Compare commits
140
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0d682fba34 | ||
|
|
84848ebd37 | ||
|
|
9c4df3f574 | ||
|
|
96b82f03c4 | ||
|
|
a340a7a878 | ||
|
|
908dc1151c | ||
|
|
595b5aeba7 | ||
|
|
fc5fd661aa | ||
|
|
d38d1a4f40 | ||
|
|
8d420b827c | ||
|
|
bde01290d3 | ||
|
|
ab524903e8 | ||
|
|
ef00a0afbb | ||
|
|
74c8179d39 | ||
|
|
bc41886e18 | ||
|
|
1c73553e36 | ||
|
|
fac3d41a58 | ||
|
|
d8073c4b76 | ||
|
|
77184c6339 | ||
|
|
5558c35bb3 | ||
|
|
e85d57a50e | ||
|
|
3eb62794c5 | ||
|
|
7cf33ac2f2 | ||
|
|
493bee0560 | ||
|
|
659a1e1bd0 | ||
|
|
6e80be31cd | ||
|
|
3fb5c613f0 | ||
|
|
7d16ba5d7e | ||
|
|
a92a9da9c8 | ||
|
|
c1fa9df06b | ||
|
|
6e2bbef080 | ||
|
|
9ca24b6906 | ||
|
|
70e1d26338 | ||
|
|
89c7383074 | ||
|
|
40f2ab01b7 | ||
|
|
2bedf4a221 | ||
|
|
87052cdc7b | ||
|
|
47d790678f | ||
|
|
1e946feb37 | ||
|
|
8a1ad91c0a | ||
|
|
8296deda21 | ||
|
|
733ef0ab01 | ||
|
|
da24556b54 | ||
|
|
9af0caf0e5 | ||
|
|
d8f2df20d5 | ||
|
|
6e9307a3d4 | ||
|
|
8805179dc9 | ||
|
|
014300b08c | ||
|
|
34486f306e | ||
|
|
9b155d6432 | ||
|
|
f199659a6a | ||
|
|
38ecb5b593 | ||
|
|
0e9e935cc8 | ||
|
|
69d2faa365 | ||
|
|
7e14978e0e | ||
|
|
8477905b0e | ||
|
|
f3ff3564fa | ||
|
|
c7565d44ec | ||
|
|
82299c3bbe | ||
|
|
2013ccccfe | ||
|
|
3a2b68706a | ||
|
|
a87294d992 | ||
|
|
5a5d4df8ad | ||
|
|
4eb8182aba | ||
|
|
67d4f4bd7a | ||
|
|
d2e453a37e | ||
|
|
ce3cf9537a | ||
|
|
479b69732e | ||
|
|
aee95908ea | ||
|
|
080ada6281 | ||
|
|
430e5f0bbf | ||
|
|
51699b6461 | ||
|
|
ac9b193beb | ||
|
|
d630451aa0 | ||
|
|
c8dafca32b | ||
|
|
bc858b5649 | ||
|
|
cd1541ea8d | ||
|
|
7bce095f93 | ||
|
|
195b0c2e88 | ||
|
|
cdee0bc8c3 | ||
|
|
0e562a634b | ||
|
|
3d00aed36d | ||
|
|
2c5ec1eea8 | ||
|
|
bf0431a342 | ||
|
|
c26b132baa | ||
|
|
3ffdd4d73e | ||
|
|
ea2cae5127 | ||
|
|
dfe560420d | ||
|
|
e4033dcc29 | ||
|
|
92129e58e4 | ||
|
|
bf9bc3f2a6 | ||
|
|
d703cf58c3 | ||
|
|
c80eb9894b | ||
|
|
5e7a6ffc7d | ||
|
|
c665328b35 | ||
|
|
5370d75f36 | ||
|
|
7f3cd87ec0 | ||
|
|
67ca5cc413 | ||
|
|
8992b0e1c7 | ||
|
|
5e9a56c6de | ||
|
|
9cd1f01f7f | ||
|
|
a0be92bfc2 | ||
|
|
6ec8e13b9a | ||
|
|
c9bb42fdbf | ||
|
|
b109bc8c95 | ||
|
|
5f24a51147 | ||
|
|
ef281d4e24 | ||
|
|
67fc6dd646 | ||
|
|
2caab057ed | ||
|
|
3b139cfc5f | ||
|
|
d6807b6643 | ||
|
|
c89b41fdc6 | ||
|
|
eee97d8b03 | ||
|
|
9d101822a3 | ||
|
|
9192be9c72 | ||
|
|
2fc8e23b12 | ||
|
|
fb86db2043 | ||
|
|
0a198ab3ed | ||
|
|
fc499fc13a | ||
|
|
b02ea3a88b | ||
|
|
612e96e757 | ||
|
|
0adc9b8215 | ||
|
|
591cbf9044 | ||
|
|
c0a5e20c51 | ||
|
|
c82883d789 | ||
|
|
4081bf99e2 | ||
|
|
03e585eea7 | ||
|
|
08b4117924 | ||
|
|
9c3441f7ee | ||
|
|
304a544dca | ||
|
|
e99353b1e1 | ||
|
|
d8ae44e2a0 | ||
|
|
a6993e2c61 | ||
|
|
d92f08b3ff | ||
|
|
3e334b7ca7 | ||
|
|
32b7d886d5 | ||
|
|
14b94f8fbc | ||
|
|
6ea3b24563 | ||
|
|
ac1d2d7d35 | ||
|
|
fe833075f3 |
@@ -12,3 +12,14 @@ updates:
|
|||||||
ignore:
|
ignore:
|
||||||
- dependency-name: '@types/node'
|
- dependency-name: '@types/node'
|
||||||
update-types: ['version-update:semver-major']
|
update-types: ['version-update:semver-major']
|
||||||
|
groups:
|
||||||
|
minor-updates:
|
||||||
|
update-types:
|
||||||
|
- 'minor'
|
||||||
|
- 'patch'
|
||||||
|
exclude-patterns:
|
||||||
|
- '*spdx*'
|
||||||
|
# Pull out any updates to spdx definitions and parsing as a priority PR
|
||||||
|
spdx-licenses:
|
||||||
|
patterns:
|
||||||
|
- '*spdx*'
|
||||||
|
|||||||
@@ -16,6 +16,9 @@ on:
|
|||||||
- '**.md'
|
- '**.md'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
check-dist:
|
check-dist:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
|||||||
@@ -10,6 +10,9 @@ on:
|
|||||||
paths-ignore:
|
paths-ignore:
|
||||||
- '**.md'
|
- '**.md'
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
test:
|
test:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
|||||||
@@ -20,7 +20,7 @@ jobs:
|
|||||||
strategy:
|
strategy:
|
||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
language: [ 'javascript-typescript' ]
|
language: [ 'javascript-typescript', 'actions', 'ruby' ]
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
|
|||||||
@@ -1,4 +1,5 @@
|
|||||||
name: 'Dependency Review'
|
name: 'Dependency Review'
|
||||||
|
|
||||||
on: [pull_request]
|
on: [pull_request]
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
@@ -11,4 +12,4 @@ jobs:
|
|||||||
- name: 'Checkout Repository'
|
- name: 'Checkout Repository'
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Dependency Review
|
- name: Dependency Review
|
||||||
uses: actions/dependency-review-action@main
|
uses: ./
|
||||||
|
|||||||
@@ -12,12 +12,15 @@ jobs:
|
|||||||
stale:
|
stale:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/stale@v9.0.0
|
- uses: actions/stale@v9.1.0
|
||||||
name: Clean up stale PRs and Issues
|
name: Clean up stale PRs and Issues
|
||||||
with:
|
with:
|
||||||
stale-pr-message: "👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the `Keep` label to hold stale off permanently, or do nothing. If you do nothing, this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details."
|
stale-pr-message: "👋 This pull request has been marked as stale because it has been open with no activity for 180 days. You can: comment on the PR or remove the stale label to hold stalebot off for a while, add the `Keep` label to hold stale off permanently, or do nothing. If you do nothing, this pull request will be closed eventually by the stalebot. Please see CONTRIBUTING.md for more policy details."
|
||||||
stale-pr-label: "Stale"
|
stale-pr-label: "Stale"
|
||||||
|
close-pr-message: "👋 This pull request has been closed by stalebot because it has been open with no activity for over 180 days. Please see CONTRIBUTING.md for more policy details."
|
||||||
stale-issue-label: "Stale"
|
stale-issue-label: "Stale"
|
||||||
|
stale-issue-message: "👋 This issue has been marked as stale because it has been open with no activity for 180 days. You can: comment on the issue or remove the stale label to hold stalebot off for a while, add the `Keep` label to hold stale off permanently, or do nothing. If you do nothing, this issue will be closed eventually by the stalebot. Please see CONTRIBUTING.md for more policy details."
|
||||||
|
close-issue-message: "👋 This issue has been closed by stalebot because it has been open with no activity for over 180 days. Please see CONTRIBUTING.md for more policy details."
|
||||||
exempt-pr-labels: "Keep" # a "Keep" label will keep the PR from being closed as stale
|
exempt-pr-labels: "Keep" # a "Keep" label will keep the PR from being closed as stale
|
||||||
exempt-issue-labels: "Keep" # a "Keep" label will keep the issue from being closed as stale
|
exempt-issue-labels: "Keep" # a "Keep" label will keep the issue from being closed as stale
|
||||||
days-before-pr-stale: 180 # when the PR is considered stale
|
days-before-pr-stale: 180 # when the PR is considered stale
|
||||||
|
|||||||
+3
-3
@@ -35,11 +35,11 @@ Ready to contribute to `dependency-review-action`? Here is some information to
|
|||||||
|
|
||||||
This action makes an authenticated query to the [Dependency Review API](https://docs.github.com/en/rest/dependency-graph/dependency-review) endpoint (`GET /repos/{owner}/{repo}/dependency-graph/compare/{basehead}`) to find out the set of added and removed dependencies for each manifest.
|
This action makes an authenticated query to the [Dependency Review API](https://docs.github.com/en/rest/dependency-graph/dependency-review) endpoint (`GET /repos/{owner}/{repo}/dependency-graph/compare/{basehead}`) to find out the set of added and removed dependencies for each manifest.
|
||||||
|
|
||||||
The action then evaluates the differences between the pushes based on the the rules defined in the action configuration, and summarizes the differences and any violations of the rules you have defined as a comment in the pull request that triggered it and the action outputs.
|
The action then evaluates the differences between the pushes based on the rules defined in the action configuration, and summarizes the differences and any violations of the rules you have defined as a comment in the pull request that triggered it and the action outputs.
|
||||||
|
|
||||||
### Local Development
|
### Local Development
|
||||||
|
|
||||||
Before you begin, you need to have [Node.js](https://nodejs.org/en/) installed, minimum version 18.
|
Before you begin, you need to have [Node.js](https://nodejs.org/en/) installed, minimum version 20.
|
||||||
|
|
||||||
#### Bootstrapping the project
|
#### Bootstrapping the project
|
||||||
|
|
||||||
@@ -81,7 +81,7 @@ $ GITHUB_TOKEN=<token> ./scripts/scan_pr --config-file my_custom_config.yml <pr_
|
|||||||
npm run test
|
npm run test
|
||||||
```
|
```
|
||||||
|
|
||||||
_Note_: We don't a very comprehensive test suite, so any contributions to the existing tests are welcome!
|
_Note_: We don't have a very comprehensive test suite, so any contributions to the existing tests are welcome!
|
||||||
|
|
||||||
### Submitting a pull request
|
### Submitting a pull request
|
||||||
|
|
||||||
|
|||||||
@@ -1,13 +1,23 @@
|
|||||||
# dependency-review-action
|
# dependency-review-action
|
||||||
|
|
||||||
- [Overview](#overview)
|
- [dependency-review-action](#dependency-review-action)
|
||||||
- [Installation](#installation)
|
- [Overview](#overview)
|
||||||
- [Configuration](#configuration)
|
- [Viewing the results](#viewing-the-results)
|
||||||
- [Using dependency review action to block a pull request from being merged](#using-dependency-review-action-to-block-a-pull-request-from-being-merged)
|
- [Installation](#installation)
|
||||||
- [Outputs](#outputs)
|
- [Installation (standard)](#installation-standard)
|
||||||
- [Getting help](#getting-help)
|
- [Installation (GitHub Enterprise Server)](#installation-github-enterprise-server)
|
||||||
- [Contributing](#contributing)
|
- [Configuration](#configuration)
|
||||||
- [License](#license)
|
- [Configuration options](#configuration-options)
|
||||||
|
- [Configuration methods](#configuration-methods)
|
||||||
|
- [Option 1: Using inline configuration](#option-1-using-inline-configuration)
|
||||||
|
- [Option 2: Using an external configuration file](#option-2-using-an-external-configuration-file)
|
||||||
|
- [`OTHER` in license strings](#other-in-license-strings)
|
||||||
|
- [Further information](#further-information)
|
||||||
|
- [Using dependency review action to block a pull request from being merged](#using-dependency-review-action-to-block-a-pull-request-from-being-merged)
|
||||||
|
- [Outputs](#outputs)
|
||||||
|
- [Getting help](#getting-help)
|
||||||
|
- [Contributing](#contributing)
|
||||||
|
- [License](#license)
|
||||||
|
|
||||||
## Overview
|
## Overview
|
||||||
|
|
||||||
@@ -15,6 +25,7 @@ The dependency review action scans your pull requests for dependency changes, an
|
|||||||
The action is supported by an [API endpoint](https://docs.github.com/en/rest/dependency-graph/dependency-review?apiVersion=2022-11-28) that diffs the dependencies between any two revisions on your default branch.
|
The action is supported by an [API endpoint](https://docs.github.com/en/rest/dependency-graph/dependency-review?apiVersion=2022-11-28) that diffs the dependencies between any two revisions on your default branch.
|
||||||
|
|
||||||
The action is available for:
|
The action is available for:
|
||||||
|
|
||||||
- Public repositories
|
- Public repositories
|
||||||
- Private repositories with a [GitHub Advanced Security](https://docs.github.com/en/enterprise-cloud@latest/get-started/learning-about-github/about-github-advanced-security) license.
|
- Private repositories with a [GitHub Advanced Security](https://docs.github.com/en/enterprise-cloud@latest/get-started/learning-about-github/about-github-advanced-security) license.
|
||||||
|
|
||||||
@@ -26,7 +37,7 @@ When the action runs, you can see the results on:
|
|||||||
1. Go to the **Actions** tab for the repository and select the relevant workflow run.
|
1. Go to the **Actions** tab for the repository and select the relevant workflow run.
|
||||||
1. Then under "Jobs", click **dependency review**.
|
1. Then under "Jobs", click **dependency review**.
|
||||||
|
|
||||||
<img width="850" alt="GitHub workflow run log showing Dependency Review job output" src="https://user-images.githubusercontent.com/2161/161042286-b22d7dd3-13cb-458d-8744-ce70ed9bf562.png">
|
<img width="850" alt="GitHub workflow run log showing Dependency Review job output" src="https://user-images.githubusercontent.com/2161/161042286-b22d7dd3-13cb-458d-8744-ce70ed9bf562.png">
|
||||||
|
|
||||||
- The **job summary** page.
|
- The **job summary** page.
|
||||||
1. Go to the **Actions** tab for the repository and select the relevant workflow run.
|
1. Go to the **Actions** tab for the repository and select the relevant workflow run.
|
||||||
@@ -70,7 +81,7 @@ You can install the action on repositories on GitHub Enterprise Server.
|
|||||||
2. Ensure you have installed the [dependency-review-action](https://github.com/actions/dependency-review-action) on the server.
|
2. Ensure you have installed the [dependency-review-action](https://github.com/actions/dependency-review-action) on the server.
|
||||||
3. Add a new YAML workflow to your `.github/workflows` folder:
|
3. Add a new YAML workflow to your `.github/workflows` folder:
|
||||||
|
|
||||||
``` yaml
|
```yaml
|
||||||
name: 'Dependency Review'
|
name: 'Dependency Review'
|
||||||
on: [pull_request]
|
on: [pull_request]
|
||||||
|
|
||||||
@@ -86,7 +97,8 @@ You can install the action on repositories on GitHub Enterprise Server.
|
|||||||
- name: 'Dependency Review'
|
- name: 'Dependency Review'
|
||||||
uses: actions/dependency-review-action@v4
|
uses: actions/dependency-review-action@v4
|
||||||
```
|
```
|
||||||
5. In the workflow file, replace the `runs-on` value with the label of any of your runners. (The default value is `self-hosted`.)
|
|
||||||
|
4. In the workflow file, replace the `runs-on` value with the label of any of your runners. (The default value is `self-hosted`.)
|
||||||
|
|
||||||
## Configuration
|
## Configuration
|
||||||
|
|
||||||
@@ -99,27 +111,28 @@ There are various configuration options you can use to specify settings for the
|
|||||||
|
|
||||||
All configuration options are optional.
|
All configuration options are optional.
|
||||||
|
|
||||||
| Option | Usage | Possible values | Default value |
|
| Option | Usage | Possible values | Default value |
|
||||||
| -------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ | ------------- |
|
| -------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | ------------- |
|
||||||
| `fail-on-severity` | Defines the threshold for the level of severity. The action will fail on any pull requests that introduce vulnerabilities of the specified severity level or higher. | `low`, `moderate`, `high`, `critical` | `low` |
|
| `fail-on-severity` | Defines the threshold for the level of severity. The action will fail on any pull requests that introduce vulnerabilities of the specified severity level or higher. | `low`, `moderate`, `high`, `critical` | `low` |
|
||||||
| `allow-licenses`\* | Contains a list of allowed licenses. The action will fail on pull requests that introduce dependencies with licenses that do not match the list. | Any [SPDX-compliant identifier(s)](https://spdx.org/licenses/) | none |
|
| `allow-licenses`\* | Contains a list of allowed licenses. The action will fail on pull requests that introduce dependencies with licenses that do not match the list. | Any [SPDX-compliant identifier(s)](https://spdx.org/licenses/) | none |
|
||||||
| `deny-licenses`\* | Contains a list of prohibited licenses. The action will fail on pull requests that introduce dependencies with licenses that match the list. | Any [SPDX-compliant identifier(s)](https://spdx.org/licenses/) | none |
|
| `deny-licenses`\* | ⚠️ This option is deprecated for possible removal in the next major release. See [Deprecate the deny-licenses option #938](https://github.com/actions/dependency-review-action/issues/938) for more information. <br> Contains a list of prohibited licenses. The action will fail on pull requests that introduce dependencies with licenses that match the list. | Any [SPDX-compliant identifier(s)](https://spdx.org/licenses/) | none |
|
||||||
| `fail-on-scopes` | Contains a list of strings of the build environments you want to support. The action will fail on pull requests that introduce vulnerabilities in the scopes that match the list. | `runtime`, `development`, `unknown` | `runtime` |
|
| `fail-on-scopes` | Contains a list of strings of the build environments you want to support. The action will fail on pull requests that introduce vulnerabilities in the scopes that match the list. | `runtime`, `development`, `unknown` | `runtime` |
|
||||||
| `allow-ghsas` | Contains a list of GitHub Advisory Database IDs that can be skipped during detection. | Any GHSAs from the [GitHub Advisory Database](https://github.com/advisories) | none |
|
| `allow-ghsas` | Contains a list of GitHub Advisory Database IDs that can be skipped during detection. | Any GHSAs from the [GitHub Advisory Database](https://github.com/advisories) | none |
|
||||||
| `license-check` | Enable or disable the license check performed by the action. | `true`, `false` | `true` |
|
| `license-check` | Enable or disable the license check performed by the action. | `true`, `false` | `true` |
|
||||||
| `vulnerability-check` | Enable or disable the vulnerability check performed by the action. | `true`, `false` | `true` |
|
| `vulnerability-check` | Enable or disable the vulnerability check performed by the action. | `true`, `false` | `true` |
|
||||||
| `allow-dependencies-licenses`\* | Contains a list of packages that will be excluded from license checks. | Any package(s) in [purl](https://github.com/package-url/purl-spec) format | none |
|
| `allow-dependencies-licenses`\* | Contains a list of packages that will be excluded from license checks. | Any package(s) in [purl](https://github.com/package-url/purl-spec) format | none |
|
||||||
| `base-ref`/`head-ref` | Provide custom git references for the git base/head when performing the comparison check. This is only used for event types other than `pull_request` and `pull_request_target`. | Any valid git ref(s) in your project | none |
|
| `base-ref`/`head-ref` | Provide custom git references for the git base/head when performing the comparison check. This is only used for event types other than `pull_request` and `pull_request_target`. | Any valid git ref(s) in your project | none |
|
||||||
| `comment-summary-in-pr` | Enable or disable reporting the review summary as a comment in the pull request. If enabled, you must give the workflow or job the `pull-requests: write` permission. | `always`, `on-failure`, `never` | `never` |
|
| `comment-summary-in-pr` | Enable or disable reporting the review summary as a comment in the pull request. If enabled, you must give the workflow or job the `pull-requests: write` permission. With each execution, a new comment will overwrite the existing one. | `always`, `on-failure`, `never` | `never` |
|
||||||
| `deny-packages` | Any number of packages to block in a PR. This option will match on the exact version provided. If no version is provided, the option will treat the specified package as a wildcard and deny all versions. | Package(s) in [purl](https://github.com/package-url/purl-spec) format | empty |
|
| `deny-packages` | Any number of packages to block in a PR. This option will match on the exact version provided. If no version is provided, the option will treat the specified package as a wildcard and deny all versions. | Package(s) in [purl](https://github.com/package-url/purl-spec) format | empty |
|
||||||
| `deny-groups` | Any number of groups (namespaces) to block in a PR. | Namespace(s) in [purl](https://github.com/package-url/purl-spec) format (no package name, no version number) | empty |
|
| `deny-groups` | Any number of groups (namespaces) to block in a PR. | Namespace(s) in [purl](https://github.com/package-url/purl-spec) format (no package name, no version number) | empty |
|
||||||
| `retry-on-snapshot-warnings`\* | Enable or disable retrying the action every 10 seconds while waiting for dependency submission actions to complete. | `true`, `false` | `false` |
|
| `retry-on-snapshot-warnings`\* | Enable or disable retrying the action every 10 seconds while waiting for dependency submission actions to complete. | `true`, `false` | `false` |
|
||||||
| `retry-on-snapshot-warnings-timeout`\* | Maximum amount of time (in seconds) to retry the action while waiting for dependency submission actions to complete. | Any positive integer | 120 |
|
| `retry-on-snapshot-warnings-timeout`\* | Maximum amount of time (in seconds) to retry the action while waiting for dependency submission actions to complete. | Any positive integer | 120 |
|
||||||
| `warn-only`+ | When set to `true`, the action will log all vulnerabilities as warnings regardless of the severity, and the action will complete with a `success` status. This overrides the `fail-on-severity` option. | `true`, `false` | `false` |
|
| `warn-only`+ | When set to `true`, the action will log all vulnerabilities as warnings regardless of the severity, and the action will complete with a `success` status. This overrides the `fail-on-severity` option. | `true`, `false` | `false` |
|
||||||
| `show-openssf-scorecard` | When set to `true`, the action will output information about all the known OpenSSF Scorecard scores for the dependencies changed in this pull request. | `true`, `false` | `true` |
|
| `show-openssf-scorecard` | When set to `true`, the action will output information about all the known OpenSSF Scorecard scores for the dependencies changed in this pull request. | `true`, `false` | `true` |
|
||||||
| `warn-on-openssf-scorecard-level` | When `show-openssf-scorecard-levels` is set to `true`, this option lets you configure the threshold for when a score is considered too low and gets a :warning: warning in the CI. | Any positive integer | 3 |
|
| `warn-on-openssf-scorecard-level` | When `show-openssf-scorecard-levels` is set to `true`, this option lets you configure the threshold for when a score is considered too low and gets a :warning: warning in the CI. | Any positive integer | 3 |
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
|
>
|
||||||
> - \* Not supported for use with GitHub Enterprise Server. (Checking for licenses is not supported on GitHub Enterprise Server because the API does not return license information.)
|
> - \* Not supported for use with GitHub Enterprise Server. (Checking for licenses is not supported on GitHub Enterprise Server because the API does not return license information.)
|
||||||
> - \+ When `warn-only` is set to `true`, all vulnerabilities, independently of the severity, will be reported as warnings and the action will not fail.
|
> - \+ When `warn-only` is set to `true`, all vulnerabilities, independently of the severity, will be reported as warnings and the action will not fail.
|
||||||
> - The `allow-licenses` and `deny-licenses` options are mutually exclusive; an error will be raised if you provide both.
|
> - The `allow-licenses` and `deny-licenses` options are mutually exclusive; an error will be raised if you provide both.
|
||||||
@@ -128,6 +141,7 @@ All configuration options are optional.
|
|||||||
### Configuration methods
|
### Configuration methods
|
||||||
|
|
||||||
To specify settings for the dependency review action, you can choose from two options:
|
To specify settings for the dependency review action, you can choose from two options:
|
||||||
|
|
||||||
- [Option 1: Inline the configuration options]() in your workflow file.
|
- [Option 1: Inline the configuration options]() in your workflow file.
|
||||||
- [Option 2: Reference an external configuration file]() in your workflow file.
|
- [Option 2: Reference an external configuration file]() in your workflow file.
|
||||||
|
|
||||||
@@ -136,6 +150,7 @@ To specify settings for the dependency review action, you can choose from two op
|
|||||||
You can pass configuration options to the dependency review action using your workflow file.
|
You can pass configuration options to the dependency review action using your workflow file.
|
||||||
|
|
||||||
1. In the same YAML workflow file you created during installation, use the `with:` key to specify your chosen settings:
|
1. In the same YAML workflow file you created during installation, use the `with:` key to specify your chosen settings:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
name: 'Dependency Review'
|
name: 'Dependency Review'
|
||||||
on: [pull_request]
|
on: [pull_request]
|
||||||
@@ -178,34 +193,42 @@ You can use an external configuration file to specify settings for this action.
|
|||||||
with:
|
with:
|
||||||
config-file: './.github/dependency-review-config.yml'
|
config-file: './.github/dependency-review-config.yml'
|
||||||
```
|
```
|
||||||
| Option | Usage | Possible values |
|
|
||||||
|--------------------- | ----------- | ----------------------------- |
|
| Option | Usage | Possible values |
|
||||||
| `config-file` | A path to a file in the current repository or an external repository. Use this syntax for external files: `OWNER/REPOSITORY/FILENAME@BRANCH` | **Local file**: `./.github/dependency-review-config.yml` <br> **External repo**: `github/octorepo/dependency-review-config.yml@main` |
|
| ------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------ |
|
||||||
|
| `config-file` | A path to a file in the current repository or an external repository. Use this syntax for external files: `OWNER/REPOSITORY/FILENAME@BRANCH` | **Local file**: `./.github/dependency-review-config.yml` <br> **External repo**: `github/octorepo/dependency-review-config.yml@main` |
|
||||||
|
|
||||||
2. Optionally, if the file resides in a private external repository, and for all GitHub Enterprise Server repositories, use `external-repo-token` to specify a token for fetching the file.
|
2. Optionally, if the file resides in a private external repository, and for all GitHub Enterprise Server repositories, use `external-repo-token` to specify a token for fetching the file.
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
- name: Dependency Review
|
- name: Dependency Review
|
||||||
uses: actions/dependency-review-action@v4
|
uses: actions/dependency-review-action@v4
|
||||||
with:
|
with:
|
||||||
config-file: 'github/octorepo/dependency-review-config.yml@main'
|
config-file: 'github/octorepo/dependency-review-config.yml@main'
|
||||||
external-repo-token: 'ghp_123456789abcde'
|
external-repo-token: 'ghp_123456789abcde'
|
||||||
```
|
```
|
||||||
|
|
||||||
| Option | Usage | Possible values |
|
| Option | Usage | Possible values |
|
||||||
|--------------------- | ----------- | ----------------------------- |
|
| --------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------- |
|
||||||
| `external-repo-token` | Specifies a token for fetching the configuration file. It is required if the file resides in a private external repository and for all GitHub Enterprise Server repositories. Create a token in [developer settings](https://github.com/settings/tokens). | Any token with `read` permissions to the repository hosting the config file. |
|
| `external-repo-token` | Specifies a token for fetching the configuration file. It is required if the file resides in a private external repository and for all GitHub Enterprise Server repositories. Create a token in [developer settings](https://github.com/settings/tokens). | Any token with `read` permissions to the repository hosting the config file. |
|
||||||
|
|
||||||
3. Create the configuration file in the path you specified for `config-file`.
|
3. Create the configuration file in the path you specified for `config-file`.
|
||||||
4. In the configuration file, specify your chosen settings.
|
4. In the configuration file, specify your chosen settings.
|
||||||
```yaml
|
```yaml
|
||||||
fail_on_severity: 'critical'
|
fail-on-severity: 'critical'
|
||||||
allow_licenses:
|
allow-licenses:
|
||||||
- 'GPL-3.0'
|
- 'GPL-3.0'
|
||||||
- 'BSD-3-Clause'
|
- 'BSD-3-Clause'
|
||||||
- 'MIT'
|
- 'MIT'
|
||||||
```
|
```
|
||||||
> [!NOTE]
|
|
||||||
> For external configuration files, the option names use underscores instead of dashes.
|
#### `OTHER` in license strings
|
||||||
> Example: `fail_on_severity`
|
|
||||||
|
License data comes from [ClearlyDefined](https://clearlydefined.io) and you may sometimes see licenses displayed with the string `OTHER` in them. ClearlyDefined [defines OTHER](https://docs.clearlydefined.io/docs/curation/curation-guidelines) as:
|
||||||
|
|
||||||
|
> This indicates that a human confirmed that there is license information in the file but that the license is not an SPDX-identified license.
|
||||||
|
|
||||||
|
`OTHER` is not a valid [SPDX license identifier](https://spdx.org/licenses/), so we convert `OTHER` in a license string into `LicenseRef-clearlydefined-OTHER`, which _is_ valid in SPDX. If you want to add that to the deny or allow list, be sure to add `LicenseRef-clearlydefined-OTHER` to this list, because that is what we'll actually be comparing.
|
||||||
|
|
||||||
#### Further information
|
#### Further information
|
||||||
|
|
||||||
|
|||||||
@@ -124,11 +124,7 @@ test('it raises an error when no refs are provided and the event is not a pull r
|
|||||||
).toThrow()
|
).toThrow()
|
||||||
})
|
})
|
||||||
|
|
||||||
const pullRequestLikeEvents = [
|
const pullRequestLikeEvents = ['pull_request', 'pull_request_target']
|
||||||
'pull_request',
|
|
||||||
'pull_request_target',
|
|
||||||
'merge_group'
|
|
||||||
]
|
|
||||||
|
|
||||||
test.each(pullRequestLikeEvents)(
|
test.each(pullRequestLikeEvents)(
|
||||||
'it uses the given refs even when the event is %s',
|
'it uses the given refs even when the event is %s',
|
||||||
@@ -152,7 +148,7 @@ test.each(pullRequestLikeEvents)(
|
|||||||
)
|
)
|
||||||
|
|
||||||
test.each(pullRequestLikeEvents)(
|
test.each(pullRequestLikeEvents)(
|
||||||
'it uses the event refs when the event is %s and the no refs are input',
|
'it uses the event refs when the event is %s and no refs are provided in config',
|
||||||
async eventName => {
|
async eventName => {
|
||||||
const refs = getRefs(await readConfig(), {
|
const refs = getRefs(await readConfig(), {
|
||||||
payload: {
|
payload: {
|
||||||
@@ -169,6 +165,37 @@ test.each(pullRequestLikeEvents)(
|
|||||||
}
|
}
|
||||||
)
|
)
|
||||||
|
|
||||||
|
test('it uses the given refs even when the event is merge_group', async () => {
|
||||||
|
setInput('base-ref', 'a-custom-base-ref')
|
||||||
|
setInput('head-ref', 'a-custom-head-ref')
|
||||||
|
|
||||||
|
const refs = getRefs(await readConfig(), {
|
||||||
|
payload: {
|
||||||
|
merge_group: {
|
||||||
|
base_sha: 'pr-base-ref',
|
||||||
|
head_sha: 'pr-head-ref'
|
||||||
|
}
|
||||||
|
},
|
||||||
|
eventName: 'merge_group'
|
||||||
|
})
|
||||||
|
expect(refs.base).toEqual('a-custom-base-ref')
|
||||||
|
expect(refs.head).toEqual('a-custom-head-ref')
|
||||||
|
})
|
||||||
|
|
||||||
|
test('it uses the event refs when the event is merge_group and no refs are provided in config', async () => {
|
||||||
|
const refs = getRefs(await readConfig(), {
|
||||||
|
payload: {
|
||||||
|
merge_group: {
|
||||||
|
base_sha: 'pr-base-ref',
|
||||||
|
head_sha: 'pr-head-ref'
|
||||||
|
}
|
||||||
|
},
|
||||||
|
eventName: 'merge_group'
|
||||||
|
})
|
||||||
|
expect(refs.base).toEqual('pr-base-ref')
|
||||||
|
expect(refs.head).toEqual('pr-head-ref')
|
||||||
|
})
|
||||||
|
|
||||||
test('it defaults to runtime scope', async () => {
|
test('it defaults to runtime scope', async () => {
|
||||||
const config = await readConfig()
|
const config = await readConfig()
|
||||||
expect(config.fail_on_scopes).toEqual(['runtime'])
|
expect(config.fail_on_scopes).toEqual(['runtime'])
|
||||||
|
|||||||
@@ -134,3 +134,62 @@ test('allows packages not defined in the deny packages and groups list', async (
|
|||||||
|
|
||||||
expect(deniedChanges.length).toEqual(0)
|
expect(deniedChanges.length).toEqual(0)
|
||||||
})
|
})
|
||||||
|
|
||||||
|
test('deny packages does not prevent removal of denied packages', async () => {
|
||||||
|
const changes: Changes = [
|
||||||
|
createTestChange({
|
||||||
|
change_type: 'added',
|
||||||
|
name: 'deny-by-name-and-version',
|
||||||
|
version: '1.0.0',
|
||||||
|
ecosystem: 'npm'
|
||||||
|
}),
|
||||||
|
createTestChange({
|
||||||
|
change_type: 'removed',
|
||||||
|
name: 'pass-by-name-and-version',
|
||||||
|
version: '1.0.0',
|
||||||
|
ecosystem: 'npm'
|
||||||
|
}),
|
||||||
|
createTestChange({
|
||||||
|
change_type: 'added',
|
||||||
|
name: 'deny-by-name',
|
||||||
|
version: '1.0.0',
|
||||||
|
ecosystem: 'npm'
|
||||||
|
}),
|
||||||
|
createTestChange({
|
||||||
|
change_type: 'removed',
|
||||||
|
name: 'pass-by-name',
|
||||||
|
version: '1.0.0',
|
||||||
|
ecosystem: 'npm'
|
||||||
|
}),
|
||||||
|
createTestChange({
|
||||||
|
change_type: 'added',
|
||||||
|
package_url: 'pkg:npm/org.test.deny.by.namespace/[email protected]',
|
||||||
|
ecosystem: 'npm'
|
||||||
|
}),
|
||||||
|
createTestChange({
|
||||||
|
change_type: 'removed',
|
||||||
|
package_url: 'pkg:npm/org.test.pass.by.namespace/[email protected]',
|
||||||
|
ecosystem: 'npm'
|
||||||
|
})
|
||||||
|
]
|
||||||
|
const deniedPackages = createTestPURLs([
|
||||||
|
'pkg:npm/org.test.deny.by/[email protected]',
|
||||||
|
'pkg:npm/org.test.pass.by/[email protected]',
|
||||||
|
'pkg:npm/org.test.deny.by/deny-by-name',
|
||||||
|
'pkg:npm/org.test.pass.by/pass-by-name'
|
||||||
|
])
|
||||||
|
const deniedGroups = createTestPURLs([
|
||||||
|
'pkg:npm/org.test.deny.by.namespace/',
|
||||||
|
'pkg:npm/org.test.pass.by.namespace/'
|
||||||
|
])
|
||||||
|
const deniedChanges = await getDeniedChanges(
|
||||||
|
changes,
|
||||||
|
deniedPackages,
|
||||||
|
deniedGroups
|
||||||
|
)
|
||||||
|
|
||||||
|
expect(deniedChanges.length).toEqual(3)
|
||||||
|
expect(deniedChanges[0]).toBe(changes[0])
|
||||||
|
expect(deniedChanges[1]).toBe(changes[2])
|
||||||
|
expect(deniedChanges[2]).toBe(changes[4])
|
||||||
|
})
|
||||||
|
|||||||
@@ -74,6 +74,46 @@ const pipChange: Change = {
|
|||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const complexLicenseChange: Change = {
|
||||||
|
change_type: 'added',
|
||||||
|
manifest: 'requirements.txt',
|
||||||
|
ecosystem: 'pip',
|
||||||
|
name: 'package-1',
|
||||||
|
version: '1.1.1',
|
||||||
|
package_url: 'pkg:pypi/[email protected]',
|
||||||
|
license: 'MIT AND Apache-2.0',
|
||||||
|
source_repository_url: 'github.com/some-repo',
|
||||||
|
scope: 'runtime',
|
||||||
|
vulnerabilities: [
|
||||||
|
{
|
||||||
|
severity: 'moderate',
|
||||||
|
advisory_ghsa_id: 'second-random_string',
|
||||||
|
advisory_summary: 'not so dangerous',
|
||||||
|
advisory_url: 'github.com/future-funk'
|
||||||
|
},
|
||||||
|
{
|
||||||
|
severity: 'low',
|
||||||
|
advisory_ghsa_id: 'third-random_string',
|
||||||
|
advisory_summary: 'dont page me',
|
||||||
|
advisory_url: 'github.com/future-funk'
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
|
||||||
|
const unlicensedChange: Change = {
|
||||||
|
change_type: 'added',
|
||||||
|
manifest: '.github/workflows/ci.yml',
|
||||||
|
ecosystem: 'actions',
|
||||||
|
name: 'foo-org/actions-repo/.github/workflows/some-action.yml',
|
||||||
|
version: '1.1.1',
|
||||||
|
package_url:
|
||||||
|
'pkg:githubactions/foo-org/actions-repo/.github/workflows/[email protected]',
|
||||||
|
license: null,
|
||||||
|
source_repository_url: 'github.com/some-repo',
|
||||||
|
scope: 'development',
|
||||||
|
vulnerabilities: []
|
||||||
|
}
|
||||||
|
|
||||||
jest.mock('@actions/core')
|
jest.mock('@actions/core')
|
||||||
|
|
||||||
const mockOctokit = {
|
const mockOctokit = {
|
||||||
@@ -129,6 +169,30 @@ test('it adds license inside the deny list to forbidden changes', async () => {
|
|||||||
expect(forbidden.length).toEqual(1)
|
expect(forbidden.length).toEqual(1)
|
||||||
})
|
})
|
||||||
|
|
||||||
|
test('it handles allowed complex licenses', async () => {
|
||||||
|
const changes: Changes = [
|
||||||
|
complexLicenseChange // MIT AND Apache-2.0 license
|
||||||
|
]
|
||||||
|
|
||||||
|
const {forbidden} = await getInvalidLicenseChanges(changes, {
|
||||||
|
allow: ['MIT', 'Apache-2.0']
|
||||||
|
})
|
||||||
|
|
||||||
|
expect(forbidden.length).toEqual(0)
|
||||||
|
})
|
||||||
|
|
||||||
|
test('it handles complex licenses not all on the allow list', async () => {
|
||||||
|
const changes: Changes = [
|
||||||
|
complexLicenseChange // MIT AND Apache-2.0 license
|
||||||
|
]
|
||||||
|
|
||||||
|
const {forbidden} = await getInvalidLicenseChanges(changes, {
|
||||||
|
allow: ['MIT']
|
||||||
|
})
|
||||||
|
|
||||||
|
expect(forbidden.length).toEqual(1)
|
||||||
|
})
|
||||||
|
|
||||||
test('it does not add license outside the allow list to forbidden changes if it is in removed changes', async () => {
|
test('it does not add license outside the allow list to forbidden changes if it is in removed changes', async () => {
|
||||||
const changes: Changes = [
|
const changes: Changes = [
|
||||||
{...npmChange, change_type: 'removed'},
|
{...npmChange, change_type: 'removed'},
|
||||||
@@ -226,6 +290,19 @@ test('it does filters out changes if they are not on the exclusions list', async
|
|||||||
expect(invalidLicenses.forbidden[1]).toBe(npmChange)
|
expect(invalidLicenses.forbidden[1]).toBe(npmChange)
|
||||||
})
|
})
|
||||||
|
|
||||||
|
test('it does not fail if there is a license expression in the allow list', async () => {
|
||||||
|
const changes: Changes = [
|
||||||
|
{...npmChange, license: 'MIT AND Apache-2.0'},
|
||||||
|
{...rubyChange, license: 'BSD-3-Clause'}
|
||||||
|
]
|
||||||
|
|
||||||
|
const {forbidden} = await getInvalidLicenseChanges(changes, {
|
||||||
|
allow: ['BSD-3-Clause', 'MIT AND Apache-2.0', 'MIT', 'Apache-2.0']
|
||||||
|
})
|
||||||
|
|
||||||
|
expect(forbidden.length).toEqual(0)
|
||||||
|
})
|
||||||
|
|
||||||
describe('GH License API fallback', () => {
|
describe('GH License API fallback', () => {
|
||||||
test('it calls licenses endpoint if atleast one of the changes has null license and valid source_repository_url', async () => {
|
test('it calls licenses endpoint if atleast one of the changes has null license and valid source_repository_url', async () => {
|
||||||
const nullLicenseChange = {
|
const nullLicenseChange = {
|
||||||
@@ -263,4 +340,26 @@ describe('GH License API fallback', () => {
|
|||||||
expect(mockOctokit.rest.licenses.getForRepo).not.toHaveBeenCalled()
|
expect(mockOctokit.rest.licenses.getForRepo).not.toHaveBeenCalled()
|
||||||
expect(unlicensed.length).toEqual(0)
|
expect(unlicensed.length).toEqual(0)
|
||||||
})
|
})
|
||||||
|
|
||||||
|
test('it does not call licenses API if the package is excluded', async () => {
|
||||||
|
const {unlicensed} = await getInvalidLicenseChanges([unlicensedChange], {
|
||||||
|
licenseExclusions: [
|
||||||
|
'pkg:githubactions/foo-org/actions-repo/.github/workflows/some-action.yml'
|
||||||
|
]
|
||||||
|
})
|
||||||
|
|
||||||
|
expect(mockOctokit.rest.licenses.getForRepo).not.toHaveBeenCalled()
|
||||||
|
expect(unlicensed.length).toEqual(0)
|
||||||
|
})
|
||||||
|
|
||||||
|
test('it checks namespaces when doing exclusions', async () => {
|
||||||
|
const {unlicensed} = await getInvalidLicenseChanges([unlicensedChange], {
|
||||||
|
licenseExclusions: [
|
||||||
|
'pkg:githubactions/bar-org/actions-repo/.github/workflows/some-action.yml'
|
||||||
|
]
|
||||||
|
})
|
||||||
|
|
||||||
|
expect(mockOctokit.rest.licenses.getForRepo).not.toHaveBeenCalled()
|
||||||
|
expect(unlicensed.length).toEqual(1)
|
||||||
|
})
|
||||||
})
|
})
|
||||||
|
|||||||
+85
-16
@@ -55,6 +55,16 @@ describe('satisfiesAny', () => {
|
|||||||
candidate: 'MIT OR ISC',
|
candidate: 'MIT OR ISC',
|
||||||
licenses: ['MiT'],
|
licenses: ['MiT'],
|
||||||
expected: false
|
expected: false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
candidate: 'MIT AND OTHER',
|
||||||
|
licenses: ['MIT'],
|
||||||
|
expected: false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
candidate: 'MIT OR OTHER',
|
||||||
|
licenses: ['MIT', 'LicenseRef-clearlydefined-OTHER'],
|
||||||
|
expected: true
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
|
||||||
@@ -130,6 +140,16 @@ describe('satisfiesAll', () => {
|
|||||||
candidate: 'MIT OR ISC',
|
candidate: 'MIT OR ISC',
|
||||||
licenses: ['MiT'],
|
licenses: ['MiT'],
|
||||||
expected: false
|
expected: false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
candidate: 'MIT AND OTHER',
|
||||||
|
licenses: ['MIT'],
|
||||||
|
expected: false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
candidate: 'MIT AND OTHER',
|
||||||
|
licenses: ['MIT', 'LicenseRef-clearlydefined-OTHER'],
|
||||||
|
expected: true
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
|
||||||
@@ -145,47 +165,47 @@ describe('satisfies', () => {
|
|||||||
const units = [
|
const units = [
|
||||||
{
|
{
|
||||||
candidate: 'MIT',
|
candidate: 'MIT',
|
||||||
constraint: 'MIT',
|
allowList: ['MIT'],
|
||||||
expected: true
|
expected: true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
candidate: 'Apache-2.0',
|
candidate: 'Apache-2.0',
|
||||||
constraint: 'MIT',
|
allowList: ['MIT'],
|
||||||
expected: false
|
expected: false
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
candidate: 'MIT OR Apache-2.0',
|
candidate: 'MIT OR Apache-2.0',
|
||||||
constraint: 'MIT',
|
allowList: ['MIT'],
|
||||||
expected: true
|
expected: true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
candidate: 'MIT OR Apache-2.0',
|
candidate: 'MIT OR Apache-2.0',
|
||||||
constraint: 'Apache-2.0',
|
allowList: ['Apache-2.0'],
|
||||||
expected: true
|
expected: true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
candidate: 'MIT OR Apache-2.0',
|
candidate: 'MIT OR Apache-2.0',
|
||||||
constraint: 'BSD-3-Clause',
|
allowList: ['BSD-3-Clause'],
|
||||||
expected: false
|
expected: false
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
candidate: 'MIT OR Apache-2.0',
|
candidate: 'MIT OR Apache-2.0',
|
||||||
constraint: 'Apache-2.0 OR BSD-3-Clause',
|
allowList: ['Apache-2.0', 'BSD-3-Clause'],
|
||||||
expected: true
|
expected: true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
candidate: 'MIT AND Apache-2.0',
|
candidate: 'MIT AND Apache-2.0',
|
||||||
constraint: 'MIT AND Apache-2.0',
|
allowList: ['MIT', 'Apache-2.0'],
|
||||||
expected: true
|
expected: true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
candidate: 'MIT OR Apache-2.0',
|
candidate: 'MIT OR Apache-2.0',
|
||||||
constraint: 'MIT AND Apache-2.0',
|
allowList: ['MIT', 'Apache-2.0'],
|
||||||
expected: false
|
expected: true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
candidate: 'ISC OR (MIT AND Apache-2.0)',
|
candidate: 'ISC OR (MIT AND Apache-2.0)',
|
||||||
constraint: 'MIT AND Apache-2.0',
|
allowList: ['MIT', 'Apache-2.0'],
|
||||||
expected: true
|
expected: true
|
||||||
},
|
},
|
||||||
|
|
||||||
@@ -193,29 +213,39 @@ describe('satisfies', () => {
|
|||||||
// or unknown licenses will return 'false'
|
// or unknown licenses will return 'false'
|
||||||
{
|
{
|
||||||
candidate: 'MIT',
|
candidate: 'MIT',
|
||||||
constraint: 'MiT',
|
allowList: ['MiT'],
|
||||||
expected: false
|
expected: false
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
candidate: 'MIT AND (ISC OR',
|
candidate: 'MIT AND (ISC OR',
|
||||||
constraint: 'MIT',
|
allowList: ['MIT'],
|
||||||
expected: false
|
expected: false
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
candidate: 'MIT OR ISC OR Apache-2.0',
|
candidate: 'MIT OR ISC OR Apache-2.0',
|
||||||
constraint: '',
|
allowList: [],
|
||||||
expected: false
|
expected: false
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
candidate: '',
|
candidate: '',
|
||||||
constraint: '(BSD-3-Clause AND ISC) OR MIT',
|
allowList: ['BSD-3-Clause', 'ISC', 'MIT'],
|
||||||
expected: false
|
expected: false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
candidate: 'MIT OR OTHER',
|
||||||
|
allowList: ['MIT', 'LicenseRef-clearlydefined-OTHER'],
|
||||||
|
expected: true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
candidate: '(Apache-2.0 AND OTHER) OR (MIT AND OTHER)',
|
||||||
|
allowList: ['Apache-2.0', 'LicenseRef-clearlydefined-OTHER'],
|
||||||
|
expected: true
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
|
||||||
for (const unit of units) {
|
for (const unit of units) {
|
||||||
const got: boolean = spdx.satisfies(unit.candidate, unit.constraint)
|
const got: boolean = spdx.satisfies(unit.candidate, unit.allowList)
|
||||||
test(`should return ${unit.expected} for ("${unit.candidate}", "${unit.constraint}")`, () => {
|
test(`should return ${unit.expected} for ("${unit.candidate}", "${unit.allowList}")`, () => {
|
||||||
expect(got).toBe(unit.expected)
|
expect(got).toBe(unit.expected)
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
@@ -246,6 +276,10 @@ describe('isValid', () => {
|
|||||||
{
|
{
|
||||||
candidate: '',
|
candidate: '',
|
||||||
expected: false
|
expected: false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
candidate: 'MIT AND OTHER',
|
||||||
|
expected: true
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
for (const unit of units) {
|
for (const unit of units) {
|
||||||
@@ -255,3 +289,38 @@ describe('isValid', () => {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
})
|
})
|
||||||
|
|
||||||
|
describe('cleanInvalidSPDX', () => {
|
||||||
|
const units = [
|
||||||
|
{
|
||||||
|
candidate: 'MIT',
|
||||||
|
expected: 'MIT'
|
||||||
|
},
|
||||||
|
{
|
||||||
|
candidate: 'OTHER',
|
||||||
|
expected: 'LicenseRef-clearlydefined-OTHER'
|
||||||
|
},
|
||||||
|
{
|
||||||
|
candidate: 'LicenseRef-clearlydefined-OTHER',
|
||||||
|
expected: 'LicenseRef-clearlydefined-OTHER'
|
||||||
|
},
|
||||||
|
{
|
||||||
|
candidate: 'OTHER AND MIT',
|
||||||
|
expected: 'LicenseRef-clearlydefined-OTHER AND MIT'
|
||||||
|
},
|
||||||
|
{
|
||||||
|
candidate: 'MIT AND OTHER',
|
||||||
|
expected: 'MIT AND LicenseRef-clearlydefined-OTHER'
|
||||||
|
},
|
||||||
|
{
|
||||||
|
candidate: 'MIT AND SomethingElse-OTHER',
|
||||||
|
expected: 'MIT AND SomethingElse-OTHER'
|
||||||
|
}
|
||||||
|
]
|
||||||
|
for (const unit of units) {
|
||||||
|
const got: string = spdx.cleanInvalidSPDX(unit.candidate)
|
||||||
|
test(`should return ${unit.expected} for ("${unit.candidate}")`, () => {
|
||||||
|
expect(got).toBe(unit.expected)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
})
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
import {expect, jest, test} from '@jest/globals'
|
import {expect, jest, test} from '@jest/globals'
|
||||||
import {Change, Changes, ConfigurationOptions, Scorecard} from '../src/schemas'
|
import {Changes, ConfigurationOptions, Scorecard} from '../src/schemas'
|
||||||
import * as summary from '../src/summary'
|
import * as summary from '../src/summary'
|
||||||
import * as core from '@actions/core'
|
import * as core from '@actions/core'
|
||||||
import {createTestChange} from './fixtures/create-test-change'
|
import {createTestChange} from './fixtures/create-test-change'
|
||||||
@@ -109,10 +109,38 @@ test('prints headline as h1', () => {
|
|||||||
expect(text).toContain('<h1>Dependency Review</h1>')
|
expect(text).toContain('<h1>Dependency Review</h1>')
|
||||||
})
|
})
|
||||||
|
|
||||||
|
test('does not add deprecation warning for deny-licenses option if not set', () => {
|
||||||
|
summary.addSummaryToSummary(
|
||||||
|
emptyChanges,
|
||||||
|
emptyInvalidLicenseChanges,
|
||||||
|
emptyChanges,
|
||||||
|
scorecard,
|
||||||
|
defaultConfig
|
||||||
|
)
|
||||||
|
const text = core.summary.stringify()
|
||||||
|
|
||||||
|
expect(text).not.toContain('deny-licenses')
|
||||||
|
})
|
||||||
|
|
||||||
|
test('adds deprecation warning for deny-licenses option if set', () => {
|
||||||
|
const config = {...defaultConfig, deny_licenses: ['MIT']}
|
||||||
|
|
||||||
|
summary.addSummaryToSummary(
|
||||||
|
emptyChanges,
|
||||||
|
emptyInvalidLicenseChanges,
|
||||||
|
emptyChanges,
|
||||||
|
scorecard,
|
||||||
|
config
|
||||||
|
)
|
||||||
|
const text = core.summary.stringify()
|
||||||
|
|
||||||
|
expect(text).toContain('deny-licenses')
|
||||||
|
})
|
||||||
|
|
||||||
test('returns minimal summary formatted for posting as a PR comment', () => {
|
test('returns minimal summary formatted for posting as a PR comment', () => {
|
||||||
const OLD_ENV = process.env
|
const OLD_ENV = process.env
|
||||||
|
|
||||||
let changes: Changes = [
|
const changes: Changes = [
|
||||||
createTestChange({name: 'lodash', version: '1.2.3'}),
|
createTestChange({name: 'lodash', version: '1.2.3'}),
|
||||||
createTestChange({name: 'colors', version: '2.3.4'}),
|
createTestChange({name: 'colors', version: '2.3.4'}),
|
||||||
createTestChange({name: '@foo/bar', version: '*'})
|
createTestChange({name: '@foo/bar', version: '*'})
|
||||||
@@ -122,7 +150,7 @@ test('returns minimal summary formatted for posting as a PR comment', () => {
|
|||||||
process.env.GITHUB_REPOSITORY = 'owner/repo'
|
process.env.GITHUB_REPOSITORY = 'owner/repo'
|
||||||
process.env.GITHUB_RUN_ID = 'abc-123-xyz'
|
process.env.GITHUB_RUN_ID = 'abc-123-xyz'
|
||||||
|
|
||||||
let minSummary: string = summary.addSummaryToSummary(
|
const minSummary: string = summary.addSummaryToSummary(
|
||||||
changes,
|
changes,
|
||||||
emptyInvalidLicenseChanges,
|
emptyInvalidLicenseChanges,
|
||||||
emptyChanges,
|
emptyChanges,
|
||||||
|
|||||||
+4557
-3614
File diff suppressed because one or more lines are too long
+1
-1
File diff suppressed because one or more lines are too long
+50
-33
@@ -10,6 +10,18 @@ The above copyright notice and this permission notice shall be included in all c
|
|||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
||||||
|
|
||||||
|
@actions/exec
|
||||||
|
MIT
|
||||||
|
The MIT License (MIT)
|
||||||
|
|
||||||
|
Copyright 2019 GitHub
|
||||||
|
|
||||||
|
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
|
||||||
|
|
||||||
|
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
|
||||||
|
|
||||||
|
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
||||||
|
|
||||||
@actions/github
|
@actions/github
|
||||||
MIT
|
MIT
|
||||||
The MIT License (MIT)
|
The MIT License (MIT)
|
||||||
@@ -47,6 +59,18 @@ WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
|
|||||||
SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
||||||
|
|
||||||
|
|
||||||
|
@actions/io
|
||||||
|
MIT
|
||||||
|
The MIT License (MIT)
|
||||||
|
|
||||||
|
Copyright 2019 GitHub
|
||||||
|
|
||||||
|
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
|
||||||
|
|
||||||
|
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
|
||||||
|
|
||||||
|
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
||||||
|
|
||||||
@fastify/busboy
|
@fastify/busboy
|
||||||
MIT
|
MIT
|
||||||
Copyright Brian White. All rights reserved.
|
Copyright Brian White. All rights reserved.
|
||||||
@@ -1460,7 +1484,7 @@ lru-cache
|
|||||||
ISC
|
ISC
|
||||||
The ISC License
|
The ISC License
|
||||||
|
|
||||||
Copyright (c) Isaac Z. Schlueter and Contributors
|
Copyright (c) 2010-2023 Isaac Z. Schlueter and Contributors
|
||||||
|
|
||||||
Permission to use, copy, modify, and/or distribute this software for any
|
Permission to use, copy, modify, and/or distribute this software for any
|
||||||
purpose with or without fee is hereby granted, provided that the above
|
purpose with or without fee is hereby granted, provided that the above
|
||||||
@@ -1646,6 +1670,31 @@ The above copyright notice and this permission notice shall be included in all c
|
|||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
||||||
|
|
||||||
|
|
||||||
|
spdx-satisfies
|
||||||
|
MIT
|
||||||
|
The MIT License
|
||||||
|
|
||||||
|
Copyright (c) spdx-satisfies.js contributors
|
||||||
|
|
||||||
|
Permission is hereby granted, free of charge, to any person obtaining a
|
||||||
|
copy of this software and associated documentation files (the "Software"),
|
||||||
|
to deal in the Software without restriction, including without limitation
|
||||||
|
the rights to use, copy, modify, merge, publish, distribute, sublicense,
|
||||||
|
and/or sell copies of the Software, and to permit persons to whom the
|
||||||
|
Software is furnished to do so, subject to the following conditions:
|
||||||
|
|
||||||
|
The above copyright notice and this permission notice shall be included
|
||||||
|
in all copies or substantial portions of the Software.
|
||||||
|
|
||||||
|
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||||
|
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||||
|
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
|
||||||
|
THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR
|
||||||
|
OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE,
|
||||||
|
ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR
|
||||||
|
OTHER DEALINGS IN THE SOFTWARE.
|
||||||
|
|
||||||
|
|
||||||
tunnel
|
tunnel
|
||||||
MIT
|
MIT
|
||||||
The MIT License (MIT)
|
The MIT License (MIT)
|
||||||
@@ -1732,19 +1781,6 @@ Permission to use, copy, modify, and/or distribute this software for any purpose
|
|||||||
THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
|
||||||
uuid
|
|
||||||
MIT
|
|
||||||
The MIT License (MIT)
|
|
||||||
|
|
||||||
Copyright (c) 2010-2020 Robert Kieffer and other contributors
|
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
|
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
|
||||||
|
|
||||||
|
|
||||||
wrappy
|
wrappy
|
||||||
ISC
|
ISC
|
||||||
The ISC License
|
The ISC License
|
||||||
@@ -1764,25 +1800,6 @@ ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR
|
|||||||
IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
|
||||||
yallist
|
|
||||||
ISC
|
|
||||||
The ISC License
|
|
||||||
|
|
||||||
Copyright (c) Isaac Z. Schlueter and Contributors
|
|
||||||
|
|
||||||
Permission to use, copy, modify, and/or distribute this software for any
|
|
||||||
purpose with or without fee is hereby granted, provided that the above
|
|
||||||
copyright notice and this permission notice appear in all copies.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
|
|
||||||
WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
|
|
||||||
MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
|
|
||||||
ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
|
|
||||||
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
|
|
||||||
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR
|
|
||||||
IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
|
||||||
|
|
||||||
|
|
||||||
yaml
|
yaml
|
||||||
ISC
|
ISC
|
||||||
Copyright Eemeli Aro <[email protected]>
|
Copyright Eemeli Aro <[email protected]>
|
||||||
|
|||||||
+1
-1
File diff suppressed because one or more lines are too long
+3
-3
@@ -1,4 +1,4 @@
|
|||||||
# Examples on how to use the Dependency Review Action
|
# Examples of how to use the Dependency Review Action
|
||||||
|
|
||||||
## Basic Usage
|
## Basic Usage
|
||||||
|
|
||||||
@@ -89,7 +89,7 @@ The following example will use a configuration file from an external public GitH
|
|||||||
|
|
||||||
Let's say that the configuration file is located in `github/octorepo/dependency-review-config.yml@main`
|
Let's say that the configuration file is located in `github/octorepo/dependency-review-config.yml@main`
|
||||||
|
|
||||||
The Dependancy Review Action workflow file will then look like this:
|
The Dependency Review Action workflow file will then look like this:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
name: 'Dependency Review'
|
name: 'Dependency Review'
|
||||||
@@ -116,7 +116,7 @@ The following example will use a configuration file from an external private Gti
|
|||||||
|
|
||||||
Let's say that the configuration file is located in `github/octorepo-private/dependency-review-config.yml@main`
|
Let's say that the configuration file is located in `github/octorepo-private/dependency-review-config.yml@main`
|
||||||
|
|
||||||
The Dependancy Review Action workflow file will then look like this:
|
The Dependency Review Action workflow file will then look like this:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
name: 'Dependency Review'
|
name: 'Dependency Review'
|
||||||
|
|||||||
Generated
+787
-817
File diff suppressed because it is too large
Load Diff
+22
-18
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "dependency-review-action",
|
"name": "dependency-review-action",
|
||||||
"version": "4.3.4",
|
"version": "4.7.3",
|
||||||
"private": true,
|
"private": true,
|
||||||
"description": "A GitHub Action for Dependency Review",
|
"description": "A GitHub Action for Dependency Review",
|
||||||
"main": "lib/main.js",
|
"main": "lib/main.js",
|
||||||
@@ -25,37 +25,41 @@
|
|||||||
"author": "GitHub",
|
"author": "GitHub",
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/core": "^1.10.1",
|
"@actions/core": "^1.11.1",
|
||||||
"@actions/github": "^6.0.0",
|
"@actions/github": "^6.0.1",
|
||||||
"@octokit/plugin-retry": "^6.0.1",
|
"@octokit/plugin-retry": "^6.1.0",
|
||||||
"@octokit/request-error": "^5.0.1",
|
"@octokit/request-error": "^5.1.1",
|
||||||
|
"@octokit/types": "12.5.0",
|
||||||
"@onebeyond/spdx-license-satisfies": "^1.0.1",
|
"@onebeyond/spdx-license-satisfies": "^1.0.1",
|
||||||
"ansi-styles": "^6.2.1",
|
"ansi-styles": "^6.2.1",
|
||||||
"got": "^14.4.1",
|
"got": "^14.4.7",
|
||||||
"jest": "^29.7.0",
|
"jest": "^29.7.0",
|
||||||
"octokit": "^3.1.2",
|
"octokit": "^3.1.2",
|
||||||
"spdx-expression-parse": "^3.0.1",
|
"spdx-expression-parse": "^3.0.1",
|
||||||
"spdx-satisfies": "^5.0.1",
|
"spdx-satisfies": "^6.0.0",
|
||||||
"ts-jest": "^29.1.2",
|
"ts-jest": "^29.4.1",
|
||||||
"yaml": "^2.3.4",
|
"yaml": "^2.8.1",
|
||||||
"zod": "^3.23.8"
|
"zod": "^3.24.1"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@types/jest": "^29.5.12",
|
"@types/jest": "^29.5.12",
|
||||||
"@types/node": "^20",
|
"@types/node": "^20",
|
||||||
"@types/spdx-expression-parse": "^3.0.4",
|
"@types/spdx-expression-parse": "^3.0.4",
|
||||||
"@types/spdx-satisfies": "^0.1.1",
|
|
||||||
"@typescript-eslint/eslint-plugin": "^6.21.0",
|
"@typescript-eslint/eslint-plugin": "^6.21.0",
|
||||||
"@typescript-eslint/parser": "^6.21.0",
|
"@typescript-eslint/parser": "^6.21.0",
|
||||||
"@vercel/ncc": "^0.38.0",
|
"@vercel/ncc": "^0.38.3",
|
||||||
"esbuild-register": "^3.5.0",
|
"esbuild-register": "^3.6.0",
|
||||||
"eslint": "^8.57.0",
|
"eslint": "^8.57.0",
|
||||||
"eslint-plugin-github": "^4.10.2",
|
"eslint-plugin-github": "^4.10.2",
|
||||||
"eslint-plugin-jest": "^27.9.0",
|
"eslint-plugin-jest": "^28.8.3",
|
||||||
"eslint-plugin-prettier": "^5.1.3",
|
"eslint-plugin-prettier": "^5.5.4",
|
||||||
"js-yaml": "^4.1.0",
|
"js-yaml": "^4.1.0",
|
||||||
"nodemon": "^3.1.0",
|
"nodemon": "^3.1.10",
|
||||||
"prettier": "3.2.5",
|
"prettier": "3.6.2",
|
||||||
"typescript": "^5.4.5"
|
"typescript": "^5.9.2"
|
||||||
|
},
|
||||||
|
"overrides": {
|
||||||
|
"cross-spawn": ">=7.0.5",
|
||||||
|
"@octokit/[email protected]": "5.1.1"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+3
-3
@@ -17,13 +17,13 @@ const COMMENT_MARKER = '<!-- dependency-review-pr-comment-marker -->'
|
|||||||
|
|
||||||
export async function commentPr(
|
export async function commentPr(
|
||||||
commentContent: string,
|
commentContent: string,
|
||||||
config: ConfigurationOptions
|
config: ConfigurationOptions,
|
||||||
|
issueFound: boolean
|
||||||
): Promise<void> {
|
): Promise<void> {
|
||||||
if (
|
if (
|
||||||
!(
|
!(
|
||||||
config.comment_summary_in_pr === 'always' ||
|
config.comment_summary_in_pr === 'always' ||
|
||||||
(config.comment_summary_in_pr === 'on-failure' &&
|
(config.comment_summary_in_pr === 'on-failure' && issueFound)
|
||||||
process.exitCode === core.ExitCode.Failure)
|
|
||||||
)
|
)
|
||||||
) {
|
) {
|
||||||
return
|
return
|
||||||
|
|||||||
+4
-9
@@ -9,15 +9,17 @@ export async function getDeniedChanges(
|
|||||||
): Promise<Change[]> {
|
): Promise<Change[]> {
|
||||||
const changesDenied: Change[] = []
|
const changesDenied: Change[] = []
|
||||||
|
|
||||||
let hasDeniedPackage = false
|
|
||||||
for (const change of changes) {
|
for (const change of changes) {
|
||||||
|
if (change.change_type === 'removed') {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
|
||||||
for (const denied of deniedPackages) {
|
for (const denied of deniedPackages) {
|
||||||
if (
|
if (
|
||||||
(!denied.version || change.version === denied.version) &&
|
(!denied.version || change.version === denied.version) &&
|
||||||
change.name === denied.name
|
change.name === denied.name
|
||||||
) {
|
) {
|
||||||
changesDenied.push(change)
|
changesDenied.push(change)
|
||||||
hasDeniedPackage = true
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -30,17 +32,10 @@ export async function getDeniedChanges(
|
|||||||
}
|
}
|
||||||
if (namespace && namespace === denied.namespace) {
|
if (namespace && namespace === denied.namespace) {
|
||||||
changesDenied.push(change)
|
changesDenied.push(change)
|
||||||
hasDeniedPackage = true
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (hasDeniedPackage) {
|
|
||||||
core.setFailed('Dependency review detected denied packages.')
|
|
||||||
} else {
|
|
||||||
core.info('Dependency review did not detect any denied packages')
|
|
||||||
}
|
|
||||||
|
|
||||||
return changesDenied
|
return changesDenied
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+22
-10
@@ -1,22 +1,34 @@
|
|||||||
import {PullRequestSchema, ConfigurationOptions} from './schemas'
|
import {
|
||||||
|
PullRequestSchema,
|
||||||
|
ConfigurationOptions,
|
||||||
|
MergeGroupSchema
|
||||||
|
} from './schemas'
|
||||||
|
|
||||||
export function getRefs(
|
export function getRefs(
|
||||||
config: ConfigurationOptions,
|
config: ConfigurationOptions,
|
||||||
context: {payload: {pull_request?: unknown}; eventName: string}
|
context: {
|
||||||
|
payload: {pull_request?: unknown; merge_group?: unknown}
|
||||||
|
eventName: string
|
||||||
|
}
|
||||||
): {base: string; head: string} {
|
): {base: string; head: string} {
|
||||||
let base_ref = config.base_ref
|
let base_ref = config.base_ref
|
||||||
let head_ref = config.head_ref
|
let head_ref = config.head_ref
|
||||||
|
|
||||||
// If possible, source default base & head refs from the GitHub event.
|
// If possible, source default base & head refs from the GitHub event.
|
||||||
// The base/head ref from the config take priority, if provided.
|
// The base/head ref from the config take priority, if provided.
|
||||||
if (
|
if (!base_ref && !head_ref) {
|
||||||
context.eventName === 'pull_request' ||
|
if (
|
||||||
context.eventName === 'pull_request_target' ||
|
context.eventName === 'pull_request' ||
|
||||||
context.eventName === 'merge_group'
|
context.eventName === 'pull_request_target'
|
||||||
) {
|
) {
|
||||||
const pull_request = PullRequestSchema.parse(context.payload.pull_request)
|
const pull_request = PullRequestSchema.parse(context.payload.pull_request)
|
||||||
base_ref = base_ref || pull_request.base.sha
|
base_ref = base_ref || pull_request.base.sha
|
||||||
head_ref = head_ref || pull_request.head.sha
|
head_ref = head_ref || pull_request.head.sha
|
||||||
|
} else if (context.eventName === 'merge_group') {
|
||||||
|
const merge_group = MergeGroupSchema.parse(context.payload.merge_group)
|
||||||
|
base_ref = base_ref || merge_group.base_sha
|
||||||
|
head_ref = head_ref || merge_group.head_sha
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!base_ref && !head_ref) {
|
if (!base_ref && !head_ref) {
|
||||||
|
|||||||
+47
-32
@@ -1,6 +1,6 @@
|
|||||||
import {Change, Changes} from './schemas'
|
import {Change, Changes} from './schemas'
|
||||||
import {octokitClient} from './utils'
|
import {octokitClient} from './utils'
|
||||||
import {parsePURL} from './purl'
|
import {parsePURL, PackageURL} from './purl'
|
||||||
import * as spdx from './spdx'
|
import * as spdx from './spdx'
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -29,41 +29,24 @@ export async function getInvalidLicenseChanges(
|
|||||||
licenseExclusions?: string[]
|
licenseExclusions?: string[]
|
||||||
}
|
}
|
||||||
): Promise<InvalidLicenseChanges> {
|
): Promise<InvalidLicenseChanges> {
|
||||||
const {allow, deny} = licenses
|
const deny = licenses.deny
|
||||||
|
let allow = licenses.allow
|
||||||
|
|
||||||
|
// Filter out elements of the allow list that include AND
|
||||||
|
// or OR because the list should be simple license IDs and
|
||||||
|
// not expressions.
|
||||||
|
allow = allow?.filter(license => {
|
||||||
|
return !license.includes(' AND ') && !license.includes(' OR ')
|
||||||
|
})
|
||||||
|
|
||||||
const licenseExclusions = licenses.licenseExclusions?.map(
|
const licenseExclusions = licenses.licenseExclusions?.map(
|
||||||
(pkgUrl: string) => {
|
(pkgUrl: string) => {
|
||||||
return parsePURL(pkgUrl)
|
return parsePURL(pkgUrl)
|
||||||
}
|
}
|
||||||
)
|
)
|
||||||
|
|
||||||
const groupedChanges = await groupChanges(changes)
|
const groupedChanges = await groupChanges(changes, licenseExclusions)
|
||||||
|
|
||||||
// Takes the changes from the groupedChanges object and filters out the ones that are part of the exclusions list
|
|
||||||
// It does by creating a new PackageURL object from the change and comparing it to the exclusions list
|
|
||||||
groupedChanges.licensed = groupedChanges.licensed.filter(change => {
|
|
||||||
if (change.package_url.length === 0) {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
const changeAsPackageURL = parsePURL(encodeURI(change.package_url))
|
|
||||||
|
|
||||||
// We want to find if the licenseExclusion list contains the PackageURL of the Change
|
|
||||||
// If it does, we want to filter it out and therefore return false
|
|
||||||
// If it doesn't, we want to keep it and therefore return true
|
|
||||||
if (
|
|
||||||
licenseExclusions !== null &&
|
|
||||||
licenseExclusions !== undefined &&
|
|
||||||
licenseExclusions.findIndex(
|
|
||||||
exclusion =>
|
|
||||||
exclusion.type === changeAsPackageURL.type &&
|
|
||||||
exclusion.name === changeAsPackageURL.name
|
|
||||||
) !== -1
|
|
||||||
) {
|
|
||||||
return false
|
|
||||||
} else {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
})
|
|
||||||
const licensedChanges: Changes = groupedChanges.licensed
|
const licensedChanges: Changes = groupedChanges.licensed
|
||||||
|
|
||||||
const invalidLicenseChanges: InvalidLicenseChanges = {
|
const invalidLicenseChanges: InvalidLicenseChanges = {
|
||||||
@@ -88,7 +71,7 @@ export async function getInvalidLicenseChanges(
|
|||||||
try {
|
try {
|
||||||
if (allow !== undefined) {
|
if (allow !== undefined) {
|
||||||
if (spdx.isValid(license)) {
|
if (spdx.isValid(license)) {
|
||||||
const found = spdx.satisfiesAny(license, allow)
|
const found = spdx.satisfies(license, allow)
|
||||||
validityCache.set(license, found)
|
validityCache.set(license, found)
|
||||||
} else {
|
} else {
|
||||||
invalidLicenseChanges.unresolved.push(change)
|
invalidLicenseChanges.unresolved.push(change)
|
||||||
@@ -172,16 +155,48 @@ const truncatedDGLicense = (license: string): boolean =>
|
|||||||
license.length === 255 && !spdx.isValid(license)
|
license.length === 255 && !spdx.isValid(license)
|
||||||
|
|
||||||
async function groupChanges(
|
async function groupChanges(
|
||||||
changes: Changes
|
changes: Changes,
|
||||||
|
licenseExclusions: PackageURL[] | null = null
|
||||||
): Promise<Record<string, Changes>> {
|
): Promise<Record<string, Changes>> {
|
||||||
const result: Record<string, Changes> = {
|
const result: Record<string, Changes> = {
|
||||||
licensed: [],
|
licensed: [],
|
||||||
unlicensed: []
|
unlicensed: []
|
||||||
}
|
}
|
||||||
|
|
||||||
|
let candidateChanges = changes
|
||||||
|
|
||||||
|
// If a package is excluded from license checking, we don't bother trying to
|
||||||
|
// fetch the license for it and we leave it off of the `licensed` and
|
||||||
|
// `unlicensed` lists.
|
||||||
|
if (licenseExclusions !== null && licenseExclusions !== undefined) {
|
||||||
|
candidateChanges = candidateChanges.filter(change => {
|
||||||
|
if (change.package_url.length === 0) {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
|
||||||
|
const changeAsPackageURL = parsePURL(encodeURI(change.package_url))
|
||||||
|
|
||||||
|
// We want to find if the licenseExclusion list contains the PackageURL of the Change
|
||||||
|
// If it does, we want to filter it out and therefore return false
|
||||||
|
// If it doesn't, we want to keep it and therefore return true
|
||||||
|
if (
|
||||||
|
licenseExclusions.findIndex(
|
||||||
|
exclusion =>
|
||||||
|
exclusion.type === changeAsPackageURL.type &&
|
||||||
|
exclusion.namespace === changeAsPackageURL.namespace &&
|
||||||
|
exclusion.name === changeAsPackageURL.name
|
||||||
|
) !== -1
|
||||||
|
) {
|
||||||
|
return false
|
||||||
|
} else {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
const ghChanges = []
|
const ghChanges = []
|
||||||
|
|
||||||
for (const change of changes) {
|
for (const change of candidateChanges) {
|
||||||
if (change.change_type === 'removed') {
|
if (change.change_type === 'removed') {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
|
|||||||
+45
-21
@@ -141,10 +141,16 @@ async function run(): Promise<void> {
|
|||||||
summary.addSnapshotWarnings(config, snapshot_warnings)
|
summary.addSnapshotWarnings(config, snapshot_warnings)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
let issueFound = false
|
||||||
|
|
||||||
if (config.vulnerability_check) {
|
if (config.vulnerability_check) {
|
||||||
core.setOutput('vulnerable-changes', JSON.stringify(vulnerableChanges))
|
core.setOutput('vulnerable-changes', JSON.stringify(vulnerableChanges))
|
||||||
summary.addChangeVulnerabilitiesToSummary(vulnerableChanges, minSeverity)
|
summary.addChangeVulnerabilitiesToSummary(vulnerableChanges, minSeverity)
|
||||||
printVulnerabilitiesBlock(vulnerableChanges, minSeverity, warnOnly)
|
issueFound ||= await printVulnerabilitiesBlock(
|
||||||
|
vulnerableChanges,
|
||||||
|
minSeverity,
|
||||||
|
warnOnly
|
||||||
|
)
|
||||||
}
|
}
|
||||||
if (config.license_check) {
|
if (config.license_check) {
|
||||||
core.setOutput(
|
core.setOutput(
|
||||||
@@ -152,12 +158,12 @@ async function run(): Promise<void> {
|
|||||||
JSON.stringify(invalidLicenseChanges)
|
JSON.stringify(invalidLicenseChanges)
|
||||||
)
|
)
|
||||||
summary.addLicensesToSummary(invalidLicenseChanges, config)
|
summary.addLicensesToSummary(invalidLicenseChanges, config)
|
||||||
printLicensesBlock(invalidLicenseChanges, warnOnly)
|
issueFound ||= await printLicensesBlock(invalidLicenseChanges, warnOnly)
|
||||||
}
|
}
|
||||||
if (config.deny_packages || config.deny_groups) {
|
if (config.deny_packages || config.deny_groups) {
|
||||||
core.setOutput('denied-changes', JSON.stringify(deniedChanges))
|
core.setOutput('denied-changes', JSON.stringify(deniedChanges))
|
||||||
summary.addDeniedToSummary(deniedChanges)
|
summary.addDeniedToSummary(deniedChanges)
|
||||||
printDeniedDependencies(deniedChanges, config)
|
issueFound ||= await printDeniedDependencies(deniedChanges, config)
|
||||||
}
|
}
|
||||||
if (config.show_openssf_scorecard) {
|
if (config.show_openssf_scorecard) {
|
||||||
summary.addScorecardToSummary(scorecard, config)
|
summary.addScorecardToSummary(scorecard, config)
|
||||||
@@ -182,7 +188,7 @@ async function run(): Promise<void> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// update the PR comment if needed with the right-sized summary
|
// update the PR comment if needed with the right-sized summary
|
||||||
await commentPr(rendered, config)
|
await commentPr(rendered, config, issueFound)
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
if (error instanceof RequestError && error.status === 404) {
|
if (error instanceof RequestError && error.status === 404) {
|
||||||
core.setFailed(
|
core.setFailed(
|
||||||
@@ -190,7 +196,7 @@ async function run(): Promise<void> {
|
|||||||
)
|
)
|
||||||
} else if (error instanceof RequestError && error.status === 403) {
|
} else if (error instanceof RequestError && error.status === 403) {
|
||||||
core.setFailed(
|
core.setFailed(
|
||||||
`Dependency review is not supported on this repository. Please ensure that Dependency graph is enabled along with GitHub Advanced Security on private repositories, see https://github.com/${github.context.repo.owner}/${github.context.repo.repo}/settings/security_analysis`
|
`Dependency review is not supported on this repository. Please ensure that Dependency graph is enabled along with GitHub Advanced Security on private repositories, see ${github.context.serverUrl}/${github.context.repo.owner}/${github.context.repo.repo}/settings/security_analysis`
|
||||||
)
|
)
|
||||||
} else {
|
} else {
|
||||||
if (error instanceof Error) {
|
if (error instanceof Error) {
|
||||||
@@ -204,18 +210,16 @@ async function run(): Promise<void> {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
function printVulnerabilitiesBlock(
|
async function printVulnerabilitiesBlock(
|
||||||
addedChanges: Changes,
|
addedChanges: Changes,
|
||||||
minSeverity: Severity,
|
minSeverity: Severity,
|
||||||
warnOnly: boolean
|
warnOnly: boolean
|
||||||
): void {
|
): Promise<boolean> {
|
||||||
let vulFound = false
|
return core.group('Vulnerabilities', async () => {
|
||||||
core.group('Vulnerabilities', async () => {
|
let vulFound = false
|
||||||
if (addedChanges.length > 0) {
|
|
||||||
for (const change of addedChanges) {
|
for (const change of addedChanges) {
|
||||||
printChangeVulnerabilities(change)
|
vulFound ||= printChangeVulnerabilities(change)
|
||||||
}
|
|
||||||
vulFound = true
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (vulFound) {
|
if (vulFound) {
|
||||||
@@ -230,10 +234,12 @@ function printVulnerabilitiesBlock(
|
|||||||
`Dependency review did not detect any vulnerable packages with severity level "${minSeverity}" or higher.`
|
`Dependency review did not detect any vulnerable packages with severity level "${minSeverity}" or higher.`
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
return vulFound
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
function printChangeVulnerabilities(change: Change): void {
|
function printChangeVulnerabilities(change: Change): boolean {
|
||||||
for (const vuln of change.vulnerabilities) {
|
for (const vuln of change.vulnerabilities) {
|
||||||
core.info(
|
core.info(
|
||||||
`${styles.bold.open}${change.manifest} » ${change.name}@${
|
`${styles.bold.open}${change.manifest} » ${change.name}@${
|
||||||
@@ -244,14 +250,18 @@ function printChangeVulnerabilities(change: Change): void {
|
|||||||
)
|
)
|
||||||
core.info(` ↪ ${vuln.advisory_url}`)
|
core.info(` ↪ ${vuln.advisory_url}`)
|
||||||
}
|
}
|
||||||
|
return change.vulnerabilities.length > 0
|
||||||
}
|
}
|
||||||
|
|
||||||
function printLicensesBlock(
|
async function printLicensesBlock(
|
||||||
invalidLicenseChanges: Record<string, Changes>,
|
invalidLicenseChanges: Record<string, Changes>,
|
||||||
warnOnly: boolean
|
warnOnly: boolean
|
||||||
): void {
|
): Promise<boolean> {
|
||||||
core.group('Licenses', async () => {
|
return core.group('Licenses', async () => {
|
||||||
|
let issueFound = false
|
||||||
|
|
||||||
if (invalidLicenseChanges.forbidden.length > 0) {
|
if (invalidLicenseChanges.forbidden.length > 0) {
|
||||||
|
issueFound = true
|
||||||
core.info('\nThe following dependencies have incompatible licenses:')
|
core.info('\nThe following dependencies have incompatible licenses:')
|
||||||
printLicensesError(invalidLicenseChanges.forbidden)
|
printLicensesError(invalidLicenseChanges.forbidden)
|
||||||
const msg = 'Dependency review detected incompatible licenses.'
|
const msg = 'Dependency review detected incompatible licenses.'
|
||||||
@@ -262,6 +272,7 @@ function printLicensesBlock(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
if (invalidLicenseChanges.unresolved.length > 0) {
|
if (invalidLicenseChanges.unresolved.length > 0) {
|
||||||
|
issueFound = true
|
||||||
core.warning(
|
core.warning(
|
||||||
'\nThe validity of the licenses of the dependencies below could not be determined. Ensure that they are valid SPDX licenses:'
|
'\nThe validity of the licenses of the dependencies below could not be determined. Ensure that they are valid SPDX licenses:'
|
||||||
)
|
)
|
||||||
@@ -271,6 +282,8 @@ function printLicensesBlock(
|
|||||||
)
|
)
|
||||||
}
|
}
|
||||||
printNullLicenses(invalidLicenseChanges.unlicensed)
|
printNullLicenses(invalidLicenseChanges.unlicensed)
|
||||||
|
|
||||||
|
return issueFound
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -370,11 +383,13 @@ function printScannedDependencies(changes: Changes): void {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
function printDeniedDependencies(
|
async function printDeniedDependencies(
|
||||||
changes: Changes,
|
changes: Changes,
|
||||||
config: ConfigurationOptions
|
config: ConfigurationOptions
|
||||||
): void {
|
): Promise<boolean> {
|
||||||
core.group('Denied', async () => {
|
return core.group('Denied', async () => {
|
||||||
|
let issueFound = false
|
||||||
|
|
||||||
for (const denied of config.deny_packages) {
|
for (const denied of config.deny_packages) {
|
||||||
core.info(`Config: ${denied}`)
|
core.info(`Config: ${denied}`)
|
||||||
}
|
}
|
||||||
@@ -383,6 +398,15 @@ function printDeniedDependencies(
|
|||||||
core.info(`Change: ${change.name}@${change.version} is denied`)
|
core.info(`Change: ${change.name}@${change.version} is denied`)
|
||||||
core.info(`Change: ${change.package_url} is denied`)
|
core.info(`Change: ${change.package_url} is denied`)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (changes.length > 0) {
|
||||||
|
issueFound = true
|
||||||
|
core.setFailed('Dependency review detected denied packages.')
|
||||||
|
} else {
|
||||||
|
core.info('Dependency review did not detect any denied packages')
|
||||||
|
}
|
||||||
|
|
||||||
|
return issueFound
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -91,6 +91,11 @@ export const PullRequestSchema = z.object({
|
|||||||
head: z.object({sha: z.string()})
|
head: z.object({sha: z.string()})
|
||||||
})
|
})
|
||||||
|
|
||||||
|
export const MergeGroupSchema = z.object({
|
||||||
|
base_sha: z.string(),
|
||||||
|
head_sha: z.string()
|
||||||
|
})
|
||||||
|
|
||||||
export const ConfigurationOptionsSchema = z
|
export const ConfigurationOptionsSchema = z
|
||||||
.object({
|
.object({
|
||||||
fail_on_severity: SeveritySchema,
|
fail_on_severity: SeveritySchema,
|
||||||
|
|||||||
Vendored
+4
@@ -0,0 +1,4 @@
|
|||||||
|
declare module 'spdx-satisfies' {
|
||||||
|
function spdxSatisfies(candidate: string, allowList: string[]): boolean
|
||||||
|
export = spdxSatisfies
|
||||||
|
}
|
||||||
+15
-5
@@ -1,4 +1,5 @@
|
|||||||
import * as spdxlib from '@onebeyond/spdx-license-satisfies'
|
import * as spdxlib from '@onebeyond/spdx-license-satisfies'
|
||||||
|
import spdxSatisfies from 'spdx-satisfies'
|
||||||
import parse from 'spdx-expression-parse'
|
import parse from 'spdx-expression-parse'
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -10,12 +11,10 @@ import parse from 'spdx-expression-parse'
|
|||||||
|
|
||||||
// accepts a pair of well-formed SPDX expressions. the
|
// accepts a pair of well-formed SPDX expressions. the
|
||||||
// candidate is tested against the constraint
|
// candidate is tested against the constraint
|
||||||
export function satisfies(
|
export function satisfies(candidateExpr: string, allowList: string[]): boolean {
|
||||||
candidateExpr: string,
|
candidateExpr = cleanInvalidSPDX(candidateExpr)
|
||||||
constraintExpr: string
|
|
||||||
): boolean {
|
|
||||||
try {
|
try {
|
||||||
return spdxlib.satisfies(candidateExpr, constraintExpr)
|
return spdxSatisfies(candidateExpr, allowList)
|
||||||
} catch (_) {
|
} catch (_) {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
@@ -26,6 +25,7 @@ export function satisfiesAny(
|
|||||||
candidateExpr: string,
|
candidateExpr: string,
|
||||||
licenses: string[]
|
licenses: string[]
|
||||||
): boolean {
|
): boolean {
|
||||||
|
candidateExpr = cleanInvalidSPDX(candidateExpr)
|
||||||
try {
|
try {
|
||||||
return spdxlib.satisfiesAny(candidateExpr, licenses)
|
return spdxlib.satisfiesAny(candidateExpr, licenses)
|
||||||
} catch (_) {
|
} catch (_) {
|
||||||
@@ -38,6 +38,7 @@ export function satisfiesAll(
|
|||||||
candidateExpr: string,
|
candidateExpr: string,
|
||||||
licenses: string[]
|
licenses: string[]
|
||||||
): boolean {
|
): boolean {
|
||||||
|
candidateExpr = cleanInvalidSPDX(candidateExpr)
|
||||||
try {
|
try {
|
||||||
return spdxlib.satisfiesAll(candidateExpr, licenses)
|
return spdxlib.satisfiesAll(candidateExpr, licenses)
|
||||||
} catch (_) {
|
} catch (_) {
|
||||||
@@ -47,6 +48,7 @@ export function satisfiesAll(
|
|||||||
|
|
||||||
// accepts any SPDX expression
|
// accepts any SPDX expression
|
||||||
export function isValid(spdxExpr: string): boolean {
|
export function isValid(spdxExpr: string): boolean {
|
||||||
|
spdxExpr = cleanInvalidSPDX(spdxExpr)
|
||||||
try {
|
try {
|
||||||
parse(spdxExpr)
|
parse(spdxExpr)
|
||||||
return true
|
return true
|
||||||
@@ -54,3 +56,11 @@ export function isValid(spdxExpr: string): boolean {
|
|||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const replaceOtherRegex = /(?<![\w-])OTHER(?![\w-])/g
|
||||||
|
|
||||||
|
// adjusts license expressions to not include the invalid `OTHER`
|
||||||
|
// which ClearlyDefined adds to license strings
|
||||||
|
export function cleanInvalidSPDX(spdxExpr: string): string {
|
||||||
|
return spdxExpr.replace(replaceOtherRegex, 'LicenseRef-clearlydefined-OTHER')
|
||||||
|
}
|
||||||
|
|||||||
+20
-1
@@ -22,6 +22,10 @@ export function addSummaryToSummary(
|
|||||||
scorecard: Scorecard,
|
scorecard: Scorecard,
|
||||||
config: ConfigurationOptions
|
config: ConfigurationOptions
|
||||||
): string {
|
): string {
|
||||||
|
if (config.deny_licenses && config.deny_licenses.length > 0) {
|
||||||
|
addDenyListsDeprecationWarningToSummary()
|
||||||
|
}
|
||||||
|
|
||||||
const out: string[] = []
|
const out: string[] = []
|
||||||
|
|
||||||
const scorecardWarnings = countScorecardWarnings(scorecard, config)
|
const scorecardWarnings = countScorecardWarnings(scorecard, config)
|
||||||
@@ -106,6 +110,13 @@ export function addSummaryToSummary(
|
|||||||
return out.join('\n')
|
return out.join('\n')
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function addDenyListsDeprecationWarningToSummary(): void {
|
||||||
|
core.summary.addRaw(
|
||||||
|
`${icons.warning} <strong>Deprecation Warning</strong>: The <em>deny-licenses</em> option is deprecated for possible removal in the next major release. For more information, see actions/dependency-review-action/issues/938.`,
|
||||||
|
true
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
function countScorecardWarnings(
|
function countScorecardWarnings(
|
||||||
scorecard: Scorecard,
|
scorecard: Scorecard,
|
||||||
config: ConfigurationOptions
|
config: ConfigurationOptions
|
||||||
@@ -291,7 +302,12 @@ export function addScannedFiles(changes: Changes): void {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
core.summary.addHeading('Scanned Files', 2).addList(manifests)
|
const summary = core.summary.addHeading('Scanned Files', 2)
|
||||||
|
if (manifests.length === 0) {
|
||||||
|
summary.addRaw('None')
|
||||||
|
} else {
|
||||||
|
summary.addList(manifests)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
function snapshotWarningRecommendation(
|
function snapshotWarningRecommendation(
|
||||||
@@ -316,6 +332,9 @@ export function addScorecardToSummary(
|
|||||||
scorecard: Scorecard,
|
scorecard: Scorecard,
|
||||||
config: ConfigurationOptions
|
config: ConfigurationOptions
|
||||||
): void {
|
): void {
|
||||||
|
if (scorecard.dependencies.length === 0) {
|
||||||
|
return
|
||||||
|
}
|
||||||
core.summary.addHeading('OpenSSF Scorecard', 2)
|
core.summary.addHeading('OpenSSF Scorecard', 2)
|
||||||
if (scorecard.dependencies.length > 10) {
|
if (scorecard.dependencies.length > 10) {
|
||||||
core.summary.addRaw(`<details><summary>Scorecard details</summary>`, true)
|
core.summary.addRaw(`<details><summary>Scorecard details</summary>`, true)
|
||||||
|
|||||||
Reference in New Issue
Block a user