Compare commits
61
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1ade604b58 | ||
|
|
cc2a6ab32f | ||
|
|
5de8be4c40 | ||
|
|
1b8bd021a3 | ||
|
|
65d8cd176f | ||
|
|
6d500ff869 | ||
|
|
0259ed8420 | ||
|
|
ec636f3d19 | ||
|
|
367e85631b | ||
|
|
abf7b5a775 | ||
|
|
ba85772f4b | ||
|
|
8d812df813 | ||
|
|
63e12b21ed | ||
|
|
0385b5b162 | ||
|
|
8e053e0f5e | ||
|
|
e0ff0cf732 | ||
|
|
ea65cbfc18 | ||
|
|
5bf43a89cd | ||
|
|
468485fc8e | ||
|
|
46c9f79a1f | ||
|
|
cd3f55e8f9 | ||
|
|
f832351766 | ||
|
|
f96ed229f4 | ||
|
|
629703a27b | ||
|
|
d05bfb69a5 | ||
|
|
02bcebdd6e | ||
|
|
fbeabf7e29 | ||
|
|
0515f5cb39 | ||
|
|
2d1d679f58 | ||
|
|
a3563a05bc | ||
|
|
8a20ddbf25 | ||
|
|
2a646668d9 | ||
|
|
60be833ffd | ||
|
|
edc501a219 | ||
|
|
000837f2ac | ||
|
|
89f99d150a | ||
|
|
0ed41eff02 | ||
|
|
dbe70eb550 | ||
|
|
78c7c01396 | ||
|
|
89a5c76329 | ||
|
|
4a6d691283 | ||
|
|
b58d457243 | ||
|
|
cc033856be | ||
|
|
8595e805a5 | ||
|
|
fa10a7f0d6 | ||
|
|
6755d8aa71 | ||
|
|
375c537008 | ||
|
|
98f28ebe06 | ||
|
|
716b322ec9 | ||
|
|
12ae1bd550 | ||
|
|
bcb52636bd | ||
|
|
241ff73141 | ||
|
|
062b749663 | ||
|
|
4f00b72b84 | ||
|
|
602f968ea2 | ||
|
|
bd61ea0d9e | ||
|
|
8ec13c1f01 | ||
|
|
723ec8c0d3 | ||
|
|
2843194510 | ||
|
|
6944531f76 | ||
|
|
29cdbbed37 |
@@ -1,4 +1,5 @@
|
|||||||
event.json
|
event.json
|
||||||
|
.ruby-version
|
||||||
|
|
||||||
# Dependency directory
|
# Dependency directory
|
||||||
node_modules
|
node_modules
|
||||||
|
|||||||
@@ -67,19 +67,19 @@ jobs:
|
|||||||
Configure this action by either using an external configuration file,
|
Configure this action by either using an external configuration file,
|
||||||
or by inlining these options in your workflow file.
|
or by inlining these options in your workflow file.
|
||||||
|
|
||||||
### Options
|
## Configuration Options
|
||||||
|
|
||||||
#### config-file
|
### config-file
|
||||||
|
|
||||||
A string representing the path to an external configuraton file. By
|
A string representing the path to an external configuraton file. By
|
||||||
default external configuration files are not used.
|
default external configuration files are not used.
|
||||||
|
|
||||||
**Possible values**: A string representing the absolute path to the
|
**Possible values**: A string representing the absolute path to the
|
||||||
configuration file.
|
configuration file.
|
||||||
|
|
||||||
**Example**: `config-file: ./.github/dependency-review-config.yml`.
|
**Example**: `config-file: ./.github/dependency-review-config.yml`.
|
||||||
|
|
||||||
#### fail-on-severity
|
### fail-on-severity
|
||||||
|
|
||||||
Configure the severity level for alerting. See "[Vulnerability Severity](https://github.com/actions/dependency-review-action#vulnerability-severity)".
|
Configure the severity level for alerting. See "[Vulnerability Severity](https://github.com/actions/dependency-review-action#vulnerability-severity)".
|
||||||
|
|
||||||
@@ -87,7 +87,7 @@ Configure the severity level for alerting. See "[Vulnerability Severity](https:/
|
|||||||
|
|
||||||
**Example**: `fail-on-severity: moderate`.
|
**Example**: `fail-on-severity: moderate`.
|
||||||
|
|
||||||
#### fail-on-scopes
|
### fail-on-scopes
|
||||||
|
|
||||||
A list of strings representing the build environments you want to
|
A list of strings representing the build environments you want to
|
||||||
support. The default value is `development, runtime`.
|
support. The default value is `development, runtime`.
|
||||||
@@ -97,13 +97,14 @@ support. The default value is `development, runtime`.
|
|||||||
**Inline example**: `fail-on-scopes: development, runtime`
|
**Inline example**: `fail-on-scopes: development, runtime`
|
||||||
|
|
||||||
**YAML example**:
|
**YAML example**:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
# this prevents scanning development dependencies
|
# this prevents scanning development dependencies
|
||||||
fail-on-scopes:
|
fail-on-scopes:
|
||||||
- runtime
|
- runtime
|
||||||
```
|
```
|
||||||
|
|
||||||
#### allow-licenses
|
### allow-licenses
|
||||||
|
|
||||||
Only allow the licenses in this list. See "[Licenses](https://github.com/actions/dependency-review-action#licenses)".
|
Only allow the licenses in this list. See "[Licenses](https://github.com/actions/dependency-review-action#licenses)".
|
||||||
|
|
||||||
@@ -113,13 +114,14 @@ https://docs.github.com/en/rest/licenses.
|
|||||||
**Inline example**: `allow-licenses: BSD-3-Clause, MIT`
|
**Inline example**: `allow-licenses: BSD-3-Clause, MIT`
|
||||||
|
|
||||||
**YAML example**:
|
**YAML example**:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
allow-licenses:
|
allow-licenses:
|
||||||
- BSD-3-Clause
|
- BSD-3-Clause
|
||||||
- MIT
|
- MIT
|
||||||
```
|
```
|
||||||
|
|
||||||
#### deny-licenses
|
### deny-licenses
|
||||||
|
|
||||||
Add a custom list of licenses you want to block. See
|
Add a custom list of licenses you want to block. See
|
||||||
"[Licenses](https://github.com/actions/dependency-review-action#licenses)".
|
"[Licenses](https://github.com/actions/dependency-review-action#licenses)".
|
||||||
@@ -130,13 +132,30 @@ https://docs.github.com/en/rest/licenses.
|
|||||||
**Inline example**: `deny-licenses: LGPL-2.0, BSD-2-Clause`
|
**Inline example**: `deny-licenses: LGPL-2.0, BSD-2-Clause`
|
||||||
|
|
||||||
**YAML example**:
|
**YAML example**:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
deny-licenses:
|
deny-licenses:
|
||||||
- LGPL-2.0
|
- LGPL-2.0
|
||||||
- BSD-2-Clause
|
- BSD-2-Clause
|
||||||
```
|
```
|
||||||
|
|
||||||
#### base-ref/head-ref
|
### allow-ghsas
|
||||||
|
|
||||||
|
Add a custom list of GitHub Advisory IDs that can be skipped during detection.
|
||||||
|
|
||||||
|
**Possible values**: Any valid advisory GHSA ids.
|
||||||
|
|
||||||
|
**Inline example**: `allow-ghsas: GHSA-abcd-1234-5679, GHSA-efgh-1234-5679`
|
||||||
|
|
||||||
|
**YAML example**:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
allow-ghsas:
|
||||||
|
- GHSA-abcd-1234-5679
|
||||||
|
- GHSA-efgh-1234-5679
|
||||||
|
```
|
||||||
|
|
||||||
|
### base-ref/head-ref
|
||||||
|
|
||||||
Provide custom git references for the git base/head when performing
|
Provide custom git references for the git base/head when performing
|
||||||
the comparison. If you are using pull requests, or
|
the comparison. If you are using pull requests, or
|
||||||
@@ -146,6 +165,7 @@ this. The values need to be specified for all other event types.
|
|||||||
**Possible values**: Any valid git ref(s) in your project.
|
**Possible values**: Any valid git ref(s) in your project.
|
||||||
|
|
||||||
**Example**:
|
**Example**:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
base-ref: 8bb8a58d6a4028b6c2e314d5caaf273f57644896
|
base-ref: 8bb8a58d6a4028b6c2e314d5caaf273f57644896
|
||||||
head-ref: 69af5638bf660cf218aad5709a4c100e42a2f37b
|
head-ref: 69af5638bf660cf218aad5709a4c100e42a2f37b
|
||||||
@@ -163,18 +183,18 @@ file:
|
|||||||
- name: Dependency Review
|
- name: Dependency Review
|
||||||
uses: actions/dependency-review-action@v2
|
uses: actions/dependency-review-action@v2
|
||||||
with:
|
with:
|
||||||
config-file: "./.github/dependency-review-config.yml"
|
config-file: './.github/dependency-review-config.yml'
|
||||||
```
|
```
|
||||||
|
|
||||||
And then create the file in the path you just specified. **All of these fields are
|
And then create the file in the path you just specified. **All of these fields are
|
||||||
optional**:
|
optional**:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
fail-on-severity: "critical"
|
fail-on-severity: 'critical'
|
||||||
allow-licenses:
|
allow-licenses:
|
||||||
- "GPL-3.0"
|
- 'GPL-3.0'
|
||||||
- "BSD-3-Clause"
|
- 'BSD-3-Clause'
|
||||||
- "MIT"
|
- 'MIT'
|
||||||
```
|
```
|
||||||
|
|
||||||
### Inline Configuration
|
### Inline Configuration
|
||||||
|
|||||||
@@ -16,6 +16,7 @@ function clearInputs() {
|
|||||||
'FAIL-ON-SCOPES',
|
'FAIL-ON-SCOPES',
|
||||||
'ALLOW-LICENSES',
|
'ALLOW-LICENSES',
|
||||||
'DENY-LICENSES',
|
'DENY-LICENSES',
|
||||||
|
'ALLOW-GHSAS',
|
||||||
'CONFIG-FILE',
|
'CONFIG-FILE',
|
||||||
'BASE-REF',
|
'BASE-REF',
|
||||||
'HEAD-REF'
|
'HEAD-REF'
|
||||||
@@ -160,3 +161,17 @@ test('it raises an error when given invalid scope', async () => {
|
|||||||
setInput('fail-on-scopes', 'runtime, zombies')
|
setInput('fail-on-scopes', 'runtime, zombies')
|
||||||
expect(() => readConfig()).toThrow()
|
expect(() => readConfig()).toThrow()
|
||||||
})
|
})
|
||||||
|
|
||||||
|
test('it defaults to an empty GHSA allowlist', async () => {
|
||||||
|
const options = readConfig()
|
||||||
|
expect(options.allow_ghsas).toEqual(undefined)
|
||||||
|
})
|
||||||
|
|
||||||
|
test('it successfully parses GHSA allowlist', async () => {
|
||||||
|
setInput('allow-ghsas', 'GHSA-abcd-1234-5679, GHSA-efgh-1234-5679')
|
||||||
|
const options = readConfig()
|
||||||
|
expect(options.allow_ghsas).toEqual([
|
||||||
|
'GHSA-abcd-1234-5679',
|
||||||
|
'GHSA-efgh-1234-5679'
|
||||||
|
])
|
||||||
|
})
|
||||||
|
|||||||
@@ -1,6 +1,10 @@
|
|||||||
import {expect, test} from '@jest/globals'
|
import {expect, test} from '@jest/globals'
|
||||||
import {Change, Changes} from '../src/schemas'
|
import {Change, Changes} from '../src/schemas'
|
||||||
import {filterChangesBySeverity, filterChangesByScopes} from '../src/filter'
|
import {
|
||||||
|
filterChangesBySeverity,
|
||||||
|
filterChangesByScopes,
|
||||||
|
filterOutAllowedAdvisories
|
||||||
|
} from '../src/filter'
|
||||||
|
|
||||||
let npmChange: Change = {
|
let npmChange: Change = {
|
||||||
manifest: 'package.json',
|
manifest: 'package.json',
|
||||||
@@ -48,6 +52,19 @@ let rubyChange: Change = {
|
|||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|
||||||
|
let noVulnNpmChange: Change = {
|
||||||
|
manifest: 'package.json',
|
||||||
|
change_type: 'added',
|
||||||
|
ecosystem: 'npm',
|
||||||
|
name: 'helpful',
|
||||||
|
version: '1.0.0',
|
||||||
|
package_url: 'pkg:npm/[email protected]',
|
||||||
|
license: 'MIT',
|
||||||
|
source_repository_url: 'github.com/some-repo',
|
||||||
|
scope: 'runtime',
|
||||||
|
vulnerabilities: []
|
||||||
|
}
|
||||||
|
|
||||||
test('it properly filters changes by severity', async () => {
|
test('it properly filters changes by severity', async () => {
|
||||||
const changes = [npmChange, rubyChange]
|
const changes = [npmChange, rubyChange]
|
||||||
let result = filterChangesBySeverity('high', changes)
|
let result = filterChangesBySeverity('high', changes)
|
||||||
@@ -72,3 +89,29 @@ test('it properly filters changes by scope', async () => {
|
|||||||
result = filterChangesByScopes(['runtime', 'development'], changes)
|
result = filterChangesByScopes(['runtime', 'development'], changes)
|
||||||
expect(result).toEqual([npmChange, rubyChange])
|
expect(result).toEqual([npmChange, rubyChange])
|
||||||
})
|
})
|
||||||
|
|
||||||
|
test('it properly filters changes with allowed vulnerabilities', async () => {
|
||||||
|
const changes = [npmChange, rubyChange, noVulnNpmChange]
|
||||||
|
|
||||||
|
let result = filterOutAllowedAdvisories(['notrealGHSAID'], changes)
|
||||||
|
expect(result).toEqual([npmChange, rubyChange, noVulnNpmChange])
|
||||||
|
|
||||||
|
result = filterOutAllowedAdvisories(['first-random_string'], changes)
|
||||||
|
expect(result).toEqual([rubyChange, noVulnNpmChange])
|
||||||
|
|
||||||
|
result = filterOutAllowedAdvisories(
|
||||||
|
['second-random_string', 'third-random_string'],
|
||||||
|
changes
|
||||||
|
)
|
||||||
|
expect(result).toEqual([npmChange, noVulnNpmChange])
|
||||||
|
|
||||||
|
result = filterOutAllowedAdvisories(
|
||||||
|
['first-random_string', 'second-random_string', 'third-random_string'],
|
||||||
|
changes
|
||||||
|
)
|
||||||
|
expect(result).toEqual([noVulnNpmChange])
|
||||||
|
|
||||||
|
// if we have a change with multiple vulnerabilities but only one is allowed, we still should not filter out that change
|
||||||
|
result = filterOutAllowedAdvisories(['second-random_string'], changes)
|
||||||
|
expect(result).toEqual([npmChange, rubyChange, noVulnNpmChange])
|
||||||
|
})
|
||||||
|
|||||||
@@ -29,6 +29,9 @@ inputs:
|
|||||||
deny-licenses:
|
deny-licenses:
|
||||||
description: Comma-separated list of forbidden licenses (e.g. "MIT, GPL 3.0, BSD 2 Clause")
|
description: Comma-separated list of forbidden licenses (e.g. "MIT, GPL 3.0, BSD 2 Clause")
|
||||||
required: false
|
required: false
|
||||||
|
allow-ghsas:
|
||||||
|
description: Comma-separated list of allowed Github Advisory IDs (e.g. "GHSA-abcd-1234-5679, GHSA-efgh-1234-5679")
|
||||||
|
required: false
|
||||||
runs:
|
runs:
|
||||||
using: 'node16'
|
using: 'node16'
|
||||||
main: 'dist/index.js'
|
main: 'dist/index.js'
|
||||||
|
|||||||
+211
-80
@@ -203,6 +203,7 @@ const filter_1 = __nccwpck_require__(8752);
|
|||||||
const licenses_1 = __nccwpck_require__(3247);
|
const licenses_1 = __nccwpck_require__(3247);
|
||||||
const summary = __importStar(__nccwpck_require__(8608));
|
const summary = __importStar(__nccwpck_require__(8608));
|
||||||
const git_refs_1 = __nccwpck_require__(1086);
|
const git_refs_1 = __nccwpck_require__(1086);
|
||||||
|
const utils_1 = __nccwpck_require__(918);
|
||||||
function run() {
|
function run() {
|
||||||
return __awaiter(this, void 0, void 0, function* () {
|
return __awaiter(this, void 0, void 0, function* () {
|
||||||
try {
|
try {
|
||||||
@@ -215,37 +216,22 @@ function run() {
|
|||||||
headRef: refs.head
|
headRef: refs.head
|
||||||
});
|
});
|
||||||
const minSeverity = config.fail_on_severity;
|
const minSeverity = config.fail_on_severity;
|
||||||
let failed = false;
|
const scopedChanges = (0, filter_1.filterChangesByScopes)(config.fail_on_scopes, changes);
|
||||||
const licenses = {
|
const filteredChanges = (0, filter_1.filterOutAllowedAdvisories)(config.allow_ghsas, scopedChanges);
|
||||||
allow: config.allow_licenses,
|
const addedChanges = (0, filter_1.filterChangesBySeverity)(minSeverity, filteredChanges).filter(change => change.change_type === 'added' &&
|
||||||
deny: config.deny_licenses
|
|
||||||
};
|
|
||||||
const scopes = config.fail_on_scopes;
|
|
||||||
const scopedChanges = (0, filter_1.filterChangesByScopes)(scopes, changes);
|
|
||||||
const addedChanges = (0, filter_1.filterChangesBySeverity)(minSeverity, scopedChanges).filter(change => change.change_type === 'added' &&
|
|
||||||
change.vulnerabilities !== undefined &&
|
change.vulnerabilities !== undefined &&
|
||||||
change.vulnerabilities.length > 0);
|
change.vulnerabilities.length > 0);
|
||||||
const [licenseErrors, unknownLicenses] = (0, licenses_1.getDeniedLicenseChanges)(scopedChanges, licenses);
|
const [licenseErrors, unknownLicenses] = (0, licenses_1.getDeniedLicenseChanges)(filteredChanges, {
|
||||||
|
allow: config.allow_licenses,
|
||||||
|
deny: config.deny_licenses
|
||||||
|
});
|
||||||
summary.addSummaryToSummary(addedChanges, licenseErrors, unknownLicenses);
|
summary.addSummaryToSummary(addedChanges, licenseErrors, unknownLicenses);
|
||||||
if (addedChanges.length > 0) {
|
summary.addChangeVulnerabilitiesToSummary(addedChanges, minSeverity);
|
||||||
for (const change of addedChanges) {
|
|
||||||
printChangeVulnerabilities(change);
|
|
||||||
}
|
|
||||||
failed = true;
|
|
||||||
}
|
|
||||||
summary.addChangeVulnerabilitiesToSummary(addedChanges, minSeverity || '');
|
|
||||||
if (licenseErrors.length > 0) {
|
|
||||||
printLicensesError(licenseErrors);
|
|
||||||
core.setFailed('Dependency review detected incompatible licenses.');
|
|
||||||
}
|
|
||||||
printNullLicenses(unknownLicenses);
|
|
||||||
summary.addLicensesToSummary(licenseErrors, unknownLicenses, config);
|
summary.addLicensesToSummary(licenseErrors, unknownLicenses, config);
|
||||||
if (failed) {
|
summary.addScannedDependencies(changes);
|
||||||
core.setFailed('Dependency review detected vulnerable packages.');
|
printVulnerabilitiesBlock(addedChanges, minSeverity);
|
||||||
}
|
printLicensesBlock(licenseErrors, unknownLicenses);
|
||||||
else {
|
printScannedDependencies(changes);
|
||||||
core.info(`Dependency review did not detect any vulnerable packages with severity level "${minSeverity}" or higher.`);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
catch (error) {
|
catch (error) {
|
||||||
if (error instanceof request_error_1.RequestError && error.status === 404) {
|
if (error instanceof request_error_1.RequestError && error.status === 404) {
|
||||||
@@ -268,20 +254,37 @@ function run() {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
function printVulnerabilitiesBlock(addedChanges, minSeverity) {
|
||||||
|
let failed = false;
|
||||||
|
core.group('Vulnerabilities', () => __awaiter(this, void 0, void 0, function* () {
|
||||||
|
if (addedChanges.length > 0) {
|
||||||
|
for (const change of addedChanges) {
|
||||||
|
printChangeVulnerabilities(change);
|
||||||
|
}
|
||||||
|
failed = true;
|
||||||
|
}
|
||||||
|
if (failed) {
|
||||||
|
core.setFailed('Dependency review detected vulnerable packages.');
|
||||||
|
}
|
||||||
|
else {
|
||||||
|
core.info(`Dependency review did not detect any vulnerable packages with severity level "${minSeverity}" or higher.`);
|
||||||
|
}
|
||||||
|
}));
|
||||||
|
}
|
||||||
function printChangeVulnerabilities(change) {
|
function printChangeVulnerabilities(change) {
|
||||||
for (const vuln of change.vulnerabilities) {
|
for (const vuln of change.vulnerabilities) {
|
||||||
core.info(`${ansi_styles_1.default.bold.open}${change.manifest} » ${change.name}@${change.version}${ansi_styles_1.default.bold.close} – ${vuln.advisory_summary} ${renderSeverity(vuln.severity)}`);
|
core.info(`${ansi_styles_1.default.bold.open}${change.manifest} » ${change.name}@${change.version}${ansi_styles_1.default.bold.close} – ${vuln.advisory_summary} ${renderSeverity(vuln.severity)}`);
|
||||||
core.info(` ↪ ${vuln.advisory_url}`);
|
core.info(` ↪ ${vuln.advisory_url}`);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
function renderSeverity(severity) {
|
function printLicensesBlock(licenseErrors, unknownLicenses) {
|
||||||
const color = {
|
core.group('Licenses', () => __awaiter(this, void 0, void 0, function* () {
|
||||||
critical: 'red',
|
if (licenseErrors.length > 0) {
|
||||||
high: 'red',
|
printLicensesError(licenseErrors);
|
||||||
moderate: 'yellow',
|
core.setFailed('Dependency review detected incompatible licenses.');
|
||||||
low: 'grey'
|
}
|
||||||
}[severity];
|
printNullLicenses(unknownLicenses);
|
||||||
return `${ansi_styles_1.default.color[color].open}(${severity} severity)${ansi_styles_1.default.color[color].close}`;
|
}));
|
||||||
}
|
}
|
||||||
function printLicensesError(changes) {
|
function printLicensesError(changes) {
|
||||||
if (changes.length === 0) {
|
if (changes.length === 0) {
|
||||||
@@ -301,6 +304,42 @@ function printNullLicenses(changes) {
|
|||||||
core.info(`${ansi_styles_1.default.bold.open}${change.manifest} » ${change.name}@${change.version}${ansi_styles_1.default.bold.close}`);
|
core.info(`${ansi_styles_1.default.bold.open}${change.manifest} » ${change.name}@${change.version}${ansi_styles_1.default.bold.close}`);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
function renderSeverity(severity) {
|
||||||
|
const color = {
|
||||||
|
critical: 'red',
|
||||||
|
high: 'red',
|
||||||
|
moderate: 'yellow',
|
||||||
|
low: 'grey'
|
||||||
|
}[severity];
|
||||||
|
return `${ansi_styles_1.default.color[color].open}(${severity} severity)${ansi_styles_1.default.color[color].close}`;
|
||||||
|
}
|
||||||
|
function renderScannedDependency(change) {
|
||||||
|
const changeType = change.change_type;
|
||||||
|
if (changeType !== 'added' && changeType !== 'removed') {
|
||||||
|
throw new Error(`Unexpected change type: ${changeType}`);
|
||||||
|
}
|
||||||
|
const color = {
|
||||||
|
added: 'green',
|
||||||
|
removed: 'red'
|
||||||
|
}[changeType];
|
||||||
|
const icon = {
|
||||||
|
added: '+',
|
||||||
|
removed: '-'
|
||||||
|
}[changeType];
|
||||||
|
return `${ansi_styles_1.default.color[color].open}${icon} ${change.manifest}@${change.version}${ansi_styles_1.default.color[color].close}`;
|
||||||
|
}
|
||||||
|
function printScannedDependencies(changes) {
|
||||||
|
core.group('Dependency Changes', () => __awaiter(this, void 0, void 0, function* () {
|
||||||
|
const dependencies = (0, utils_1.groupDependenciesByManifest)(changes);
|
||||||
|
for (const manifestName of dependencies.keys()) {
|
||||||
|
const manifestChanges = dependencies.get(manifestName) || [];
|
||||||
|
core.info(`File: ${ansi_styles_1.default.bold.open}${manifestName}${ansi_styles_1.default.bold.close}`);
|
||||||
|
for (const change of manifestChanges) {
|
||||||
|
core.info(`${renderScannedDependency(change)}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}));
|
||||||
|
}
|
||||||
run();
|
run();
|
||||||
|
|
||||||
|
|
||||||
@@ -371,6 +410,7 @@ exports.ConfigurationOptionsSchema = z
|
|||||||
fail_on_scopes: z.array(z.enum(exports.SCOPES)).default(['runtime']),
|
fail_on_scopes: z.array(z.enum(exports.SCOPES)).default(['runtime']),
|
||||||
allow_licenses: z.array(z.string()).default([]),
|
allow_licenses: z.array(z.string()).default([]),
|
||||||
deny_licenses: z.array(z.string()).default([]),
|
deny_licenses: z.array(z.string()).default([]),
|
||||||
|
allow_ghsas: z.array(z.string()).default([]),
|
||||||
config_file: z.string().optional().default('false'),
|
config_file: z.string().optional().default('false'),
|
||||||
base_ref: z.string(),
|
base_ref: z.string(),
|
||||||
head_ref: z.string()
|
head_ref: z.string()
|
||||||
@@ -411,8 +451,9 @@ var __importStar = (this && this.__importStar) || function (mod) {
|
|||||||
return result;
|
return result;
|
||||||
};
|
};
|
||||||
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
||||||
exports.addLicensesToSummary = exports.addChangeVulnerabilitiesToSummary = exports.addSummaryToSummary = void 0;
|
exports.addScannedDependencies = exports.addLicensesToSummary = exports.addChangeVulnerabilitiesToSummary = exports.addSummaryToSummary = void 0;
|
||||||
const core = __importStar(__nccwpck_require__(2186));
|
const core = __importStar(__nccwpck_require__(2186));
|
||||||
|
const utils_1 = __nccwpck_require__(918);
|
||||||
function addSummaryToSummary(addedPackages, licenseErrors, unknownLicenses) {
|
function addSummaryToSummary(addedPackages, licenseErrors, unknownLicenses) {
|
||||||
core.summary
|
core.summary
|
||||||
.addHeading('Dependency Review')
|
.addHeading('Dependency Review')
|
||||||
@@ -421,7 +462,7 @@ function addSummaryToSummary(addedPackages, licenseErrors, unknownLicenses) {
|
|||||||
exports.addSummaryToSummary = addSummaryToSummary;
|
exports.addSummaryToSummary = addSummaryToSummary;
|
||||||
function addChangeVulnerabilitiesToSummary(addedPackages, severity) {
|
function addChangeVulnerabilitiesToSummary(addedPackages, severity) {
|
||||||
const rows = [];
|
const rows = [];
|
||||||
const manifests = getManifests(addedPackages);
|
const manifests = (0, utils_1.getManifestsSet)(addedPackages);
|
||||||
core.summary
|
core.summary
|
||||||
.addHeading('Vulnerabilities')
|
.addHeading('Vulnerabilities')
|
||||||
.addQuote(`Vulnerabilites were filtered by mininum severity <strong>${severity}</strong>.`);
|
.addQuote(`Vulnerabilites were filtered by mininum severity <strong>${severity}</strong>.`);
|
||||||
@@ -438,16 +479,16 @@ function addChangeVulnerabilitiesToSummary(addedPackages, severity) {
|
|||||||
previous_version === change.version;
|
previous_version === change.version;
|
||||||
if (!sameAsPrevious) {
|
if (!sameAsPrevious) {
|
||||||
rows.push([
|
rows.push([
|
||||||
renderUrl(change.source_repository_url, change.name),
|
(0, utils_1.renderUrl)(change.source_repository_url, change.name),
|
||||||
change.version,
|
change.version,
|
||||||
renderUrl(vuln.advisory_url, vuln.advisory_summary),
|
(0, utils_1.renderUrl)(vuln.advisory_url, vuln.advisory_summary),
|
||||||
vuln.severity
|
vuln.severity
|
||||||
]);
|
]);
|
||||||
}
|
}
|
||||||
else {
|
else {
|
||||||
rows.push([
|
rows.push([
|
||||||
{ data: '', colspan: '2' },
|
{ data: '', colspan: '2' },
|
||||||
renderUrl(vuln.advisory_url, vuln.advisory_summary),
|
(0, utils_1.renderUrl)(vuln.advisory_url, vuln.advisory_summary),
|
||||||
vuln.severity
|
vuln.severity
|
||||||
]);
|
]);
|
||||||
}
|
}
|
||||||
@@ -481,13 +522,13 @@ function addLicensesToSummary(licenseErrors, unknownLicenses, config) {
|
|||||||
}
|
}
|
||||||
if (licenseErrors.length > 0) {
|
if (licenseErrors.length > 0) {
|
||||||
const rows = [];
|
const rows = [];
|
||||||
const manifests = getManifests(licenseErrors);
|
const manifests = (0, utils_1.getManifestsSet)(licenseErrors);
|
||||||
core.summary.addHeading('Incompatible Licenses', 3).addSeparator();
|
core.summary.addHeading('Incompatible Licenses', 3).addSeparator();
|
||||||
for (const manifest of manifests) {
|
for (const manifest of manifests) {
|
||||||
core.summary.addHeading(`<em>${manifest}</em>`, 4);
|
core.summary.addHeading(`<em>${manifest}</em>`, 4);
|
||||||
for (const change of licenseErrors.filter(pkg => pkg.manifest === manifest)) {
|
for (const change of licenseErrors.filter(pkg => pkg.manifest === manifest)) {
|
||||||
rows.push([
|
rows.push([
|
||||||
renderUrl(change.source_repository_url, change.name),
|
(0, utils_1.renderUrl)(change.source_repository_url, change.name),
|
||||||
change.version,
|
change.version,
|
||||||
change.license || ''
|
change.license || ''
|
||||||
]);
|
]);
|
||||||
@@ -501,14 +542,14 @@ function addLicensesToSummary(licenseErrors, unknownLicenses, config) {
|
|||||||
core.debug(`found ${unknownLicenses.length} unknown licenses`);
|
core.debug(`found ${unknownLicenses.length} unknown licenses`);
|
||||||
if (unknownLicenses.length > 0) {
|
if (unknownLicenses.length > 0) {
|
||||||
const rows = [];
|
const rows = [];
|
||||||
const manifests = getManifests(unknownLicenses);
|
const manifests = (0, utils_1.getManifestsSet)(unknownLicenses);
|
||||||
core.debug(`found ${manifests.entries.length} manifests for unknown licenses`);
|
core.debug(`found ${manifests.entries.length} manifests for unknown licenses`);
|
||||||
core.summary.addHeading('Unknown Licenses', 3).addSeparator();
|
core.summary.addHeading('Unknown Licenses', 3).addSeparator();
|
||||||
for (const manifest of manifests) {
|
for (const manifest of manifests) {
|
||||||
core.summary.addHeading(`<em>${manifest}</em>`, 4);
|
core.summary.addHeading(`<em>${manifest}</em>`, 4);
|
||||||
for (const change of unknownLicenses.filter(pkg => pkg.manifest === manifest)) {
|
for (const change of unknownLicenses.filter(pkg => pkg.manifest === manifest)) {
|
||||||
rows.push([
|
rows.push([
|
||||||
renderUrl(change.source_repository_url, change.name),
|
(0, utils_1.renderUrl)(change.source_repository_url, change.name),
|
||||||
change.version
|
change.version
|
||||||
]);
|
]);
|
||||||
}
|
}
|
||||||
@@ -517,9 +558,49 @@ function addLicensesToSummary(licenseErrors, unknownLicenses, config) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
exports.addLicensesToSummary = addLicensesToSummary;
|
exports.addLicensesToSummary = addLicensesToSummary;
|
||||||
function getManifests(changes) {
|
function addScannedDependencies(changes) {
|
||||||
|
const dependencies = (0, utils_1.groupDependenciesByManifest)(changes);
|
||||||
|
const manifests = dependencies.keys();
|
||||||
|
const summary = core.summary
|
||||||
|
.addHeading('Scanned Dependencies')
|
||||||
|
.addRaw(`We scanned ${dependencies.size} manifest files:`);
|
||||||
|
for (const manifest of manifests) {
|
||||||
|
const deps = dependencies.get(manifest);
|
||||||
|
if (deps) {
|
||||||
|
const dependencyNames = deps.map(dependency => `<li>${dependency.name}@${dependency.version}</li>`);
|
||||||
|
summary.addRaw(`<h3>${manifest}</h3><ul>${dependencyNames.join('')}</ul>`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
exports.addScannedDependencies = addScannedDependencies;
|
||||||
|
|
||||||
|
|
||||||
|
/***/ }),
|
||||||
|
|
||||||
|
/***/ 918:
|
||||||
|
/***/ ((__unused_webpack_module, exports) => {
|
||||||
|
|
||||||
|
"use strict";
|
||||||
|
|
||||||
|
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
||||||
|
exports.renderUrl = exports.getManifestsSet = exports.groupDependenciesByManifest = void 0;
|
||||||
|
function groupDependenciesByManifest(changes) {
|
||||||
|
var _a;
|
||||||
|
const dependencies = new Map();
|
||||||
|
for (const change of changes) {
|
||||||
|
const manifestName = change.manifest;
|
||||||
|
if (dependencies.get(manifestName) === undefined) {
|
||||||
|
dependencies.set(manifestName, []);
|
||||||
|
}
|
||||||
|
(_a = dependencies.get(manifestName)) === null || _a === void 0 ? void 0 : _a.push(change);
|
||||||
|
}
|
||||||
|
return dependencies;
|
||||||
|
}
|
||||||
|
exports.groupDependenciesByManifest = groupDependenciesByManifest;
|
||||||
|
function getManifestsSet(changes) {
|
||||||
return new Set(changes.flatMap(c => c.manifest));
|
return new Set(changes.flatMap(c => c.manifest));
|
||||||
}
|
}
|
||||||
|
exports.getManifestsSet = getManifestsSet;
|
||||||
function renderUrl(url, text) {
|
function renderUrl(url, text) {
|
||||||
if (url) {
|
if (url) {
|
||||||
return `<a href="${url}">${text}</a>`;
|
return `<a href="${url}">${text}</a>`;
|
||||||
@@ -528,6 +609,7 @@ function renderUrl(url, text) {
|
|||||||
return text;
|
return text;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
exports.renderUrl = renderUrl;
|
||||||
|
|
||||||
|
|
||||||
/***/ }),
|
/***/ }),
|
||||||
@@ -671,7 +753,6 @@ const file_command_1 = __nccwpck_require__(717);
|
|||||||
const utils_1 = __nccwpck_require__(5278);
|
const utils_1 = __nccwpck_require__(5278);
|
||||||
const os = __importStar(__nccwpck_require__(2037));
|
const os = __importStar(__nccwpck_require__(2037));
|
||||||
const path = __importStar(__nccwpck_require__(1017));
|
const path = __importStar(__nccwpck_require__(1017));
|
||||||
const uuid_1 = __nccwpck_require__(5840);
|
|
||||||
const oidc_utils_1 = __nccwpck_require__(8041);
|
const oidc_utils_1 = __nccwpck_require__(8041);
|
||||||
/**
|
/**
|
||||||
* The code to exit an action
|
* The code to exit an action
|
||||||
@@ -701,20 +782,9 @@ function exportVariable(name, val) {
|
|||||||
process.env[name] = convertedVal;
|
process.env[name] = convertedVal;
|
||||||
const filePath = process.env['GITHUB_ENV'] || '';
|
const filePath = process.env['GITHUB_ENV'] || '';
|
||||||
if (filePath) {
|
if (filePath) {
|
||||||
const delimiter = `ghadelimiter_${uuid_1.v4()}`;
|
return file_command_1.issueFileCommand('ENV', file_command_1.prepareKeyValueMessage(name, val));
|
||||||
// These should realistically never happen, but just in case someone finds a way to exploit uuid generation let's not allow keys or values that contain the delimiter.
|
|
||||||
if (name.includes(delimiter)) {
|
|
||||||
throw new Error(`Unexpected input: name should not contain the delimiter "${delimiter}"`);
|
|
||||||
}
|
|
||||||
if (convertedVal.includes(delimiter)) {
|
|
||||||
throw new Error(`Unexpected input: value should not contain the delimiter "${delimiter}"`);
|
|
||||||
}
|
|
||||||
const commandValue = `${name}<<${delimiter}${os.EOL}${convertedVal}${os.EOL}${delimiter}`;
|
|
||||||
file_command_1.issueCommand('ENV', commandValue);
|
|
||||||
}
|
|
||||||
else {
|
|
||||||
command_1.issueCommand('set-env', { name }, convertedVal);
|
|
||||||
}
|
}
|
||||||
|
command_1.issueCommand('set-env', { name }, convertedVal);
|
||||||
}
|
}
|
||||||
exports.exportVariable = exportVariable;
|
exports.exportVariable = exportVariable;
|
||||||
/**
|
/**
|
||||||
@@ -732,7 +802,7 @@ exports.setSecret = setSecret;
|
|||||||
function addPath(inputPath) {
|
function addPath(inputPath) {
|
||||||
const filePath = process.env['GITHUB_PATH'] || '';
|
const filePath = process.env['GITHUB_PATH'] || '';
|
||||||
if (filePath) {
|
if (filePath) {
|
||||||
file_command_1.issueCommand('PATH', inputPath);
|
file_command_1.issueFileCommand('PATH', inputPath);
|
||||||
}
|
}
|
||||||
else {
|
else {
|
||||||
command_1.issueCommand('add-path', {}, inputPath);
|
command_1.issueCommand('add-path', {}, inputPath);
|
||||||
@@ -772,7 +842,10 @@ function getMultilineInput(name, options) {
|
|||||||
const inputs = getInput(name, options)
|
const inputs = getInput(name, options)
|
||||||
.split('\n')
|
.split('\n')
|
||||||
.filter(x => x !== '');
|
.filter(x => x !== '');
|
||||||
return inputs;
|
if (options && options.trimWhitespace === false) {
|
||||||
|
return inputs;
|
||||||
|
}
|
||||||
|
return inputs.map(input => input.trim());
|
||||||
}
|
}
|
||||||
exports.getMultilineInput = getMultilineInput;
|
exports.getMultilineInput = getMultilineInput;
|
||||||
/**
|
/**
|
||||||
@@ -805,8 +878,12 @@ exports.getBooleanInput = getBooleanInput;
|
|||||||
*/
|
*/
|
||||||
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
||||||
function setOutput(name, value) {
|
function setOutput(name, value) {
|
||||||
|
const filePath = process.env['GITHUB_OUTPUT'] || '';
|
||||||
|
if (filePath) {
|
||||||
|
return file_command_1.issueFileCommand('OUTPUT', file_command_1.prepareKeyValueMessage(name, value));
|
||||||
|
}
|
||||||
process.stdout.write(os.EOL);
|
process.stdout.write(os.EOL);
|
||||||
command_1.issueCommand('set-output', { name }, value);
|
command_1.issueCommand('set-output', { name }, utils_1.toCommandValue(value));
|
||||||
}
|
}
|
||||||
exports.setOutput = setOutput;
|
exports.setOutput = setOutput;
|
||||||
/**
|
/**
|
||||||
@@ -935,7 +1012,11 @@ exports.group = group;
|
|||||||
*/
|
*/
|
||||||
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
||||||
function saveState(name, value) {
|
function saveState(name, value) {
|
||||||
command_1.issueCommand('save-state', { name }, value);
|
const filePath = process.env['GITHUB_STATE'] || '';
|
||||||
|
if (filePath) {
|
||||||
|
return file_command_1.issueFileCommand('STATE', file_command_1.prepareKeyValueMessage(name, value));
|
||||||
|
}
|
||||||
|
command_1.issueCommand('save-state', { name }, utils_1.toCommandValue(value));
|
||||||
}
|
}
|
||||||
exports.saveState = saveState;
|
exports.saveState = saveState;
|
||||||
/**
|
/**
|
||||||
@@ -1001,13 +1082,14 @@ var __importStar = (this && this.__importStar) || function (mod) {
|
|||||||
return result;
|
return result;
|
||||||
};
|
};
|
||||||
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
||||||
exports.issueCommand = void 0;
|
exports.prepareKeyValueMessage = exports.issueFileCommand = void 0;
|
||||||
// We use any as a valid input type
|
// We use any as a valid input type
|
||||||
/* eslint-disable @typescript-eslint/no-explicit-any */
|
/* eslint-disable @typescript-eslint/no-explicit-any */
|
||||||
const fs = __importStar(__nccwpck_require__(7147));
|
const fs = __importStar(__nccwpck_require__(7147));
|
||||||
const os = __importStar(__nccwpck_require__(2037));
|
const os = __importStar(__nccwpck_require__(2037));
|
||||||
|
const uuid_1 = __nccwpck_require__(5840);
|
||||||
const utils_1 = __nccwpck_require__(5278);
|
const utils_1 = __nccwpck_require__(5278);
|
||||||
function issueCommand(command, message) {
|
function issueFileCommand(command, message) {
|
||||||
const filePath = process.env[`GITHUB_${command}`];
|
const filePath = process.env[`GITHUB_${command}`];
|
||||||
if (!filePath) {
|
if (!filePath) {
|
||||||
throw new Error(`Unable to find environment variable for file command ${command}`);
|
throw new Error(`Unable to find environment variable for file command ${command}`);
|
||||||
@@ -1019,7 +1101,22 @@ function issueCommand(command, message) {
|
|||||||
encoding: 'utf8'
|
encoding: 'utf8'
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
exports.issueCommand = issueCommand;
|
exports.issueFileCommand = issueFileCommand;
|
||||||
|
function prepareKeyValueMessage(key, value) {
|
||||||
|
const delimiter = `ghadelimiter_${uuid_1.v4()}`;
|
||||||
|
const convertedValue = utils_1.toCommandValue(value);
|
||||||
|
// These should realistically never happen, but just in case someone finds a
|
||||||
|
// way to exploit uuid generation let's not allow keys or values that contain
|
||||||
|
// the delimiter.
|
||||||
|
if (key.includes(delimiter)) {
|
||||||
|
throw new Error(`Unexpected input: name should not contain the delimiter "${delimiter}"`);
|
||||||
|
}
|
||||||
|
if (convertedValue.includes(delimiter)) {
|
||||||
|
throw new Error(`Unexpected input: value should not contain the delimiter "${delimiter}"`);
|
||||||
|
}
|
||||||
|
return `${key}<<${delimiter}${os.EOL}${convertedValue}${os.EOL}${delimiter}`;
|
||||||
|
}
|
||||||
|
exports.prepareKeyValueMessage = prepareKeyValueMessage;
|
||||||
//# sourceMappingURL=file-command.js.map
|
//# sourceMappingURL=file-command.js.map
|
||||||
|
|
||||||
/***/ }),
|
/***/ }),
|
||||||
@@ -1606,8 +1703,9 @@ exports.context = new Context.Context();
|
|||||||
* @param token the repo PAT or GITHUB_TOKEN
|
* @param token the repo PAT or GITHUB_TOKEN
|
||||||
* @param options other options to set
|
* @param options other options to set
|
||||||
*/
|
*/
|
||||||
function getOctokit(token, options) {
|
function getOctokit(token, options, ...additionalPlugins) {
|
||||||
return new utils_1.GitHub(utils_1.getOctokitOptions(token, options));
|
const GitHubWithPlugins = utils_1.GitHub.plugin(...additionalPlugins);
|
||||||
|
return new GitHubWithPlugins(utils_1.getOctokitOptions(token, options));
|
||||||
}
|
}
|
||||||
exports.getOctokit = getOctokit;
|
exports.getOctokit = getOctokit;
|
||||||
//# sourceMappingURL=github.js.map
|
//# sourceMappingURL=github.js.map
|
||||||
@@ -1689,7 +1787,7 @@ var __importStar = (this && this.__importStar) || function (mod) {
|
|||||||
return result;
|
return result;
|
||||||
};
|
};
|
||||||
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
||||||
exports.getOctokitOptions = exports.GitHub = exports.context = void 0;
|
exports.getOctokitOptions = exports.GitHub = exports.defaults = exports.context = void 0;
|
||||||
const Context = __importStar(__nccwpck_require__(4087));
|
const Context = __importStar(__nccwpck_require__(4087));
|
||||||
const Utils = __importStar(__nccwpck_require__(7914));
|
const Utils = __importStar(__nccwpck_require__(7914));
|
||||||
// octokit + plugins
|
// octokit + plugins
|
||||||
@@ -1698,13 +1796,13 @@ const plugin_rest_endpoint_methods_1 = __nccwpck_require__(3044);
|
|||||||
const plugin_paginate_rest_1 = __nccwpck_require__(4193);
|
const plugin_paginate_rest_1 = __nccwpck_require__(4193);
|
||||||
exports.context = new Context.Context();
|
exports.context = new Context.Context();
|
||||||
const baseUrl = Utils.getApiBaseUrl();
|
const baseUrl = Utils.getApiBaseUrl();
|
||||||
const defaults = {
|
exports.defaults = {
|
||||||
baseUrl,
|
baseUrl,
|
||||||
request: {
|
request: {
|
||||||
agent: Utils.getProxyAgent(baseUrl)
|
agent: Utils.getProxyAgent(baseUrl)
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
exports.GitHub = core_1.Octokit.plugin(plugin_rest_endpoint_methods_1.restEndpointMethods, plugin_paginate_rest_1.paginateRest).defaults(defaults);
|
exports.GitHub = core_1.Octokit.plugin(plugin_rest_endpoint_methods_1.restEndpointMethods, plugin_paginate_rest_1.paginateRest).defaults(exports.defaults);
|
||||||
/**
|
/**
|
||||||
* Convience function to correctly format Octokit Options to pass into the constructor.
|
* Convience function to correctly format Octokit Options to pass into the constructor.
|
||||||
*
|
*
|
||||||
@@ -14971,18 +15069,20 @@ function readInlineConfig() {
|
|||||||
.array(z.enum(schemas_1.SCOPES))
|
.array(z.enum(schemas_1.SCOPES))
|
||||||
.default(['runtime'])
|
.default(['runtime'])
|
||||||
.parse(parseList(getOptionalInput('fail-on-scopes')));
|
.parse(parseList(getOptionalInput('fail-on-scopes')));
|
||||||
const allow_licenses = getOptionalInput('allow-licenses');
|
const allow_licenses = parseList(getOptionalInput('allow-licenses'));
|
||||||
const deny_licenses = getOptionalInput('deny-licenses');
|
const deny_licenses = parseList(getOptionalInput('deny-licenses'));
|
||||||
if (allow_licenses !== undefined && deny_licenses !== undefined) {
|
if (allow_licenses !== undefined && deny_licenses !== undefined) {
|
||||||
throw new Error("Can't specify both allow_licenses and deny_licenses");
|
throw new Error("Can't specify both allow_licenses and deny_licenses");
|
||||||
}
|
}
|
||||||
|
const allow_ghsas = parseList(getOptionalInput('allow-ghsas'));
|
||||||
const base_ref = getOptionalInput('base-ref');
|
const base_ref = getOptionalInput('base-ref');
|
||||||
const head_ref = getOptionalInput('head-ref');
|
const head_ref = getOptionalInput('head-ref');
|
||||||
return {
|
return {
|
||||||
fail_on_severity,
|
fail_on_severity,
|
||||||
fail_on_scopes,
|
fail_on_scopes,
|
||||||
allow_licenses: parseList(allow_licenses),
|
allow_licenses,
|
||||||
deny_licenses: parseList(deny_licenses),
|
deny_licenses,
|
||||||
|
allow_ghsas,
|
||||||
base_ref,
|
base_ref,
|
||||||
head_ref
|
head_ref
|
||||||
};
|
};
|
||||||
@@ -15018,7 +15118,7 @@ exports.readConfigFile = readConfigFile;
|
|||||||
"use strict";
|
"use strict";
|
||||||
|
|
||||||
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
||||||
exports.filterChangesByScopes = exports.filterChangesBySeverity = void 0;
|
exports.filterOutAllowedAdvisories = exports.filterChangesByScopes = exports.filterChangesBySeverity = void 0;
|
||||||
const schemas_1 = __nccwpck_require__(1129);
|
const schemas_1 = __nccwpck_require__(1129);
|
||||||
function filterChangesBySeverity(severity, changes) {
|
function filterChangesBySeverity(severity, changes) {
|
||||||
const severityIdx = schemas_1.SEVERITIES.indexOf(severity);
|
const severityIdx = schemas_1.SEVERITIES.indexOf(severity);
|
||||||
@@ -15043,6 +15143,9 @@ function filterChangesBySeverity(severity, changes) {
|
|||||||
}
|
}
|
||||||
exports.filterChangesBySeverity = filterChangesBySeverity;
|
exports.filterChangesBySeverity = filterChangesBySeverity;
|
||||||
function filterChangesByScopes(scopes, changes) {
|
function filterChangesByScopes(scopes, changes) {
|
||||||
|
if (scopes === undefined) {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
const filteredChanges = changes.filter(change => {
|
const filteredChanges = changes.filter(change => {
|
||||||
// if there is no scope on the change (Enterprise Server API for now), we will assume it is a runtime scope
|
// if there is no scope on the change (Enterprise Server API for now), we will assume it is a runtime scope
|
||||||
const scope = change.scope || 'runtime';
|
const scope = change.scope || 'runtime';
|
||||||
@@ -15051,6 +15154,30 @@ function filterChangesByScopes(scopes, changes) {
|
|||||||
return filteredChanges;
|
return filteredChanges;
|
||||||
}
|
}
|
||||||
exports.filterChangesByScopes = filterChangesByScopes;
|
exports.filterChangesByScopes = filterChangesByScopes;
|
||||||
|
function filterOutAllowedAdvisories(ghsas, changes) {
|
||||||
|
if (ghsas === undefined) {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
const filteredChanges = changes.filter(change => {
|
||||||
|
const noAdvisories = change.vulnerabilities === undefined ||
|
||||||
|
change.vulnerabilities.length === 0;
|
||||||
|
if (noAdvisories) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
let allAllowedAdvisories = true;
|
||||||
|
// if there's at least one advisory that is not allowlisted, we will keep the change
|
||||||
|
for (const vulnerability of change.vulnerabilities) {
|
||||||
|
if (!ghsas.includes(vulnerability.advisory_ghsa_id)) {
|
||||||
|
allAllowedAdvisories = false;
|
||||||
|
}
|
||||||
|
if (!allAllowedAdvisories) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
return filteredChanges;
|
||||||
|
}
|
||||||
|
exports.filterOutAllowedAdvisories = filterOutAllowedAdvisories;
|
||||||
|
|
||||||
|
|
||||||
/***/ }),
|
/***/ }),
|
||||||
@@ -15120,6 +15247,7 @@ exports.ConfigurationOptionsSchema = z
|
|||||||
fail_on_scopes: z.array(z.enum(exports.SCOPES)).default(['runtime']),
|
fail_on_scopes: z.array(z.enum(exports.SCOPES)).default(['runtime']),
|
||||||
allow_licenses: z.array(z.string()).default([]),
|
allow_licenses: z.array(z.string()).default([]),
|
||||||
deny_licenses: z.array(z.string()).default([]),
|
deny_licenses: z.array(z.string()).default([]),
|
||||||
|
allow_ghsas: z.array(z.string()).default([]),
|
||||||
config_file: z.string().optional().default('false'),
|
config_file: z.string().optional().default('false'),
|
||||||
base_ref: z.string(),
|
base_ref: z.string(),
|
||||||
head_ref: z.string()
|
head_ref: z.string()
|
||||||
@@ -15440,7 +15568,7 @@ function composeNode(ctx, token, props, onError) {
|
|||||||
node.srcToken = token;
|
node.srcToken = token;
|
||||||
return node;
|
return node;
|
||||||
}
|
}
|
||||||
function composeEmptyNode(ctx, offset, before, pos, { spaceBefore, comment, anchor, tag }, onError) {
|
function composeEmptyNode(ctx, offset, before, pos, { spaceBefore, comment, anchor, tag, end }, onError) {
|
||||||
const token = {
|
const token = {
|
||||||
type: 'scalar',
|
type: 'scalar',
|
||||||
offset: utilEmptyScalarPosition.emptyScalarPosition(offset, before, pos),
|
offset: utilEmptyScalarPosition.emptyScalarPosition(offset, before, pos),
|
||||||
@@ -15455,8 +15583,10 @@ function composeEmptyNode(ctx, offset, before, pos, { spaceBefore, comment, anch
|
|||||||
}
|
}
|
||||||
if (spaceBefore)
|
if (spaceBefore)
|
||||||
node.spaceBefore = true;
|
node.spaceBefore = true;
|
||||||
if (comment)
|
if (comment) {
|
||||||
node.comment = comment;
|
node.comment = comment;
|
||||||
|
node.range[2] = end;
|
||||||
|
}
|
||||||
return node;
|
return node;
|
||||||
}
|
}
|
||||||
function composeAlias({ options }, { offset, source, end }, onError) {
|
function composeAlias({ options }, { offset, source, end }, onError) {
|
||||||
@@ -17466,7 +17596,7 @@ function createNode(value, tagName, ctx) {
|
|||||||
if (value instanceof String ||
|
if (value instanceof String ||
|
||||||
value instanceof Number ||
|
value instanceof Number ||
|
||||||
value instanceof Boolean ||
|
value instanceof Boolean ||
|
||||||
(typeof BigInt === 'function' && value instanceof BigInt) // not supported everywhere
|
(typeof BigInt !== 'undefined' && value instanceof BigInt) // not supported everywhere
|
||||||
) {
|
) {
|
||||||
// https://tc39.es/ecma262/#sec-serializejsonproperty
|
// https://tc39.es/ecma262/#sec-serializejsonproperty
|
||||||
value = value.valueOf();
|
value = value.valueOf();
|
||||||
@@ -22049,7 +22179,8 @@ class YAMLSet extends YAMLMap.YAMLMap {
|
|||||||
let pair;
|
let pair;
|
||||||
if (Node.isPair(key))
|
if (Node.isPair(key))
|
||||||
pair = key;
|
pair = key;
|
||||||
else if (typeof key === 'object' &&
|
else if (key &&
|
||||||
|
typeof key === 'object' &&
|
||||||
'key' in key &&
|
'key' in key &&
|
||||||
'value' in key &&
|
'value' in key &&
|
||||||
key.value === null)
|
key.value === null)
|
||||||
|
|||||||
+1
-1
File diff suppressed because one or more lines are too long
Generated
+278
-164
@@ -1,31 +1,32 @@
|
|||||||
{
|
{
|
||||||
"name": "dependency-review-action",
|
"name": "dependency-review-action",
|
||||||
"version": "2.2.0",
|
"version": "2.4.0",
|
||||||
"lockfileVersion": 2,
|
"lockfileVersion": 2,
|
||||||
"requires": true,
|
"requires": true,
|
||||||
"packages": {
|
"packages": {
|
||||||
"": {
|
"": {
|
||||||
"name": "dependency-review-action",
|
"name": "dependency-review-action",
|
||||||
"version": "2.2.0",
|
"version": "2.4.0",
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/core": "^1.9.1",
|
"@actions/core": "^1.10.0",
|
||||||
"@actions/github": "^5.0.3",
|
"@actions/github": "^5.1.1",
|
||||||
"@octokit/plugin-retry": "^3.0.9",
|
"@octokit/plugin-retry": "^3.0.9",
|
||||||
"@octokit/request-error": "^3.0.1",
|
"@octokit/request-error": "^3.0.1",
|
||||||
"ansi-styles": "^6.1.1",
|
"ansi-styles": "^6.1.1",
|
||||||
"got": "^12.5.0",
|
"got": "^12.5.1",
|
||||||
"nodemon": "^2.0.20",
|
"nodemon": "^2.0.20",
|
||||||
"yaml": "^2.1.1",
|
"spdx-satisfies": "^5.0.1",
|
||||||
|
"yaml": "^2.1.2",
|
||||||
"zod": "^3.19.1"
|
"zod": "^3.19.1"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@types/node": "^16.11.59",
|
"@types/node": "^16.11.63",
|
||||||
"@typescript-eslint/eslint-plugin": "^5.38.0",
|
"@typescript-eslint/eslint-plugin": "^5.38.1",
|
||||||
"@typescript-eslint/parser": "^5.38.0",
|
"@typescript-eslint/parser": "^5.38.1",
|
||||||
"@vercel/ncc": "^0.34.0",
|
"@vercel/ncc": "^0.34.0",
|
||||||
"esbuild-register": "^3.3.3",
|
"esbuild-register": "^3.3.3",
|
||||||
"eslint": "^8.23.1",
|
"eslint": "^8.24.0",
|
||||||
"eslint-plugin-github": "^4.3.7",
|
"eslint-plugin-github": "^4.3.7",
|
||||||
"eslint-plugin-jest": "^27.0.4",
|
"eslint-plugin-jest": "^27.0.4",
|
||||||
"jest": "^27.5.1",
|
"jest": "^27.5.1",
|
||||||
@@ -33,22 +34,22 @@
|
|||||||
"nodemon": "^2.0.20",
|
"nodemon": "^2.0.20",
|
||||||
"prettier": "2.7.1",
|
"prettier": "2.7.1",
|
||||||
"ts-jest": "^27.1.4",
|
"ts-jest": "^27.1.4",
|
||||||
"typescript": "^4.8.3"
|
"typescript": "^4.8.4"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@actions/core": {
|
"node_modules/@actions/core": {
|
||||||
"version": "1.9.1",
|
"version": "1.10.0",
|
||||||
"resolved": "https://registry.npmjs.org/@actions/core/-/core-1.9.1.tgz",
|
"resolved": "https://registry.npmjs.org/@actions/core/-/core-1.10.0.tgz",
|
||||||
"integrity": "sha512-5ad+U2YGrmmiw6du20AQW5XuWo7UKN2052FjSV7MX+Wfjf8sCqcsZe62NfgHys4QI4/Y+vQvLKYL8jWtA1ZBTA==",
|
"integrity": "sha512-2aZDDa3zrrZbP5ZYg159sNoLRb61nQ7awl5pSvIq5Qpj81vwDzdMRKzkWJGJuwVvWpvZKx7vspJALyvaaIQyug==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/http-client": "^2.0.1",
|
"@actions/http-client": "^2.0.1",
|
||||||
"uuid": "^8.3.2"
|
"uuid": "^8.3.2"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@actions/github": {
|
"node_modules/@actions/github": {
|
||||||
"version": "5.0.3",
|
"version": "5.1.1",
|
||||||
"resolved": "https://registry.npmjs.org/@actions/github/-/github-5.0.3.tgz",
|
"resolved": "https://registry.npmjs.org/@actions/github/-/github-5.1.1.tgz",
|
||||||
"integrity": "sha512-myjA/pdLQfhUGLtRZC/J4L1RXOG4o6aYdiEq+zr5wVVKljzbFld+xv10k1FX6IkIJtNxbAq44BdwSNpQ015P0A==",
|
"integrity": "sha512-Nk59rMDoJaV+mHCOJPXuvB1zIbomlKS0dmSIqPGxd0enAXBnOfn4VWF+CGtRCwXZG9Epa54tZA7VIRlJDS8A6g==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/http-client": "^2.0.1",
|
"@actions/http-client": "^2.0.1",
|
||||||
"@octokit/core": "^3.6.0",
|
"@octokit/core": "^3.6.0",
|
||||||
@@ -705,9 +706,9 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@humanwhocodes/config-array": {
|
"node_modules/@humanwhocodes/config-array": {
|
||||||
"version": "0.10.4",
|
"version": "0.10.5",
|
||||||
"resolved": "https://registry.npmjs.org/@humanwhocodes/config-array/-/config-array-0.10.4.tgz",
|
"resolved": "https://registry.npmjs.org/@humanwhocodes/config-array/-/config-array-0.10.5.tgz",
|
||||||
"integrity": "sha512-mXAIHxZT3Vcpg83opl1wGlVZ9xydbfZO3r5YfRSH6Gpp2J/PfdBP0wbDa2sO6/qRbcalpoevVyW6A/fI6LfeMw==",
|
"integrity": "sha512-XVVDtp+dVvRxMoxSiSfasYaG02VEe1qH5cKgMQJWhol6HwzbcqoCMJi8dAGoYAO57jhUyhI6cWuRiTcRaDaYug==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@humanwhocodes/object-schema": "^1.2.1",
|
"@humanwhocodes/object-schema": "^1.2.1",
|
||||||
@@ -1393,6 +1394,11 @@
|
|||||||
"@types/node": "*"
|
"@types/node": "*"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"node_modules/@types/http-cache-semantics": {
|
||||||
|
"version": "4.0.1",
|
||||||
|
"resolved": "https://registry.npmjs.org/@types/http-cache-semantics/-/http-cache-semantics-4.0.1.tgz",
|
||||||
|
"integrity": "sha512-SZs7ekbP8CN0txVG2xVRH6EgKmEm31BOxA07vkFaETzZz1xh+cbt8BcI0slpymvwhx5dlFnQG2rTlPVQn+iRPQ=="
|
||||||
|
},
|
||||||
"node_modules/@types/istanbul-lib-coverage": {
|
"node_modules/@types/istanbul-lib-coverage": {
|
||||||
"version": "2.0.3",
|
"version": "2.0.3",
|
||||||
"resolved": "https://registry.npmjs.org/@types/istanbul-lib-coverage/-/istanbul-lib-coverage-2.0.3.tgz",
|
"resolved": "https://registry.npmjs.org/@types/istanbul-lib-coverage/-/istanbul-lib-coverage-2.0.3.tgz",
|
||||||
@@ -1430,9 +1436,9 @@
|
|||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"node_modules/@types/node": {
|
"node_modules/@types/node": {
|
||||||
"version": "16.11.59",
|
"version": "16.11.63",
|
||||||
"resolved": "https://registry.npmjs.org/@types/node/-/node-16.11.59.tgz",
|
"resolved": "https://registry.npmjs.org/@types/node/-/node-16.11.63.tgz",
|
||||||
"integrity": "sha512-6u+36Dj3aDzhfBVUf/mfmc92OEdzQ2kx2jcXGdigfl70E/neV21ZHE6UCz4MDzTRcVqGAM27fk+DLXvyDsn3Jw==",
|
"integrity": "sha512-3OxnrEQLBz8EIIaHpg3CibmTAEGkDBcHY4fL5cnBwg2vd2yvHrUDGWxK+MlYPeXWWIoJJW79dGtU+oeBr6166Q==",
|
||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"node_modules/@types/prettier": {
|
"node_modules/@types/prettier": {
|
||||||
@@ -1463,14 +1469,14 @@
|
|||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"node_modules/@typescript-eslint/eslint-plugin": {
|
"node_modules/@typescript-eslint/eslint-plugin": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/eslint-plugin/-/eslint-plugin-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/eslint-plugin/-/eslint-plugin-5.38.1.tgz",
|
||||||
"integrity": "sha512-GgHi/GNuUbTOeoJiEANi0oI6fF3gBQc3bGFYj40nnAPCbhrtEDf2rjBmefFadweBmO1Du1YovHeDP2h5JLhtTQ==",
|
"integrity": "sha512-ky7EFzPhqz3XlhS7vPOoMDaQnQMn+9o5ICR9CPr/6bw8HrFkzhMSxuA3gRfiJVvs7geYrSeawGJjZoZQKCOglQ==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@typescript-eslint/scope-manager": "5.38.0",
|
"@typescript-eslint/scope-manager": "5.38.1",
|
||||||
"@typescript-eslint/type-utils": "5.38.0",
|
"@typescript-eslint/type-utils": "5.38.1",
|
||||||
"@typescript-eslint/utils": "5.38.0",
|
"@typescript-eslint/utils": "5.38.1",
|
||||||
"debug": "^4.3.4",
|
"debug": "^4.3.4",
|
||||||
"ignore": "^5.2.0",
|
"ignore": "^5.2.0",
|
||||||
"regexpp": "^3.2.0",
|
"regexpp": "^3.2.0",
|
||||||
@@ -1510,14 +1516,14 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@typescript-eslint/parser": {
|
"node_modules/@typescript-eslint/parser": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/parser/-/parser-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/parser/-/parser-5.38.1.tgz",
|
||||||
"integrity": "sha512-/F63giJGLDr0ms1Cr8utDAxP2SPiglaD6V+pCOcG35P2jCqdfR7uuEhz1GIC3oy4hkUF8xA1XSXmd9hOh/a5EA==",
|
"integrity": "sha512-LDqxZBVFFQnQRz9rUZJhLmox+Ep5kdUmLatLQnCRR6523YV+XhRjfYzStQ4MheFA8kMAfUlclHSbu+RKdRwQKw==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@typescript-eslint/scope-manager": "5.38.0",
|
"@typescript-eslint/scope-manager": "5.38.1",
|
||||||
"@typescript-eslint/types": "5.38.0",
|
"@typescript-eslint/types": "5.38.1",
|
||||||
"@typescript-eslint/typescript-estree": "5.38.0",
|
"@typescript-eslint/typescript-estree": "5.38.1",
|
||||||
"debug": "^4.3.4"
|
"debug": "^4.3.4"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
@@ -1537,13 +1543,13 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@typescript-eslint/scope-manager": {
|
"node_modules/@typescript-eslint/scope-manager": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/scope-manager/-/scope-manager-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/scope-manager/-/scope-manager-5.38.1.tgz",
|
||||||
"integrity": "sha512-ByhHIuNyKD9giwkkLqzezZ9y5bALW8VNY6xXcP+VxoH4JBDKjU5WNnsiD4HJdglHECdV+lyaxhvQjTUbRboiTA==",
|
"integrity": "sha512-BfRDq5RidVU3RbqApKmS7RFMtkyWMM50qWnDAkKgQiezRtLKsoyRKIvz1Ok5ilRWeD9IuHvaidaLxvGx/2eqTQ==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@typescript-eslint/types": "5.38.0",
|
"@typescript-eslint/types": "5.38.1",
|
||||||
"@typescript-eslint/visitor-keys": "5.38.0"
|
"@typescript-eslint/visitor-keys": "5.38.1"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": "^12.22.0 || ^14.17.0 || >=16.0.0"
|
"node": "^12.22.0 || ^14.17.0 || >=16.0.0"
|
||||||
@@ -1554,13 +1560,13 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@typescript-eslint/type-utils": {
|
"node_modules/@typescript-eslint/type-utils": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/type-utils/-/type-utils-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/type-utils/-/type-utils-5.38.1.tgz",
|
||||||
"integrity": "sha512-iZq5USgybUcj/lfnbuelJ0j3K9dbs1I3RICAJY9NZZpDgBYXmuUlYQGzftpQA9wC8cKgtS6DASTvF3HrXwwozA==",
|
"integrity": "sha512-UU3j43TM66gYtzo15ivK2ZFoDFKKP0k03MItzLdq0zV92CeGCXRfXlfQX5ILdd4/DSpHkSjIgLLLh1NtkOJOAw==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@typescript-eslint/typescript-estree": "5.38.0",
|
"@typescript-eslint/typescript-estree": "5.38.1",
|
||||||
"@typescript-eslint/utils": "5.38.0",
|
"@typescript-eslint/utils": "5.38.1",
|
||||||
"debug": "^4.3.4",
|
"debug": "^4.3.4",
|
||||||
"tsutils": "^3.21.0"
|
"tsutils": "^3.21.0"
|
||||||
},
|
},
|
||||||
@@ -1581,9 +1587,9 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@typescript-eslint/types": {
|
"node_modules/@typescript-eslint/types": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/types/-/types-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/types/-/types-5.38.1.tgz",
|
||||||
"integrity": "sha512-HHu4yMjJ7i3Cb+8NUuRCdOGu2VMkfmKyIJsOr9PfkBVYLYrtMCK/Ap50Rpov+iKpxDTfnqvDbuPLgBE5FwUNfA==",
|
"integrity": "sha512-QTW1iHq1Tffp9lNfbfPm4WJabbvpyaehQ0SrvVK2yfV79SytD9XDVxqiPvdrv2LK7DGSFo91TB2FgWanbJAZXg==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": "^12.22.0 || ^14.17.0 || >=16.0.0"
|
"node": "^12.22.0 || ^14.17.0 || >=16.0.0"
|
||||||
@@ -1594,13 +1600,13 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@typescript-eslint/typescript-estree": {
|
"node_modules/@typescript-eslint/typescript-estree": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/typescript-estree/-/typescript-estree-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/typescript-estree/-/typescript-estree-5.38.1.tgz",
|
||||||
"integrity": "sha512-6P0RuphkR+UuV7Avv7MU3hFoWaGcrgOdi8eTe1NwhMp2/GjUJoODBTRWzlHpZh6lFOaPmSvgxGlROa0Sg5Zbyg==",
|
"integrity": "sha512-99b5e/Enoe8fKMLdSuwrfH/C0EIbpUWmeEKHmQlGZb8msY33qn1KlkFww0z26o5Omx7EVjzVDCWEfrfCDHfE7g==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@typescript-eslint/types": "5.38.0",
|
"@typescript-eslint/types": "5.38.1",
|
||||||
"@typescript-eslint/visitor-keys": "5.38.0",
|
"@typescript-eslint/visitor-keys": "5.38.1",
|
||||||
"debug": "^4.3.4",
|
"debug": "^4.3.4",
|
||||||
"globby": "^11.1.0",
|
"globby": "^11.1.0",
|
||||||
"is-glob": "^4.0.3",
|
"is-glob": "^4.0.3",
|
||||||
@@ -1636,15 +1642,15 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@typescript-eslint/utils": {
|
"node_modules/@typescript-eslint/utils": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/utils/-/utils-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/utils/-/utils-5.38.1.tgz",
|
||||||
"integrity": "sha512-6sdeYaBgk9Fh7N2unEXGz+D+som2QCQGPAf1SxrkEr+Z32gMreQ0rparXTNGRRfYUWk/JzbGdcM8NSSd6oqnTA==",
|
"integrity": "sha512-oIuUiVxPBsndrN81oP8tXnFa/+EcZ03qLqPDfSZ5xIJVm7A9V0rlkQwwBOAGtrdN70ZKDlKv+l1BeT4eSFxwXA==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@types/json-schema": "^7.0.9",
|
"@types/json-schema": "^7.0.9",
|
||||||
"@typescript-eslint/scope-manager": "5.38.0",
|
"@typescript-eslint/scope-manager": "5.38.1",
|
||||||
"@typescript-eslint/types": "5.38.0",
|
"@typescript-eslint/types": "5.38.1",
|
||||||
"@typescript-eslint/typescript-estree": "5.38.0",
|
"@typescript-eslint/typescript-estree": "5.38.1",
|
||||||
"eslint-scope": "^5.1.1",
|
"eslint-scope": "^5.1.1",
|
||||||
"eslint-utils": "^3.0.0"
|
"eslint-utils": "^3.0.0"
|
||||||
},
|
},
|
||||||
@@ -1660,12 +1666,12 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@typescript-eslint/visitor-keys": {
|
"node_modules/@typescript-eslint/visitor-keys": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/visitor-keys/-/visitor-keys-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/visitor-keys/-/visitor-keys-5.38.1.tgz",
|
||||||
"integrity": "sha512-MxnrdIyArnTi+XyFLR+kt/uNAcdOnmT+879os7qDRI+EYySR4crXJq9BXPfRzzLGq0wgxkwidrCJ9WCAoacm1w==",
|
"integrity": "sha512-bSHr1rRxXt54+j2n4k54p4fj8AHJ49VDWtjpImOpzQj4qjAiOpPni+V1Tyajh19Api1i844F757cur8wH3YvOA==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@typescript-eslint/types": "5.38.0",
|
"@typescript-eslint/types": "5.38.1",
|
||||||
"eslint-visitor-keys": "^3.3.0"
|
"eslint-visitor-keys": "^3.3.0"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
@@ -1856,6 +1862,14 @@
|
|||||||
"node": ">=6.0"
|
"node": ">=6.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"node_modules/array-find-index": {
|
||||||
|
"version": "1.0.2",
|
||||||
|
"resolved": "https://registry.npmjs.org/array-find-index/-/array-find-index-1.0.2.tgz",
|
||||||
|
"integrity": "sha512-M1HQyIXcBGtVywBt8WVdim+lrNaK7VHp99Qt5pSNziXznKHViIBbXWtfRTpEFpF/c4FdfxNAsCCwPp5phBYJtw==",
|
||||||
|
"engines": {
|
||||||
|
"node": ">=0.10.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
"node_modules/array-includes": {
|
"node_modules/array-includes": {
|
||||||
"version": "3.1.5",
|
"version": "3.1.5",
|
||||||
"resolved": "https://registry.npmjs.org/array-includes/-/array-includes-3.1.5.tgz",
|
"resolved": "https://registry.npmjs.org/array-includes/-/array-includes-3.1.5.tgz",
|
||||||
@@ -2124,18 +2138,19 @@
|
|||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"node_modules/cacheable-lookup": {
|
"node_modules/cacheable-lookup": {
|
||||||
"version": "6.0.4",
|
"version": "7.0.0",
|
||||||
"resolved": "https://registry.npmjs.org/cacheable-lookup/-/cacheable-lookup-6.0.4.tgz",
|
"resolved": "https://registry.npmjs.org/cacheable-lookup/-/cacheable-lookup-7.0.0.tgz",
|
||||||
"integrity": "sha512-mbcDEZCkv2CZF4G01kr8eBd/5agkt9oCqz75tJMSIsquvRZ2sL6Hi5zGVKi/0OSC9oO1GHfJ2AV0ZIOY9vye0A==",
|
"integrity": "sha512-+qJyx4xiKra8mZrcwhjMRMUhD5NR1R8esPkzIYxX96JiecFoxAXFuz/GpR3+ev4PE1WamHip78wV0vcmPQtp8w==",
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=10.6.0"
|
"node": ">=14.16"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/cacheable-request": {
|
"node_modules/cacheable-request": {
|
||||||
"version": "10.1.2",
|
"version": "10.2.1",
|
||||||
"resolved": "https://registry.npmjs.org/cacheable-request/-/cacheable-request-10.1.2.tgz",
|
"resolved": "https://registry.npmjs.org/cacheable-request/-/cacheable-request-10.2.1.tgz",
|
||||||
"integrity": "sha512-N7F4os5ZI+8mWHSbeJmxn+qimf5uK3WU53FD1b298XLGtOLPpSA/1xAchfP4NJlDwqgaviZ0SQfxTQD0K6lr9w==",
|
"integrity": "sha512-3tLJyBjGuXw1s5gpKFSG3iS4kaKT4id04dZi98wzHQp/8cqZNweBnrF9J+rrlvrf4M53OdtDGNctNHFias8BEA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
|
"@types/http-cache-semantics": "^4.0.1",
|
||||||
"get-stream": "^6.0.1",
|
"get-stream": "^6.0.1",
|
||||||
"http-cache-semantics": "^4.1.0",
|
"http-cache-semantics": "^4.1.0",
|
||||||
"keyv": "^4.5.0",
|
"keyv": "^4.5.0",
|
||||||
@@ -2776,13 +2791,13 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/eslint": {
|
"node_modules/eslint": {
|
||||||
"version": "8.23.1",
|
"version": "8.24.0",
|
||||||
"resolved": "https://registry.npmjs.org/eslint/-/eslint-8.23.1.tgz",
|
"resolved": "https://registry.npmjs.org/eslint/-/eslint-8.24.0.tgz",
|
||||||
"integrity": "sha512-w7C1IXCc6fNqjpuYd0yPlcTKKmHlHHktRkzmBPZ+7cvNBQuiNjx0xaMTjAJGCafJhQkrFJooREv0CtrVzmHwqg==",
|
"integrity": "sha512-dWFaPhGhTAiPcCgm3f6LI2MBWbogMnTJzFBbhXVRQDJPkr9pGZvVjlVfXd+vyDcWPA2Ic9L2AXPIQM0+vk/cSQ==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@eslint/eslintrc": "^1.3.2",
|
"@eslint/eslintrc": "^1.3.2",
|
||||||
"@humanwhocodes/config-array": "^0.10.4",
|
"@humanwhocodes/config-array": "^0.10.5",
|
||||||
"@humanwhocodes/gitignore-to-minimatch": "^1.0.2",
|
"@humanwhocodes/gitignore-to-minimatch": "^1.0.2",
|
||||||
"@humanwhocodes/module-importer": "^1.0.1",
|
"@humanwhocodes/module-importer": "^1.0.1",
|
||||||
"ajv": "^6.10.0",
|
"ajv": "^6.10.0",
|
||||||
@@ -3805,14 +3820,14 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/got": {
|
"node_modules/got": {
|
||||||
"version": "12.5.0",
|
"version": "12.5.1",
|
||||||
"resolved": "https://registry.npmjs.org/got/-/got-12.5.0.tgz",
|
"resolved": "https://registry.npmjs.org/got/-/got-12.5.1.tgz",
|
||||||
"integrity": "sha512-/Bneo/L6bLN1wDyJCeRZ3CLoixvwb9v3rE3IHulFSfTHwP85xSr4QatA8K0c6GlL5+mc4IZ57BzluNZJiXvHIg==",
|
"integrity": "sha512-sD16AK8cCyUoPtKr/NMvLTFFa+T3i3S+zoiuvhq0HP2YiqBZA9AtlBjAdsQBsLBK7slPuvmfE0OxhGi7N5dD4w==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@sindresorhus/is": "^5.2.0",
|
"@sindresorhus/is": "^5.2.0",
|
||||||
"@szmarczak/http-timer": "^5.0.1",
|
"@szmarczak/http-timer": "^5.0.1",
|
||||||
"cacheable-lookup": "^6.0.4",
|
"cacheable-lookup": "^7.0.0",
|
||||||
"cacheable-request": "^10.1.2",
|
"cacheable-request": "^10.2.1",
|
||||||
"decompress-response": "^6.0.0",
|
"decompress-response": "^6.0.0",
|
||||||
"form-data-encoder": "^2.1.2",
|
"form-data-encoder": "^2.1.2",
|
||||||
"get-stream": "^6.0.1",
|
"get-stream": "^6.0.1",
|
||||||
@@ -5700,9 +5715,9 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/normalize-url": {
|
"node_modules/normalize-url": {
|
||||||
"version": "7.1.0",
|
"version": "7.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/normalize-url/-/normalize-url-7.1.0.tgz",
|
"resolved": "https://registry.npmjs.org/normalize-url/-/normalize-url-7.2.0.tgz",
|
||||||
"integrity": "sha512-JgkdydFdLe1E5Q7DpLvKVyBZOOwXYGhIbMbOMm3lJ06XKzaiit+qo1HciO3z3IFklStfarzJHVQf9ZcNPTvZlw==",
|
"integrity": "sha512-uhXOdZry0L6M2UIo9BTt7FdpBDiAGN/7oItedQwPKh8jh31ZlvC8U9Xl/EJ3aijDHaywXTW3QbZ6LuCocur1YA==",
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=12.20"
|
"node": ">=12.20"
|
||||||
},
|
},
|
||||||
@@ -6416,6 +6431,50 @@
|
|||||||
"source-map": "^0.6.0"
|
"source-map": "^0.6.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"node_modules/spdx-compare": {
|
||||||
|
"version": "1.0.0",
|
||||||
|
"resolved": "https://registry.npmjs.org/spdx-compare/-/spdx-compare-1.0.0.tgz",
|
||||||
|
"integrity": "sha512-C1mDZOX0hnu0ep9dfmuoi03+eOdDoz2yvK79RxbcrVEG1NO1Ph35yW102DHWKN4pk80nwCgeMmSY5L25VE4D9A==",
|
||||||
|
"dependencies": {
|
||||||
|
"array-find-index": "^1.0.2",
|
||||||
|
"spdx-expression-parse": "^3.0.0",
|
||||||
|
"spdx-ranges": "^2.0.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/spdx-exceptions": {
|
||||||
|
"version": "2.3.0",
|
||||||
|
"resolved": "https://registry.npmjs.org/spdx-exceptions/-/spdx-exceptions-2.3.0.tgz",
|
||||||
|
"integrity": "sha512-/tTrYOC7PPI1nUAgx34hUpqXuyJG+DTHJTnIULG4rDygi4xu/tfgmq1e1cIRwRzwZgo4NLySi+ricLkZkw4i5A=="
|
||||||
|
},
|
||||||
|
"node_modules/spdx-expression-parse": {
|
||||||
|
"version": "3.0.1",
|
||||||
|
"resolved": "https://registry.npmjs.org/spdx-expression-parse/-/spdx-expression-parse-3.0.1.tgz",
|
||||||
|
"integrity": "sha512-cbqHunsQWnJNE6KhVSMsMeH5H/L9EpymbzqTQ3uLwNCLZ1Q481oWaofqH7nO6V07xlXwY6PhQdQ2IedWx/ZK4Q==",
|
||||||
|
"dependencies": {
|
||||||
|
"spdx-exceptions": "^2.1.0",
|
||||||
|
"spdx-license-ids": "^3.0.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/spdx-license-ids": {
|
||||||
|
"version": "3.0.12",
|
||||||
|
"resolved": "https://registry.npmjs.org/spdx-license-ids/-/spdx-license-ids-3.0.12.tgz",
|
||||||
|
"integrity": "sha512-rr+VVSXtRhO4OHbXUiAF7xW3Bo9DuuF6C5jH+q/x15j2jniycgKbxU09Hr0WqlSLUs4i4ltHGXqTe7VHclYWyA=="
|
||||||
|
},
|
||||||
|
"node_modules/spdx-ranges": {
|
||||||
|
"version": "2.1.1",
|
||||||
|
"resolved": "https://registry.npmjs.org/spdx-ranges/-/spdx-ranges-2.1.1.tgz",
|
||||||
|
"integrity": "sha512-mcdpQFV7UDAgLpXEE/jOMqvK4LBoO0uTQg0uvXUewmEFhpiZx5yJSZITHB8w1ZahKdhfZqP5GPEOKLyEq5p8XA=="
|
||||||
|
},
|
||||||
|
"node_modules/spdx-satisfies": {
|
||||||
|
"version": "5.0.1",
|
||||||
|
"resolved": "https://registry.npmjs.org/spdx-satisfies/-/spdx-satisfies-5.0.1.tgz",
|
||||||
|
"integrity": "sha512-Nwor6W6gzFp8XX4neaKQ7ChV4wmpSh2sSDemMFSzHxpTw460jxFYeOn+jq4ybnSSw/5sc3pjka9MQPouksQNpw==",
|
||||||
|
"dependencies": {
|
||||||
|
"spdx-compare": "^1.0.0",
|
||||||
|
"spdx-expression-parse": "^3.0.0",
|
||||||
|
"spdx-ranges": "^2.0.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
"node_modules/sprintf-js": {
|
"node_modules/sprintf-js": {
|
||||||
"version": "1.0.3",
|
"version": "1.0.3",
|
||||||
"resolved": "https://registry.npmjs.org/sprintf-js/-/sprintf-js-1.0.3.tgz",
|
"resolved": "https://registry.npmjs.org/sprintf-js/-/sprintf-js-1.0.3.tgz",
|
||||||
@@ -6842,9 +6901,9 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/typescript": {
|
"node_modules/typescript": {
|
||||||
"version": "4.8.3",
|
"version": "4.8.4",
|
||||||
"resolved": "https://registry.npmjs.org/typescript/-/typescript-4.8.3.tgz",
|
"resolved": "https://registry.npmjs.org/typescript/-/typescript-4.8.4.tgz",
|
||||||
"integrity": "sha512-goMHfm00nWPa8UvR/CPSvykqf6dVV8x/dp0c5mFTMTIu0u0FlGWRioyy7Nn0PGAdHxpJZnuO/ut+PpQ8UiHAig==",
|
"integrity": "sha512-QCh+85mCy+h0IGff8r5XWzOVSbBO+KfeYrMQh7NJ58QujwcE22u+NUSmUxqF+un70P9GXKxa2HCNiTTMJknyjQ==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"bin": {
|
"bin": {
|
||||||
"tsc": "bin/tsc",
|
"tsc": "bin/tsc",
|
||||||
@@ -7135,9 +7194,9 @@
|
|||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"node_modules/yaml": {
|
"node_modules/yaml": {
|
||||||
"version": "2.1.1",
|
"version": "2.1.2",
|
||||||
"resolved": "https://registry.npmjs.org/yaml/-/yaml-2.1.1.tgz",
|
"resolved": "https://registry.npmjs.org/yaml/-/yaml-2.1.2.tgz",
|
||||||
"integrity": "sha512-o96x3OPo8GjWeSLF+wOAbrPfhFOGY0W00GNaxCDv+9hkcDJEnev1yh8S7pgHF0ik6zc8sQLuL8hjHjJULZp8bw==",
|
"integrity": "sha512-VSdf2/K3FqAetooKQv45Hcu6sA00aDgWZeGcG6V9IYJnVLTnb6988Tie79K5nx2vK7cEpf+yW8Oy+7iPAbdiHA==",
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">= 14"
|
"node": ">= 14"
|
||||||
}
|
}
|
||||||
@@ -7192,18 +7251,18 @@
|
|||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/core": {
|
"@actions/core": {
|
||||||
"version": "1.9.1",
|
"version": "1.10.0",
|
||||||
"resolved": "https://registry.npmjs.org/@actions/core/-/core-1.9.1.tgz",
|
"resolved": "https://registry.npmjs.org/@actions/core/-/core-1.10.0.tgz",
|
||||||
"integrity": "sha512-5ad+U2YGrmmiw6du20AQW5XuWo7UKN2052FjSV7MX+Wfjf8sCqcsZe62NfgHys4QI4/Y+vQvLKYL8jWtA1ZBTA==",
|
"integrity": "sha512-2aZDDa3zrrZbP5ZYg159sNoLRb61nQ7awl5pSvIq5Qpj81vwDzdMRKzkWJGJuwVvWpvZKx7vspJALyvaaIQyug==",
|
||||||
"requires": {
|
"requires": {
|
||||||
"@actions/http-client": "^2.0.1",
|
"@actions/http-client": "^2.0.1",
|
||||||
"uuid": "^8.3.2"
|
"uuid": "^8.3.2"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"@actions/github": {
|
"@actions/github": {
|
||||||
"version": "5.0.3",
|
"version": "5.1.1",
|
||||||
"resolved": "https://registry.npmjs.org/@actions/github/-/github-5.0.3.tgz",
|
"resolved": "https://registry.npmjs.org/@actions/github/-/github-5.1.1.tgz",
|
||||||
"integrity": "sha512-myjA/pdLQfhUGLtRZC/J4L1RXOG4o6aYdiEq+zr5wVVKljzbFld+xv10k1FX6IkIJtNxbAq44BdwSNpQ015P0A==",
|
"integrity": "sha512-Nk59rMDoJaV+mHCOJPXuvB1zIbomlKS0dmSIqPGxd0enAXBnOfn4VWF+CGtRCwXZG9Epa54tZA7VIRlJDS8A6g==",
|
||||||
"requires": {
|
"requires": {
|
||||||
"@actions/http-client": "^2.0.1",
|
"@actions/http-client": "^2.0.1",
|
||||||
"@octokit/core": "^3.6.0",
|
"@octokit/core": "^3.6.0",
|
||||||
@@ -7705,9 +7764,9 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"@humanwhocodes/config-array": {
|
"@humanwhocodes/config-array": {
|
||||||
"version": "0.10.4",
|
"version": "0.10.5",
|
||||||
"resolved": "https://registry.npmjs.org/@humanwhocodes/config-array/-/config-array-0.10.4.tgz",
|
"resolved": "https://registry.npmjs.org/@humanwhocodes/config-array/-/config-array-0.10.5.tgz",
|
||||||
"integrity": "sha512-mXAIHxZT3Vcpg83opl1wGlVZ9xydbfZO3r5YfRSH6Gpp2J/PfdBP0wbDa2sO6/qRbcalpoevVyW6A/fI6LfeMw==",
|
"integrity": "sha512-XVVDtp+dVvRxMoxSiSfasYaG02VEe1qH5cKgMQJWhol6HwzbcqoCMJi8dAGoYAO57jhUyhI6cWuRiTcRaDaYug==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"requires": {
|
"requires": {
|
||||||
"@humanwhocodes/object-schema": "^1.2.1",
|
"@humanwhocodes/object-schema": "^1.2.1",
|
||||||
@@ -8275,6 +8334,11 @@
|
|||||||
"@types/node": "*"
|
"@types/node": "*"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"@types/http-cache-semantics": {
|
||||||
|
"version": "4.0.1",
|
||||||
|
"resolved": "https://registry.npmjs.org/@types/http-cache-semantics/-/http-cache-semantics-4.0.1.tgz",
|
||||||
|
"integrity": "sha512-SZs7ekbP8CN0txVG2xVRH6EgKmEm31BOxA07vkFaETzZz1xh+cbt8BcI0slpymvwhx5dlFnQG2rTlPVQn+iRPQ=="
|
||||||
|
},
|
||||||
"@types/istanbul-lib-coverage": {
|
"@types/istanbul-lib-coverage": {
|
||||||
"version": "2.0.3",
|
"version": "2.0.3",
|
||||||
"resolved": "https://registry.npmjs.org/@types/istanbul-lib-coverage/-/istanbul-lib-coverage-2.0.3.tgz",
|
"resolved": "https://registry.npmjs.org/@types/istanbul-lib-coverage/-/istanbul-lib-coverage-2.0.3.tgz",
|
||||||
@@ -8312,9 +8376,9 @@
|
|||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"@types/node": {
|
"@types/node": {
|
||||||
"version": "16.11.59",
|
"version": "16.11.63",
|
||||||
"resolved": "https://registry.npmjs.org/@types/node/-/node-16.11.59.tgz",
|
"resolved": "https://registry.npmjs.org/@types/node/-/node-16.11.63.tgz",
|
||||||
"integrity": "sha512-6u+36Dj3aDzhfBVUf/mfmc92OEdzQ2kx2jcXGdigfl70E/neV21ZHE6UCz4MDzTRcVqGAM27fk+DLXvyDsn3Jw==",
|
"integrity": "sha512-3OxnrEQLBz8EIIaHpg3CibmTAEGkDBcHY4fL5cnBwg2vd2yvHrUDGWxK+MlYPeXWWIoJJW79dGtU+oeBr6166Q==",
|
||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"@types/prettier": {
|
"@types/prettier": {
|
||||||
@@ -8345,14 +8409,14 @@
|
|||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"@typescript-eslint/eslint-plugin": {
|
"@typescript-eslint/eslint-plugin": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/eslint-plugin/-/eslint-plugin-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/eslint-plugin/-/eslint-plugin-5.38.1.tgz",
|
||||||
"integrity": "sha512-GgHi/GNuUbTOeoJiEANi0oI6fF3gBQc3bGFYj40nnAPCbhrtEDf2rjBmefFadweBmO1Du1YovHeDP2h5JLhtTQ==",
|
"integrity": "sha512-ky7EFzPhqz3XlhS7vPOoMDaQnQMn+9o5ICR9CPr/6bw8HrFkzhMSxuA3gRfiJVvs7geYrSeawGJjZoZQKCOglQ==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"requires": {
|
"requires": {
|
||||||
"@typescript-eslint/scope-manager": "5.38.0",
|
"@typescript-eslint/scope-manager": "5.38.1",
|
||||||
"@typescript-eslint/type-utils": "5.38.0",
|
"@typescript-eslint/type-utils": "5.38.1",
|
||||||
"@typescript-eslint/utils": "5.38.0",
|
"@typescript-eslint/utils": "5.38.1",
|
||||||
"debug": "^4.3.4",
|
"debug": "^4.3.4",
|
||||||
"ignore": "^5.2.0",
|
"ignore": "^5.2.0",
|
||||||
"regexpp": "^3.2.0",
|
"regexpp": "^3.2.0",
|
||||||
@@ -8372,53 +8436,53 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"@typescript-eslint/parser": {
|
"@typescript-eslint/parser": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/parser/-/parser-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/parser/-/parser-5.38.1.tgz",
|
||||||
"integrity": "sha512-/F63giJGLDr0ms1Cr8utDAxP2SPiglaD6V+pCOcG35P2jCqdfR7uuEhz1GIC3oy4hkUF8xA1XSXmd9hOh/a5EA==",
|
"integrity": "sha512-LDqxZBVFFQnQRz9rUZJhLmox+Ep5kdUmLatLQnCRR6523YV+XhRjfYzStQ4MheFA8kMAfUlclHSbu+RKdRwQKw==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"requires": {
|
"requires": {
|
||||||
"@typescript-eslint/scope-manager": "5.38.0",
|
"@typescript-eslint/scope-manager": "5.38.1",
|
||||||
"@typescript-eslint/types": "5.38.0",
|
"@typescript-eslint/types": "5.38.1",
|
||||||
"@typescript-eslint/typescript-estree": "5.38.0",
|
"@typescript-eslint/typescript-estree": "5.38.1",
|
||||||
"debug": "^4.3.4"
|
"debug": "^4.3.4"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"@typescript-eslint/scope-manager": {
|
"@typescript-eslint/scope-manager": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/scope-manager/-/scope-manager-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/scope-manager/-/scope-manager-5.38.1.tgz",
|
||||||
"integrity": "sha512-ByhHIuNyKD9giwkkLqzezZ9y5bALW8VNY6xXcP+VxoH4JBDKjU5WNnsiD4HJdglHECdV+lyaxhvQjTUbRboiTA==",
|
"integrity": "sha512-BfRDq5RidVU3RbqApKmS7RFMtkyWMM50qWnDAkKgQiezRtLKsoyRKIvz1Ok5ilRWeD9IuHvaidaLxvGx/2eqTQ==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"requires": {
|
"requires": {
|
||||||
"@typescript-eslint/types": "5.38.0",
|
"@typescript-eslint/types": "5.38.1",
|
||||||
"@typescript-eslint/visitor-keys": "5.38.0"
|
"@typescript-eslint/visitor-keys": "5.38.1"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"@typescript-eslint/type-utils": {
|
"@typescript-eslint/type-utils": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/type-utils/-/type-utils-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/type-utils/-/type-utils-5.38.1.tgz",
|
||||||
"integrity": "sha512-iZq5USgybUcj/lfnbuelJ0j3K9dbs1I3RICAJY9NZZpDgBYXmuUlYQGzftpQA9wC8cKgtS6DASTvF3HrXwwozA==",
|
"integrity": "sha512-UU3j43TM66gYtzo15ivK2ZFoDFKKP0k03MItzLdq0zV92CeGCXRfXlfQX5ILdd4/DSpHkSjIgLLLh1NtkOJOAw==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"requires": {
|
"requires": {
|
||||||
"@typescript-eslint/typescript-estree": "5.38.0",
|
"@typescript-eslint/typescript-estree": "5.38.1",
|
||||||
"@typescript-eslint/utils": "5.38.0",
|
"@typescript-eslint/utils": "5.38.1",
|
||||||
"debug": "^4.3.4",
|
"debug": "^4.3.4",
|
||||||
"tsutils": "^3.21.0"
|
"tsutils": "^3.21.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"@typescript-eslint/types": {
|
"@typescript-eslint/types": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/types/-/types-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/types/-/types-5.38.1.tgz",
|
||||||
"integrity": "sha512-HHu4yMjJ7i3Cb+8NUuRCdOGu2VMkfmKyIJsOr9PfkBVYLYrtMCK/Ap50Rpov+iKpxDTfnqvDbuPLgBE5FwUNfA==",
|
"integrity": "sha512-QTW1iHq1Tffp9lNfbfPm4WJabbvpyaehQ0SrvVK2yfV79SytD9XDVxqiPvdrv2LK7DGSFo91TB2FgWanbJAZXg==",
|
||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"@typescript-eslint/typescript-estree": {
|
"@typescript-eslint/typescript-estree": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/typescript-estree/-/typescript-estree-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/typescript-estree/-/typescript-estree-5.38.1.tgz",
|
||||||
"integrity": "sha512-6P0RuphkR+UuV7Avv7MU3hFoWaGcrgOdi8eTe1NwhMp2/GjUJoODBTRWzlHpZh6lFOaPmSvgxGlROa0Sg5Zbyg==",
|
"integrity": "sha512-99b5e/Enoe8fKMLdSuwrfH/C0EIbpUWmeEKHmQlGZb8msY33qn1KlkFww0z26o5Omx7EVjzVDCWEfrfCDHfE7g==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"requires": {
|
"requires": {
|
||||||
"@typescript-eslint/types": "5.38.0",
|
"@typescript-eslint/types": "5.38.1",
|
||||||
"@typescript-eslint/visitor-keys": "5.38.0",
|
"@typescript-eslint/visitor-keys": "5.38.1",
|
||||||
"debug": "^4.3.4",
|
"debug": "^4.3.4",
|
||||||
"globby": "^11.1.0",
|
"globby": "^11.1.0",
|
||||||
"is-glob": "^4.0.3",
|
"is-glob": "^4.0.3",
|
||||||
@@ -8438,26 +8502,26 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"@typescript-eslint/utils": {
|
"@typescript-eslint/utils": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/utils/-/utils-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/utils/-/utils-5.38.1.tgz",
|
||||||
"integrity": "sha512-6sdeYaBgk9Fh7N2unEXGz+D+som2QCQGPAf1SxrkEr+Z32gMreQ0rparXTNGRRfYUWk/JzbGdcM8NSSd6oqnTA==",
|
"integrity": "sha512-oIuUiVxPBsndrN81oP8tXnFa/+EcZ03qLqPDfSZ5xIJVm7A9V0rlkQwwBOAGtrdN70ZKDlKv+l1BeT4eSFxwXA==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"requires": {
|
"requires": {
|
||||||
"@types/json-schema": "^7.0.9",
|
"@types/json-schema": "^7.0.9",
|
||||||
"@typescript-eslint/scope-manager": "5.38.0",
|
"@typescript-eslint/scope-manager": "5.38.1",
|
||||||
"@typescript-eslint/types": "5.38.0",
|
"@typescript-eslint/types": "5.38.1",
|
||||||
"@typescript-eslint/typescript-estree": "5.38.0",
|
"@typescript-eslint/typescript-estree": "5.38.1",
|
||||||
"eslint-scope": "^5.1.1",
|
"eslint-scope": "^5.1.1",
|
||||||
"eslint-utils": "^3.0.0"
|
"eslint-utils": "^3.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"@typescript-eslint/visitor-keys": {
|
"@typescript-eslint/visitor-keys": {
|
||||||
"version": "5.38.0",
|
"version": "5.38.1",
|
||||||
"resolved": "https://registry.npmjs.org/@typescript-eslint/visitor-keys/-/visitor-keys-5.38.0.tgz",
|
"resolved": "https://registry.npmjs.org/@typescript-eslint/visitor-keys/-/visitor-keys-5.38.1.tgz",
|
||||||
"integrity": "sha512-MxnrdIyArnTi+XyFLR+kt/uNAcdOnmT+879os7qDRI+EYySR4crXJq9BXPfRzzLGq0wgxkwidrCJ9WCAoacm1w==",
|
"integrity": "sha512-bSHr1rRxXt54+j2n4k54p4fj8AHJ49VDWtjpImOpzQj4qjAiOpPni+V1Tyajh19Api1i844F757cur8wH3YvOA==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"requires": {
|
"requires": {
|
||||||
"@typescript-eslint/types": "5.38.0",
|
"@typescript-eslint/types": "5.38.1",
|
||||||
"eslint-visitor-keys": "^3.3.0"
|
"eslint-visitor-keys": "^3.3.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
@@ -8591,6 +8655,11 @@
|
|||||||
"@babel/runtime-corejs3": "^7.10.2"
|
"@babel/runtime-corejs3": "^7.10.2"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"array-find-index": {
|
||||||
|
"version": "1.0.2",
|
||||||
|
"resolved": "https://registry.npmjs.org/array-find-index/-/array-find-index-1.0.2.tgz",
|
||||||
|
"integrity": "sha512-M1HQyIXcBGtVywBt8WVdim+lrNaK7VHp99Qt5pSNziXznKHViIBbXWtfRTpEFpF/c4FdfxNAsCCwPp5phBYJtw=="
|
||||||
|
},
|
||||||
"array-includes": {
|
"array-includes": {
|
||||||
"version": "3.1.5",
|
"version": "3.1.5",
|
||||||
"resolved": "https://registry.npmjs.org/array-includes/-/array-includes-3.1.5.tgz",
|
"resolved": "https://registry.npmjs.org/array-includes/-/array-includes-3.1.5.tgz",
|
||||||
@@ -8801,15 +8870,16 @@
|
|||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"cacheable-lookup": {
|
"cacheable-lookup": {
|
||||||
"version": "6.0.4",
|
"version": "7.0.0",
|
||||||
"resolved": "https://registry.npmjs.org/cacheable-lookup/-/cacheable-lookup-6.0.4.tgz",
|
"resolved": "https://registry.npmjs.org/cacheable-lookup/-/cacheable-lookup-7.0.0.tgz",
|
||||||
"integrity": "sha512-mbcDEZCkv2CZF4G01kr8eBd/5agkt9oCqz75tJMSIsquvRZ2sL6Hi5zGVKi/0OSC9oO1GHfJ2AV0ZIOY9vye0A=="
|
"integrity": "sha512-+qJyx4xiKra8mZrcwhjMRMUhD5NR1R8esPkzIYxX96JiecFoxAXFuz/GpR3+ev4PE1WamHip78wV0vcmPQtp8w=="
|
||||||
},
|
},
|
||||||
"cacheable-request": {
|
"cacheable-request": {
|
||||||
"version": "10.1.2",
|
"version": "10.2.1",
|
||||||
"resolved": "https://registry.npmjs.org/cacheable-request/-/cacheable-request-10.1.2.tgz",
|
"resolved": "https://registry.npmjs.org/cacheable-request/-/cacheable-request-10.2.1.tgz",
|
||||||
"integrity": "sha512-N7F4os5ZI+8mWHSbeJmxn+qimf5uK3WU53FD1b298XLGtOLPpSA/1xAchfP4NJlDwqgaviZ0SQfxTQD0K6lr9w==",
|
"integrity": "sha512-3tLJyBjGuXw1s5gpKFSG3iS4kaKT4id04dZi98wzHQp/8cqZNweBnrF9J+rrlvrf4M53OdtDGNctNHFias8BEA==",
|
||||||
"requires": {
|
"requires": {
|
||||||
|
"@types/http-cache-semantics": "^4.0.1",
|
||||||
"get-stream": "^6.0.1",
|
"get-stream": "^6.0.1",
|
||||||
"http-cache-semantics": "^4.1.0",
|
"http-cache-semantics": "^4.1.0",
|
||||||
"keyv": "^4.5.0",
|
"keyv": "^4.5.0",
|
||||||
@@ -9287,13 +9357,13 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"eslint": {
|
"eslint": {
|
||||||
"version": "8.23.1",
|
"version": "8.24.0",
|
||||||
"resolved": "https://registry.npmjs.org/eslint/-/eslint-8.23.1.tgz",
|
"resolved": "https://registry.npmjs.org/eslint/-/eslint-8.24.0.tgz",
|
||||||
"integrity": "sha512-w7C1IXCc6fNqjpuYd0yPlcTKKmHlHHktRkzmBPZ+7cvNBQuiNjx0xaMTjAJGCafJhQkrFJooREv0CtrVzmHwqg==",
|
"integrity": "sha512-dWFaPhGhTAiPcCgm3f6LI2MBWbogMnTJzFBbhXVRQDJPkr9pGZvVjlVfXd+vyDcWPA2Ic9L2AXPIQM0+vk/cSQ==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"requires": {
|
"requires": {
|
||||||
"@eslint/eslintrc": "^1.3.2",
|
"@eslint/eslintrc": "^1.3.2",
|
||||||
"@humanwhocodes/config-array": "^0.10.4",
|
"@humanwhocodes/config-array": "^0.10.5",
|
||||||
"@humanwhocodes/gitignore-to-minimatch": "^1.0.2",
|
"@humanwhocodes/gitignore-to-minimatch": "^1.0.2",
|
||||||
"@humanwhocodes/module-importer": "^1.0.1",
|
"@humanwhocodes/module-importer": "^1.0.1",
|
||||||
"ajv": "^6.10.0",
|
"ajv": "^6.10.0",
|
||||||
@@ -10044,14 +10114,14 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"got": {
|
"got": {
|
||||||
"version": "12.5.0",
|
"version": "12.5.1",
|
||||||
"resolved": "https://registry.npmjs.org/got/-/got-12.5.0.tgz",
|
"resolved": "https://registry.npmjs.org/got/-/got-12.5.1.tgz",
|
||||||
"integrity": "sha512-/Bneo/L6bLN1wDyJCeRZ3CLoixvwb9v3rE3IHulFSfTHwP85xSr4QatA8K0c6GlL5+mc4IZ57BzluNZJiXvHIg==",
|
"integrity": "sha512-sD16AK8cCyUoPtKr/NMvLTFFa+T3i3S+zoiuvhq0HP2YiqBZA9AtlBjAdsQBsLBK7slPuvmfE0OxhGi7N5dD4w==",
|
||||||
"requires": {
|
"requires": {
|
||||||
"@sindresorhus/is": "^5.2.0",
|
"@sindresorhus/is": "^5.2.0",
|
||||||
"@szmarczak/http-timer": "^5.0.1",
|
"@szmarczak/http-timer": "^5.0.1",
|
||||||
"cacheable-lookup": "^6.0.4",
|
"cacheable-lookup": "^7.0.0",
|
||||||
"cacheable-request": "^10.1.2",
|
"cacheable-request": "^10.2.1",
|
||||||
"decompress-response": "^6.0.0",
|
"decompress-response": "^6.0.0",
|
||||||
"form-data-encoder": "^2.1.2",
|
"form-data-encoder": "^2.1.2",
|
||||||
"get-stream": "^6.0.1",
|
"get-stream": "^6.0.1",
|
||||||
@@ -11481,9 +11551,9 @@
|
|||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"normalize-url": {
|
"normalize-url": {
|
||||||
"version": "7.1.0",
|
"version": "7.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/normalize-url/-/normalize-url-7.1.0.tgz",
|
"resolved": "https://registry.npmjs.org/normalize-url/-/normalize-url-7.2.0.tgz",
|
||||||
"integrity": "sha512-JgkdydFdLe1E5Q7DpLvKVyBZOOwXYGhIbMbOMm3lJ06XKzaiit+qo1HciO3z3IFklStfarzJHVQf9ZcNPTvZlw=="
|
"integrity": "sha512-uhXOdZry0L6M2UIo9BTt7FdpBDiAGN/7oItedQwPKh8jh31ZlvC8U9Xl/EJ3aijDHaywXTW3QbZ6LuCocur1YA=="
|
||||||
},
|
},
|
||||||
"npm-run-path": {
|
"npm-run-path": {
|
||||||
"version": "4.0.1",
|
"version": "4.0.1",
|
||||||
@@ -11982,6 +12052,50 @@
|
|||||||
"source-map": "^0.6.0"
|
"source-map": "^0.6.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"spdx-compare": {
|
||||||
|
"version": "1.0.0",
|
||||||
|
"resolved": "https://registry.npmjs.org/spdx-compare/-/spdx-compare-1.0.0.tgz",
|
||||||
|
"integrity": "sha512-C1mDZOX0hnu0ep9dfmuoi03+eOdDoz2yvK79RxbcrVEG1NO1Ph35yW102DHWKN4pk80nwCgeMmSY5L25VE4D9A==",
|
||||||
|
"requires": {
|
||||||
|
"array-find-index": "^1.0.2",
|
||||||
|
"spdx-expression-parse": "^3.0.0",
|
||||||
|
"spdx-ranges": "^2.0.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"spdx-exceptions": {
|
||||||
|
"version": "2.3.0",
|
||||||
|
"resolved": "https://registry.npmjs.org/spdx-exceptions/-/spdx-exceptions-2.3.0.tgz",
|
||||||
|
"integrity": "sha512-/tTrYOC7PPI1nUAgx34hUpqXuyJG+DTHJTnIULG4rDygi4xu/tfgmq1e1cIRwRzwZgo4NLySi+ricLkZkw4i5A=="
|
||||||
|
},
|
||||||
|
"spdx-expression-parse": {
|
||||||
|
"version": "3.0.1",
|
||||||
|
"resolved": "https://registry.npmjs.org/spdx-expression-parse/-/spdx-expression-parse-3.0.1.tgz",
|
||||||
|
"integrity": "sha512-cbqHunsQWnJNE6KhVSMsMeH5H/L9EpymbzqTQ3uLwNCLZ1Q481oWaofqH7nO6V07xlXwY6PhQdQ2IedWx/ZK4Q==",
|
||||||
|
"requires": {
|
||||||
|
"spdx-exceptions": "^2.1.0",
|
||||||
|
"spdx-license-ids": "^3.0.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"spdx-license-ids": {
|
||||||
|
"version": "3.0.12",
|
||||||
|
"resolved": "https://registry.npmjs.org/spdx-license-ids/-/spdx-license-ids-3.0.12.tgz",
|
||||||
|
"integrity": "sha512-rr+VVSXtRhO4OHbXUiAF7xW3Bo9DuuF6C5jH+q/x15j2jniycgKbxU09Hr0WqlSLUs4i4ltHGXqTe7VHclYWyA=="
|
||||||
|
},
|
||||||
|
"spdx-ranges": {
|
||||||
|
"version": "2.1.1",
|
||||||
|
"resolved": "https://registry.npmjs.org/spdx-ranges/-/spdx-ranges-2.1.1.tgz",
|
||||||
|
"integrity": "sha512-mcdpQFV7UDAgLpXEE/jOMqvK4LBoO0uTQg0uvXUewmEFhpiZx5yJSZITHB8w1ZahKdhfZqP5GPEOKLyEq5p8XA=="
|
||||||
|
},
|
||||||
|
"spdx-satisfies": {
|
||||||
|
"version": "5.0.1",
|
||||||
|
"resolved": "https://registry.npmjs.org/spdx-satisfies/-/spdx-satisfies-5.0.1.tgz",
|
||||||
|
"integrity": "sha512-Nwor6W6gzFp8XX4neaKQ7ChV4wmpSh2sSDemMFSzHxpTw460jxFYeOn+jq4ybnSSw/5sc3pjka9MQPouksQNpw==",
|
||||||
|
"requires": {
|
||||||
|
"spdx-compare": "^1.0.0",
|
||||||
|
"spdx-expression-parse": "^3.0.0",
|
||||||
|
"spdx-ranges": "^2.0.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
"sprintf-js": {
|
"sprintf-js": {
|
||||||
"version": "1.0.3",
|
"version": "1.0.3",
|
||||||
"resolved": "https://registry.npmjs.org/sprintf-js/-/sprintf-js-1.0.3.tgz",
|
"resolved": "https://registry.npmjs.org/sprintf-js/-/sprintf-js-1.0.3.tgz",
|
||||||
@@ -12290,9 +12404,9 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"typescript": {
|
"typescript": {
|
||||||
"version": "4.8.3",
|
"version": "4.8.4",
|
||||||
"resolved": "https://registry.npmjs.org/typescript/-/typescript-4.8.3.tgz",
|
"resolved": "https://registry.npmjs.org/typescript/-/typescript-4.8.4.tgz",
|
||||||
"integrity": "sha512-goMHfm00nWPa8UvR/CPSvykqf6dVV8x/dp0c5mFTMTIu0u0FlGWRioyy7Nn0PGAdHxpJZnuO/ut+PpQ8UiHAig==",
|
"integrity": "sha512-QCh+85mCy+h0IGff8r5XWzOVSbBO+KfeYrMQh7NJ58QujwcE22u+NUSmUxqF+un70P9GXKxa2HCNiTTMJknyjQ==",
|
||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"unbox-primitive": {
|
"unbox-primitive": {
|
||||||
@@ -12515,9 +12629,9 @@
|
|||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"yaml": {
|
"yaml": {
|
||||||
"version": "2.1.1",
|
"version": "2.1.2",
|
||||||
"resolved": "https://registry.npmjs.org/yaml/-/yaml-2.1.1.tgz",
|
"resolved": "https://registry.npmjs.org/yaml/-/yaml-2.1.2.tgz",
|
||||||
"integrity": "sha512-o96x3OPo8GjWeSLF+wOAbrPfhFOGY0W00GNaxCDv+9hkcDJEnev1yh8S7pgHF0ik6zc8sQLuL8hjHjJULZp8bw=="
|
"integrity": "sha512-VSdf2/K3FqAetooKQv45Hcu6sA00aDgWZeGcG6V9IYJnVLTnb6988Tie79K5nx2vK7cEpf+yW8Oy+7iPAbdiHA=="
|
||||||
},
|
},
|
||||||
"yargs": {
|
"yargs": {
|
||||||
"version": "16.2.0",
|
"version": "16.2.0",
|
||||||
|
|||||||
+11
-10
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "dependency-review-action",
|
"name": "dependency-review-action",
|
||||||
"version": "2.2.0",
|
"version": "2.4.0",
|
||||||
"private": true,
|
"private": true,
|
||||||
"description": "A GitHub Action for Dependency Review",
|
"description": "A GitHub Action for Dependency Review",
|
||||||
"main": "lib/main.js",
|
"main": "lib/main.js",
|
||||||
@@ -25,23 +25,24 @@
|
|||||||
"author": "GitHub",
|
"author": "GitHub",
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/core": "^1.9.1",
|
"@actions/core": "^1.10.0",
|
||||||
"@actions/github": "^5.0.3",
|
"@actions/github": "^5.1.1",
|
||||||
"@octokit/plugin-retry": "^3.0.9",
|
"@octokit/plugin-retry": "^3.0.9",
|
||||||
"@octokit/request-error": "^3.0.1",
|
"@octokit/request-error": "^3.0.1",
|
||||||
"ansi-styles": "^6.1.1",
|
"ansi-styles": "^6.1.1",
|
||||||
"got": "^12.5.0",
|
"got": "^12.5.1",
|
||||||
"nodemon": "^2.0.20",
|
"nodemon": "^2.0.20",
|
||||||
"yaml": "^2.1.1",
|
"spdx-satisfies": "^5.0.1",
|
||||||
|
"yaml": "^2.1.2",
|
||||||
"zod": "^3.19.1"
|
"zod": "^3.19.1"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@types/node": "^16.11.59",
|
"@types/node": "^16.11.63",
|
||||||
"@typescript-eslint/eslint-plugin": "^5.38.0",
|
"@typescript-eslint/eslint-plugin": "^5.38.1",
|
||||||
"@typescript-eslint/parser": "^5.38.0",
|
"@typescript-eslint/parser": "^5.38.1",
|
||||||
"@vercel/ncc": "^0.34.0",
|
"@vercel/ncc": "^0.34.0",
|
||||||
"esbuild-register": "^3.3.3",
|
"esbuild-register": "^3.3.3",
|
||||||
"eslint": "^8.23.1",
|
"eslint": "^8.24.0",
|
||||||
"eslint-plugin-github": "^4.3.7",
|
"eslint-plugin-github": "^4.3.7",
|
||||||
"eslint-plugin-jest": "^27.0.4",
|
"eslint-plugin-jest": "^27.0.4",
|
||||||
"jest": "^27.5.1",
|
"jest": "^27.5.1",
|
||||||
@@ -49,6 +50,6 @@
|
|||||||
"nodemon": "^2.0.20",
|
"nodemon": "^2.0.20",
|
||||||
"prettier": "2.7.1",
|
"prettier": "2.7.1",
|
||||||
"ts-jest": "^27.1.4",
|
"ts-jest": "^27.1.4",
|
||||||
"typescript": "^4.8.3"
|
"typescript": "^4.8.4"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+7
-4
@@ -47,21 +47,24 @@ export function readInlineConfig(): ConfigurationOptions {
|
|||||||
.default(['runtime'])
|
.default(['runtime'])
|
||||||
.parse(parseList(getOptionalInput('fail-on-scopes')))
|
.parse(parseList(getOptionalInput('fail-on-scopes')))
|
||||||
|
|
||||||
const allow_licenses = getOptionalInput('allow-licenses')
|
const allow_licenses = parseList(getOptionalInput('allow-licenses'))
|
||||||
const deny_licenses = getOptionalInput('deny-licenses')
|
const deny_licenses = parseList(getOptionalInput('deny-licenses'))
|
||||||
|
|
||||||
if (allow_licenses !== undefined && deny_licenses !== undefined) {
|
if (allow_licenses !== undefined && deny_licenses !== undefined) {
|
||||||
throw new Error("Can't specify both allow_licenses and deny_licenses")
|
throw new Error("Can't specify both allow_licenses and deny_licenses")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const allow_ghsas = parseList(getOptionalInput('allow-ghsas'))
|
||||||
|
|
||||||
const base_ref = getOptionalInput('base-ref')
|
const base_ref = getOptionalInput('base-ref')
|
||||||
const head_ref = getOptionalInput('head-ref')
|
const head_ref = getOptionalInput('head-ref')
|
||||||
|
|
||||||
return {
|
return {
|
||||||
fail_on_severity,
|
fail_on_severity,
|
||||||
fail_on_scopes,
|
fail_on_scopes,
|
||||||
allow_licenses: parseList(allow_licenses),
|
allow_licenses,
|
||||||
deny_licenses: parseList(deny_licenses),
|
deny_licenses,
|
||||||
|
allow_ghsas,
|
||||||
base_ref,
|
base_ref,
|
||||||
head_ref
|
head_ref
|
||||||
}
|
}
|
||||||
|
|||||||
+37
-1
@@ -35,9 +35,13 @@ export function filterChangesBySeverity(
|
|||||||
}
|
}
|
||||||
|
|
||||||
export function filterChangesByScopes(
|
export function filterChangesByScopes(
|
||||||
scopes: Scope[],
|
scopes: Scope[] | undefined,
|
||||||
changes: Changes
|
changes: Changes
|
||||||
): Changes {
|
): Changes {
|
||||||
|
if (scopes === undefined) {
|
||||||
|
return []
|
||||||
|
}
|
||||||
|
|
||||||
const filteredChanges = changes.filter(change => {
|
const filteredChanges = changes.filter(change => {
|
||||||
// if there is no scope on the change (Enterprise Server API for now), we will assume it is a runtime scope
|
// if there is no scope on the change (Enterprise Server API for now), we will assume it is a runtime scope
|
||||||
const scope = change.scope || 'runtime'
|
const scope = change.scope || 'runtime'
|
||||||
@@ -46,3 +50,35 @@ export function filterChangesByScopes(
|
|||||||
|
|
||||||
return filteredChanges
|
return filteredChanges
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export function filterOutAllowedAdvisories(
|
||||||
|
ghsas: string[] | undefined,
|
||||||
|
changes: Changes
|
||||||
|
): Changes {
|
||||||
|
if (ghsas === undefined) {
|
||||||
|
return []
|
||||||
|
}
|
||||||
|
|
||||||
|
const filteredChanges = changes.filter(change => {
|
||||||
|
const noAdvisories =
|
||||||
|
change.vulnerabilities === undefined ||
|
||||||
|
change.vulnerabilities.length === 0
|
||||||
|
|
||||||
|
if (noAdvisories) {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
|
||||||
|
let allAllowedAdvisories = true
|
||||||
|
// if there's at least one advisory that is not allowlisted, we will keep the change
|
||||||
|
for (const vulnerability of change.vulnerabilities) {
|
||||||
|
if (!ghsas.includes(vulnerability.advisory_ghsa_id)) {
|
||||||
|
allAllowedAdvisories = false
|
||||||
|
}
|
||||||
|
if (!allAllowedAdvisories) {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
})
|
||||||
|
|
||||||
|
return filteredChanges
|
||||||
|
}
|
||||||
|
|||||||
+112
-53
@@ -3,13 +3,19 @@ import * as dependencyGraph from './dependency-graph'
|
|||||||
import * as github from '@actions/github'
|
import * as github from '@actions/github'
|
||||||
import styles from 'ansi-styles'
|
import styles from 'ansi-styles'
|
||||||
import {RequestError} from '@octokit/request-error'
|
import {RequestError} from '@octokit/request-error'
|
||||||
import {Change, Severity, Scope} from './schemas'
|
import {Change, Severity, Changes} from './schemas'
|
||||||
import {readConfig} from '../src/config'
|
import {readConfig} from '../src/config'
|
||||||
import {filterChangesBySeverity, filterChangesByScopes} from '../src/filter'
|
import {
|
||||||
|
filterChangesBySeverity,
|
||||||
|
filterChangesByScopes,
|
||||||
|
filterOutAllowedAdvisories
|
||||||
|
} from '../src/filter'
|
||||||
import {getDeniedLicenseChanges} from './licenses'
|
import {getDeniedLicenseChanges} from './licenses'
|
||||||
import * as summary from './summary'
|
import * as summary from './summary'
|
||||||
import {getRefs} from './git-refs'
|
import {getRefs} from './git-refs'
|
||||||
|
|
||||||
|
import {groupDependenciesByManifest} from './utils'
|
||||||
|
|
||||||
async function run(): Promise<void> {
|
async function run(): Promise<void> {
|
||||||
try {
|
try {
|
||||||
const config = readConfig()
|
const config = readConfig()
|
||||||
@@ -22,21 +28,16 @@ async function run(): Promise<void> {
|
|||||||
headRef: refs.head
|
headRef: refs.head
|
||||||
})
|
})
|
||||||
|
|
||||||
const minSeverity = config.fail_on_severity
|
const minSeverity = config.fail_on_severity as Severity
|
||||||
let failed = false
|
const scopedChanges = filterChangesByScopes(config.fail_on_scopes, changes)
|
||||||
|
const filteredChanges = filterOutAllowedAdvisories(
|
||||||
const licenses = {
|
config.allow_ghsas,
|
||||||
allow: config.allow_licenses,
|
scopedChanges
|
||||||
deny: config.deny_licenses
|
)
|
||||||
}
|
|
||||||
|
|
||||||
const scopes = config.fail_on_scopes
|
|
||||||
|
|
||||||
const scopedChanges = filterChangesByScopes(scopes as Scope[], changes)
|
|
||||||
|
|
||||||
const addedChanges = filterChangesBySeverity(
|
const addedChanges = filterChangesBySeverity(
|
||||||
minSeverity as Severity,
|
minSeverity,
|
||||||
scopedChanges
|
filteredChanges
|
||||||
).filter(
|
).filter(
|
||||||
change =>
|
change =>
|
||||||
change.change_type === 'added' &&
|
change.change_type === 'added' &&
|
||||||
@@ -45,37 +46,21 @@ async function run(): Promise<void> {
|
|||||||
)
|
)
|
||||||
|
|
||||||
const [licenseErrors, unknownLicenses] = getDeniedLicenseChanges(
|
const [licenseErrors, unknownLicenses] = getDeniedLicenseChanges(
|
||||||
scopedChanges,
|
filteredChanges,
|
||||||
licenses
|
{
|
||||||
|
allow: config.allow_licenses,
|
||||||
|
deny: config.deny_licenses
|
||||||
|
}
|
||||||
)
|
)
|
||||||
|
|
||||||
summary.addSummaryToSummary(addedChanges, licenseErrors, unknownLicenses)
|
summary.addSummaryToSummary(addedChanges, licenseErrors, unknownLicenses)
|
||||||
|
summary.addChangeVulnerabilitiesToSummary(addedChanges, minSeverity)
|
||||||
if (addedChanges.length > 0) {
|
|
||||||
for (const change of addedChanges) {
|
|
||||||
printChangeVulnerabilities(change)
|
|
||||||
}
|
|
||||||
failed = true
|
|
||||||
}
|
|
||||||
|
|
||||||
summary.addChangeVulnerabilitiesToSummary(addedChanges, minSeverity || '')
|
|
||||||
|
|
||||||
if (licenseErrors.length > 0) {
|
|
||||||
printLicensesError(licenseErrors)
|
|
||||||
core.setFailed('Dependency review detected incompatible licenses.')
|
|
||||||
}
|
|
||||||
|
|
||||||
printNullLicenses(unknownLicenses)
|
|
||||||
|
|
||||||
summary.addLicensesToSummary(licenseErrors, unknownLicenses, config)
|
summary.addLicensesToSummary(licenseErrors, unknownLicenses, config)
|
||||||
|
summary.addScannedDependencies(changes)
|
||||||
|
|
||||||
if (failed) {
|
printVulnerabilitiesBlock(addedChanges, minSeverity)
|
||||||
core.setFailed('Dependency review detected vulnerable packages.')
|
printLicensesBlock(licenseErrors, unknownLicenses)
|
||||||
} else {
|
printScannedDependencies(changes)
|
||||||
core.info(
|
|
||||||
`Dependency review did not detect any vulnerable packages with severity level "${minSeverity}" or higher.`
|
|
||||||
)
|
|
||||||
}
|
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
if (error instanceof RequestError && error.status === 404) {
|
if (error instanceof RequestError && error.status === 404) {
|
||||||
core.setFailed(
|
core.setFailed(
|
||||||
@@ -97,6 +82,29 @@ async function run(): Promise<void> {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function printVulnerabilitiesBlock(
|
||||||
|
addedChanges: Change[],
|
||||||
|
minSeverity: Severity
|
||||||
|
): void {
|
||||||
|
let failed = false
|
||||||
|
core.group('Vulnerabilities', async () => {
|
||||||
|
if (addedChanges.length > 0) {
|
||||||
|
for (const change of addedChanges) {
|
||||||
|
printChangeVulnerabilities(change)
|
||||||
|
}
|
||||||
|
failed = true
|
||||||
|
}
|
||||||
|
|
||||||
|
if (failed) {
|
||||||
|
core.setFailed('Dependency review detected vulnerable packages.')
|
||||||
|
} else {
|
||||||
|
core.info(
|
||||||
|
`Dependency review did not detect any vulnerable packages with severity level "${minSeverity}" or higher.`
|
||||||
|
)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
function printChangeVulnerabilities(change: Change): void {
|
function printChangeVulnerabilities(change: Change): void {
|
||||||
for (const vuln of change.vulnerabilities) {
|
for (const vuln of change.vulnerabilities) {
|
||||||
core.info(
|
core.info(
|
||||||
@@ -110,18 +118,17 @@ function printChangeVulnerabilities(change: Change): void {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
function renderSeverity(
|
function printLicensesBlock(
|
||||||
severity: 'critical' | 'high' | 'moderate' | 'low'
|
licenseErrors: Change[],
|
||||||
): string {
|
unknownLicenses: Change[]
|
||||||
const color = (
|
): void {
|
||||||
{
|
core.group('Licenses', async () => {
|
||||||
critical: 'red',
|
if (licenseErrors.length > 0) {
|
||||||
high: 'red',
|
printLicensesError(licenseErrors)
|
||||||
moderate: 'yellow',
|
core.setFailed('Dependency review detected incompatible licenses.')
|
||||||
low: 'grey'
|
}
|
||||||
} as const
|
printNullLicenses(unknownLicenses)
|
||||||
)[severity]
|
})
|
||||||
return `${styles.color[color].open}(${severity} severity)${styles.color[color].close}`
|
|
||||||
}
|
}
|
||||||
|
|
||||||
function printLicensesError(changes: Change[]): void {
|
function printLicensesError(changes: Change[]): void {
|
||||||
@@ -150,4 +157,56 @@ function printNullLicenses(changes: Change[]): void {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function renderSeverity(
|
||||||
|
severity: 'critical' | 'high' | 'moderate' | 'low'
|
||||||
|
): string {
|
||||||
|
const color = (
|
||||||
|
{
|
||||||
|
critical: 'red',
|
||||||
|
high: 'red',
|
||||||
|
moderate: 'yellow',
|
||||||
|
low: 'grey'
|
||||||
|
} as const
|
||||||
|
)[severity]
|
||||||
|
return `${styles.color[color].open}(${severity} severity)${styles.color[color].close}`
|
||||||
|
}
|
||||||
|
|
||||||
|
function renderScannedDependency(change: Change): string {
|
||||||
|
const changeType: string = change.change_type
|
||||||
|
|
||||||
|
if (changeType !== 'added' && changeType !== 'removed') {
|
||||||
|
throw new Error(`Unexpected change type: ${changeType}`)
|
||||||
|
}
|
||||||
|
|
||||||
|
const color = (
|
||||||
|
{
|
||||||
|
added: 'green',
|
||||||
|
removed: 'red'
|
||||||
|
} as const
|
||||||
|
)[changeType]
|
||||||
|
|
||||||
|
const icon = (
|
||||||
|
{
|
||||||
|
added: '+',
|
||||||
|
removed: '-'
|
||||||
|
} as const
|
||||||
|
)[changeType]
|
||||||
|
|
||||||
|
return `${styles.color[color].open}${icon} ${change.manifest}@${change.version}${styles.color[color].close}`
|
||||||
|
}
|
||||||
|
|
||||||
|
function printScannedDependencies(changes: Changes): void {
|
||||||
|
core.group('Dependency Changes', async () => {
|
||||||
|
const dependencies = groupDependenciesByManifest(changes)
|
||||||
|
|
||||||
|
for (const manifestName of dependencies.keys()) {
|
||||||
|
const manifestChanges = dependencies.get(manifestName) || []
|
||||||
|
core.info(`File: ${styles.bold.open}${manifestName}${styles.bold.close}`)
|
||||||
|
for (const change of manifestChanges) {
|
||||||
|
core.info(`${renderScannedDependency(change)}`)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
run()
|
run()
|
||||||
|
|||||||
@@ -40,6 +40,7 @@ export const ConfigurationOptionsSchema = z
|
|||||||
fail_on_scopes: z.array(z.enum(SCOPES)).default(['runtime']),
|
fail_on_scopes: z.array(z.enum(SCOPES)).default(['runtime']),
|
||||||
allow_licenses: z.array(z.string()).default([]),
|
allow_licenses: z.array(z.string()).default([]),
|
||||||
deny_licenses: z.array(z.string()).default([]),
|
deny_licenses: z.array(z.string()).default([]),
|
||||||
|
allow_ghsas: z.array(z.string()).default([]),
|
||||||
config_file: z.string().optional().default('false'),
|
config_file: z.string().optional().default('false'),
|
||||||
base_ref: z.string(),
|
base_ref: z.string(),
|
||||||
head_ref: z.string()
|
head_ref: z.string()
|
||||||
|
|||||||
+19
-11
@@ -1,6 +1,7 @@
|
|||||||
import * as core from '@actions/core'
|
import * as core from '@actions/core'
|
||||||
import {ConfigurationOptions, Change, Changes} from './schemas'
|
import {ConfigurationOptions, Change, Changes} from './schemas'
|
||||||
import {SummaryTableRow} from '@actions/core/lib/summary'
|
import {SummaryTableRow} from '@actions/core/lib/summary'
|
||||||
|
import {groupDependenciesByManifest, getManifestsSet, renderUrl} from './utils'
|
||||||
|
|
||||||
export function addSummaryToSummary(
|
export function addSummaryToSummary(
|
||||||
addedPackages: Changes,
|
addedPackages: Changes,
|
||||||
@@ -20,7 +21,7 @@ export function addChangeVulnerabilitiesToSummary(
|
|||||||
): void {
|
): void {
|
||||||
const rows: SummaryTableRow[] = []
|
const rows: SummaryTableRow[] = []
|
||||||
|
|
||||||
const manifests = getManifests(addedPackages)
|
const manifests = getManifestsSet(addedPackages)
|
||||||
|
|
||||||
core.summary
|
core.summary
|
||||||
.addHeading('Vulnerabilities')
|
.addHeading('Vulnerabilities')
|
||||||
@@ -99,7 +100,7 @@ export function addLicensesToSummary(
|
|||||||
|
|
||||||
if (licenseErrors.length > 0) {
|
if (licenseErrors.length > 0) {
|
||||||
const rows: SummaryTableRow[] = []
|
const rows: SummaryTableRow[] = []
|
||||||
const manifests = getManifests(licenseErrors)
|
const manifests = getManifestsSet(licenseErrors)
|
||||||
|
|
||||||
core.summary.addHeading('Incompatible Licenses', 3).addSeparator()
|
core.summary.addHeading('Incompatible Licenses', 3).addSeparator()
|
||||||
|
|
||||||
@@ -125,7 +126,7 @@ export function addLicensesToSummary(
|
|||||||
|
|
||||||
if (unknownLicenses.length > 0) {
|
if (unknownLicenses.length > 0) {
|
||||||
const rows: SummaryTableRow[] = []
|
const rows: SummaryTableRow[] = []
|
||||||
const manifests = getManifests(unknownLicenses)
|
const manifests = getManifestsSet(unknownLicenses)
|
||||||
|
|
||||||
core.debug(
|
core.debug(
|
||||||
`found ${manifests.entries.length} manifests for unknown licenses`
|
`found ${manifests.entries.length} manifests for unknown licenses`
|
||||||
@@ -150,14 +151,21 @@ export function addLicensesToSummary(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
function getManifests(changes: Changes): Set<string> {
|
export function addScannedDependencies(changes: Changes): void {
|
||||||
return new Set(changes.flatMap(c => c.manifest))
|
const dependencies = groupDependenciesByManifest(changes)
|
||||||
}
|
const manifests = dependencies.keys()
|
||||||
|
|
||||||
function renderUrl(url: string | null, text: string): string {
|
const summary = core.summary
|
||||||
if (url) {
|
.addHeading('Scanned Dependencies')
|
||||||
return `<a href="${url}">${text}</a>`
|
.addRaw(`We scanned ${dependencies.size} manifest files:`)
|
||||||
} else {
|
|
||||||
return text
|
for (const manifest of manifests) {
|
||||||
|
const deps = dependencies.get(manifest)
|
||||||
|
if (deps) {
|
||||||
|
const dependencyNames = deps.map(
|
||||||
|
dependency => `<li>${dependency.name}@${dependency.version}</li>`
|
||||||
|
)
|
||||||
|
summary.addRaw(`<h3>${manifest}</h3><ul>${dependencyNames.join('')}</ul>`)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,30 @@
|
|||||||
|
import {Changes} from './schemas'
|
||||||
|
|
||||||
|
export function groupDependenciesByManifest(
|
||||||
|
changes: Changes
|
||||||
|
): Map<string, Changes> {
|
||||||
|
const dependencies: Map<string, Changes> = new Map()
|
||||||
|
for (const change of changes) {
|
||||||
|
const manifestName = change.manifest
|
||||||
|
|
||||||
|
if (dependencies.get(manifestName) === undefined) {
|
||||||
|
dependencies.set(manifestName, [])
|
||||||
|
}
|
||||||
|
|
||||||
|
dependencies.get(manifestName)?.push(change)
|
||||||
|
}
|
||||||
|
|
||||||
|
return dependencies
|
||||||
|
}
|
||||||
|
|
||||||
|
export function getManifestsSet(changes: Changes): Set<string> {
|
||||||
|
return new Set(changes.flatMap(c => c.manifest))
|
||||||
|
}
|
||||||
|
|
||||||
|
export function renderUrl(url: string | null, text: string): string {
|
||||||
|
if (url) {
|
||||||
|
return `<a href="${url}">${text}</a>`
|
||||||
|
} else {
|
||||||
|
return text
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user