babel-jest": "^29.0.0",
|
"babel-jest": "^29.0.0",
|
||||||
"jest": "^29.0.0",
|
"jest": "^29.0.0",
|
||||||
@@ -7692,6 +7614,9 @@
|
|||||||
"@babel/core": {
|
"@babel/core": {
|
||||||
"optional": true
|
"optional": true
|
||||||
},
|
},
|
||||||
|
"@jest/transform": {
|
||||||
|
"optional": true
|
||||||
|
},
|
||||||
"@jest/types": {
|
"@jest/types": {
|
||||||
"optional": true
|
"optional": true
|
||||||
},
|
},
|
||||||
@@ -7742,27 +7667,6 @@
|
|||||||
"integrity": "sha512-AEYxH93jGFPn/a2iVAwW87VuUIkR1FVUKB77NwMF7nBTDkDrrT/Hpt/IrCJ0QXhW27jTBDcf5ZY7w6RiqTMw2Q==",
|
"integrity": "sha512-AEYxH93jGFPn/a2iVAwW87VuUIkR1FVUKB77NwMF7nBTDkDrrT/Hpt/IrCJ0QXhW27jTBDcf5ZY7w6RiqTMw2Q==",
|
||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"node_modules/tsutils": {
|
|
||||||
"version": "3.21.0",
|
|
||||||
"resolved": "https://registry.npmjs.org/tsutils/-/tsutils-3.21.0.tgz",
|
|
||||||
"integrity": "sha512-mHKK3iUXL+3UF6xL5k0PEhKRUBKPBCv/+RkEOpjRWxxx27KKRBmmA60A9pgOUvMi8GKhRMPEmjBRPzs2W7O1OA==",
|
|
||||||
"dev": true,
|
|
||||||
"dependencies": {
|
|
||||||
"tslib": "^1.8.1"
|
|
||||||
},
|
|
||||||
"engines": {
|
|
||||||
"node": ">= 6"
|
|
||||||
},
|
|
||||||
"peerDependencies": {
|
|
||||||
"typescript": ">=2.8.0 || >= 3.2.0-dev || >= 3.3.0-dev || >= 3.4.0-dev || >= 3.5.0-dev || >= 3.6.0-dev || >= 3.6.0-beta || >= 3.7.0-dev || >= 3.7.0-beta"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"node_modules/tsutils/node_modules/tslib": {
|
|
||||||
"version": "1.14.1",
|
|
||||||
"resolved": "https://registry.npmjs.org/tslib/-/tslib-1.14.1.tgz",
|
|
||||||
"integrity": "sha512-Xni35NKzjgMrwevysHTCArtLDpPvye8zV/0E4EyYn43P7/7qvQwPh9BGkHewbMulVntbigmcT7rdX3BNo9wRJg==",
|
|
||||||
"dev": true
|
|
||||||
},
|
|
||||||
"node_modules/tunnel": {
|
"node_modules/tunnel": {
|
||||||
"version": "0.0.6",
|
"version": "0.0.6",
|
||||||
"resolved": "https://registry.npmjs.org/tunnel/-/tunnel-0.0.6.tgz",
|
"resolved": "https://registry.npmjs.org/tunnel/-/tunnel-0.0.6.tgz",
|
||||||
|
|||||||
+6
-6
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "dependency-review-action",
|
"name": "dependency-review-action",
|
||||||
"version": "4.3.4",
|
"version": "4.3.5",
|
||||||
"private": true,
|
"private": true,
|
||||||
"description": "A GitHub Action for Dependency Review",
|
"description": "A GitHub Action for Dependency Review",
|
||||||
"main": "lib/main.js",
|
"main": "lib/main.js",
|
||||||
@@ -31,12 +31,12 @@
|
|||||||
"@octokit/request-error": "^5.0.1",
|
"@octokit/request-error": "^5.0.1",
|
||||||
"@onebeyond/spdx-license-satisfies": "^1.0.1",
|
"@onebeyond/spdx-license-satisfies": "^1.0.1",
|
||||||
"ansi-styles": "^6.2.1",
|
"ansi-styles": "^6.2.1",
|
||||||
"got": "^14.4.1",
|
"got": "^14.4.3",
|
||||||
"jest": "^29.7.0",
|
"jest": "^29.7.0",
|
||||||
"octokit": "^3.1.2",
|
"octokit": "^3.1.2",
|
||||||
"spdx-expression-parse": "^3.0.1",
|
"spdx-expression-parse": "^3.0.1",
|
||||||
"spdx-satisfies": "^5.0.1",
|
"spdx-satisfies": "^5.0.1",
|
||||||
"ts-jest": "^29.1.2",
|
"ts-jest": "^29.2.5",
|
||||||
"yaml": "^2.3.4",
|
"yaml": "^2.3.4",
|
||||||
"zod": "^3.23.8"
|
"zod": "^3.23.8"
|
||||||
},
|
},
|
||||||
@@ -47,14 +47,14 @@
|
|||||||
"@types/spdx-satisfies": "^0.1.1",
|
"@types/spdx-satisfies": "^0.1.1",
|
||||||
"@typescript-eslint/eslint-plugin": "^6.21.0",
|
"@typescript-eslint/eslint-plugin": "^6.21.0",
|
||||||
"@typescript-eslint/parser": "^6.21.0",
|
"@typescript-eslint/parser": "^6.21.0",
|
||||||
"@vercel/ncc": "^0.38.0",
|
"@vercel/ncc": "^0.38.3",
|
||||||
"esbuild-register": "^3.5.0",
|
"esbuild-register": "^3.5.0",
|
||||||
"eslint": "^8.57.0",
|
"eslint": "^8.57.0",
|
||||||
"eslint-plugin-github": "^4.10.2",
|
"eslint-plugin-github": "^4.10.2",
|
||||||
"eslint-plugin-jest": "^27.9.0",
|
"eslint-plugin-jest": "^28.8.3",
|
||||||
"eslint-plugin-prettier": "^5.1.3",
|
"eslint-plugin-prettier": "^5.1.3",
|
||||||
"js-yaml": "^4.1.0",
|
"js-yaml": "^4.1.0",
|
||||||
"nodemon": "^3.1.0",
|
"nodemon": "^3.1.7",
|
||||||
"prettier": "3.2.5",
|
"prettier": "3.2.5",
|
||||||
"typescript": "^5.4.5"
|
"typescript": "^5.4.5"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -143,7 +143,7 @@ async function createSummary(
|
|||||||
...licenseIssues.unlicensed
|
...licenseIssues.unlicensed
|
||||||
]
|
]
|
||||||
|
|
||||||
summary.addScannedDependencies(allChanges)
|
summary.addScannedFiles(allChanges)
|
||||||
|
|
||||||
const text = core.summary.stringify()
|
const text = core.summary.stringify()
|
||||||
await fs.promises.writeFile(path.resolve(tmpDir, fileName), text, {
|
await fs.promises.writeFile(path.resolve(tmpDir, fileName), text, {
|
||||||
|
|||||||
+22
-10
@@ -1,22 +1,34 @@
|
|||||||
import {PullRequestSchema, ConfigurationOptions} from './schemas'
|
import {
|
||||||
|
PullRequestSchema,
|
||||||
|
ConfigurationOptions,
|
||||||
|
MergeGroupSchema
|
||||||
|
} from './schemas'
|
||||||
|
|
||||||
export function getRefs(
|
export function getRefs(
|
||||||
config: ConfigurationOptions,
|
config: ConfigurationOptions,
|
||||||
context: {payload: {pull_request?: unknown}; eventName: string}
|
context: {
|
||||||
|
payload: {pull_request?: unknown; merge_group?: unknown}
|
||||||
|
eventName: string
|
||||||
|
}
|
||||||
): {base: string; head: string} {
|
): {base: string; head: string} {
|
||||||
let base_ref = config.base_ref
|
let base_ref = config.base_ref
|
||||||
let head_ref = config.head_ref
|
let head_ref = config.head_ref
|
||||||
|
|
||||||
// If possible, source default base & head refs from the GitHub event.
|
// If possible, source default base & head refs from the GitHub event.
|
||||||
// The base/head ref from the config take priority, if provided.
|
// The base/head ref from the config take priority, if provided.
|
||||||
if (
|
if (!base_ref && !head_ref) {
|
||||||
context.eventName === 'pull_request' ||
|
if (
|
||||||
context.eventName === 'pull_request_target' ||
|
context.eventName === 'pull_request' ||
|
||||||
context.eventName === 'merge_group'
|
context.eventName === 'pull_request_target'
|
||||||
) {
|
) {
|
||||||
const pull_request = PullRequestSchema.parse(context.payload.pull_request)
|
const pull_request = PullRequestSchema.parse(context.payload.pull_request)
|
||||||
base_ref = base_ref || pull_request.base.sha
|
base_ref = base_ref || pull_request.base.sha
|
||||||
head_ref = head_ref || pull_request.head.sha
|
head_ref = head_ref || pull_request.head.sha
|
||||||
|
} else if (context.eventName === 'merge_group') {
|
||||||
|
const merge_group = MergeGroupSchema.parse(context.payload.merge_group)
|
||||||
|
base_ref = base_ref || merge_group.base_sha
|
||||||
|
head_ref = head_ref || merge_group.head_sha
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!base_ref && !head_ref) {
|
if (!base_ref && !head_ref) {
|
||||||
|
|||||||
+1
-1
@@ -168,7 +168,7 @@ async function run(): Promise<void> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
core.setOutput('dependency-changes', JSON.stringify(changes))
|
core.setOutput('dependency-changes', JSON.stringify(changes))
|
||||||
summary.addScannedDependencies(changes)
|
summary.addScannedFiles(changes)
|
||||||
printScannedDependencies(changes)
|
printScannedDependencies(changes)
|
||||||
|
|
||||||
// include full summary in output; Actions will truncate if oversized
|
// include full summary in output; Actions will truncate if oversized
|
||||||
|
|||||||
@@ -91,6 +91,11 @@ export const PullRequestSchema = z.object({
|
|||||||
head: z.object({sha: z.string()})
|
head: z.object({sha: z.string()})
|
||||||
})
|
})
|
||||||
|
|
||||||
|
export const MergeGroupSchema = z.object({
|
||||||
|
base_sha: z.string(),
|
||||||
|
head_sha: z.string()
|
||||||
|
})
|
||||||
|
|
||||||
export const ConfigurationOptionsSchema = z
|
export const ConfigurationOptionsSchema = z
|
||||||
.object({
|
.object({
|
||||||
fail_on_severity: SeveritySchema,
|
fail_on_severity: SeveritySchema,
|
||||||
|
|||||||
+26
-12
@@ -1,7 +1,7 @@
|
|||||||
import * as core from '@actions/core'
|
import * as core from '@actions/core'
|
||||||
import {ConfigurationOptions, Changes, Change, Scorecard} from './schemas'
|
|
||||||
import {SummaryTableRow} from '@actions/core/lib/summary'
|
import {SummaryTableRow} from '@actions/core/lib/summary'
|
||||||
import {InvalidLicenseChanges, InvalidLicenseChangeTypes} from './licenses'
|
import {InvalidLicenseChanges, InvalidLicenseChangeTypes} from './licenses'
|
||||||
|
import {Change, Changes, ConfigurationOptions, Scorecard} from './schemas'
|
||||||
import {groupDependenciesByManifest, getManifestsSet, renderUrl} from './utils'
|
import {groupDependenciesByManifest, getManifestsSet, renderUrl} from './utils'
|
||||||
|
|
||||||
const icons = {
|
const icons = {
|
||||||
@@ -10,6 +10,8 @@ const icons = {
|
|||||||
warning: '⚠️'
|
warning: '⚠️'
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const MAX_SCANNED_FILES_BYTES = 1048576
|
||||||
|
|
||||||
// generates the DR report summmary and caches it to the Action's core.summary.
|
// generates the DR report summmary and caches it to the Action's core.summary.
|
||||||
// returns the DR summary string, ready to be posted as a PR comment if the
|
// returns the DR summary string, ready to be posted as a PR comment if the
|
||||||
// final DR report is too large
|
// final DR report is too large
|
||||||
@@ -263,21 +265,33 @@ function formatLicense(license: string | null): string {
|
|||||||
return license
|
return license
|
||||||
}
|
}
|
||||||
|
|
||||||
export function addScannedDependencies(changes: Changes): void {
|
export function addScannedFiles(changes: Changes): void {
|
||||||
const dependencies = groupDependenciesByManifest(changes)
|
const manifests = Array.from(
|
||||||
const manifests = dependencies.keys()
|
groupDependenciesByManifest(changes).keys()
|
||||||
|
).sort()
|
||||||
|
|
||||||
const summary = core.summary.addHeading('Scanned Manifest Files', 2)
|
let sf_size = 0
|
||||||
|
let trunc_at = -1
|
||||||
|
|
||||||
for (const manifest of manifests) {
|
for (const [index, entry] of manifests.entries()) {
|
||||||
const deps = dependencies.get(manifest)
|
if (sf_size + entry.length >= MAX_SCANNED_FILES_BYTES) {
|
||||||
if (deps) {
|
trunc_at = index
|
||||||
const dependencyNames = deps.map(
|
break
|
||||||
dependency => `<li>${dependency.name}@${dependency.version}</li>`
|
}
|
||||||
)
|
sf_size += entry.length
|
||||||
summary.addDetails(manifest, `<ul>${dependencyNames.join('')}</ul>`)
|
}
|
||||||
|
|
||||||
|
if (trunc_at >= 0) {
|
||||||
|
// truncate the manifests list if it will overflow the summary output
|
||||||
|
manifests.slice(0, trunc_at)
|
||||||
|
// if there's room between cutoff size and list size, add a warning
|
||||||
|
const size_diff = MAX_SCANNED_FILES_BYTES - sf_size
|
||||||
|
if (size_diff < 12) {
|
||||||
|
manifests.push('(truncated)')
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
core.summary.addHeading('Scanned Files', 2).addList(manifests)
|
||||||
}
|
}
|
||||||
|
|
||||||
function snapshotWarningRecommendation(
|
function snapshotWarningRecommendation(
|
||||||
|
|||||||
Reference in New Issue
Block a user