Compare commits
23
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3c42649204 | ||
|
|
8e6ea8d29b | ||
|
|
1b3d2772d0 | ||
|
|
220872c81a | ||
|
|
087d0f81a5 | ||
|
|
4531204be7 | ||
|
|
df1ca890c5 | ||
|
|
97c6dd59c3 | ||
|
|
0bec1ca5b4 | ||
|
|
5460632ba9 | ||
|
|
f7aca4f481 | ||
|
|
1988567896 | ||
|
|
1e26117d02 | ||
|
|
b1e704b9d6 | ||
|
|
48fae2e703 | ||
|
|
8d625cd32e | ||
|
|
3afc0d4eaa | ||
|
|
bc8dee91fe | ||
|
|
0669e2939d | ||
|
|
fd46ab736e | ||
|
|
551e0b82bd | ||
|
|
fbfa3f19c8 | ||
|
|
4c5eeccebb |
+56
-38
@@ -4,41 +4,52 @@
|
|||||||
[pr]: https://github.com/actions/dependency-review-action/compare
|
[pr]: https://github.com/actions/dependency-review-action/compare
|
||||||
[code-of-conduct]: CODE_OF_CONDUCT.md
|
[code-of-conduct]: CODE_OF_CONDUCT.md
|
||||||
|
|
||||||
Hi there! We're thrilled that you'd like to contribute to this project. Your help is essential for keeping it great.
|
Hi there! We're thrilled that you'd like to contribute to this project.
|
||||||
|
|
||||||
Contributions to this project are
|
Contributions to this project are [released](https://help.github.com/articles/github-terms-of-service/#6-contributions-under-repository-license) to the public under the [project's open source license](LICENSE).
|
||||||
[released](https://help.github.com/articles/github-terms-of-service/#6-contributions-under-repository-license)
|
|
||||||
to the public under the [project's open source license](LICENSE).
|
|
||||||
|
|
||||||
Please note that this project is released with a [Contributor Code of
|
Please note that this project is released with a [Contributor Code of Conduct][code-of-conduct]. By participating in this project you agree to abide by its terms.
|
||||||
Conduct][code-of-conduct]. By participating in this project you agree
|
|
||||||
to abide by its terms.
|
|
||||||
|
|
||||||
### How it works
|
## Bug reports and other issues
|
||||||
|
|
||||||
This Action makes an authenticated query to the Dependency Graph Diff
|
If you've encountered a problem, please let us know by [submitting an issue](https://github.com/actions/dependency-review-action/issues/new)!
|
||||||
API endpoint (`GET /repos/{owner}/{repo}/dependency-graph/compare/{basehead}`)
|
|
||||||
to find out the set of added and removed dependencies for each manifest.
|
|
||||||
|
|
||||||
### Bootstrapping the project
|
## Enhancements and feature requests
|
||||||
|
|
||||||
```
|
If you've got an idea for a new feature, please submit as [an issue](https://github.com/actions/dependency-review-action/issues/new) so that the community can see it, and we can discuss it there. We may not be able to respond to every single issue, but will make a best effort!
|
||||||
git clone https://github.com/actions/dependency-review-action.git
|
|
||||||
cd dependency-review-action
|
|
||||||
npm install
|
|
||||||
```
|
|
||||||
|
|
||||||
### Running the tests
|
If you'd like to make a contribution yourself, we ask that before significant effort is put into code changes, that we have agreement that the change aligns with our strategy for the action. Since this is a verified Action owned by GitHub we want to make sure that contributions are high quality, and that they maintain consistency with the rest of the action's behavior.
|
||||||
|
|
||||||
```
|
1. Create an [issue discussing the idea](https://github.com/actions/dependency-review-action/issues/new), so that we can discuss it there.
|
||||||
npm run test
|
2. If we agree to incorporate the idea into the action, please write-up a high level summary of the approach that you plan to take so we can review
|
||||||
```
|
|
||||||
|
|
||||||
_Note_: We don't have any useful tests yet, contributions are welcome!
|
## Stalebot
|
||||||
|
|
||||||
## Local Development
|
We have begun using a [Stalebot action](https://github.com/actions/stale) to help keep the Issues and Pull requests backlogs tidy. You can see the configuration [here](.github/workflows/stalebot.yml). If you'd like to keep an issue open after getting a stalebot warning, simply comment on it and it'll reset the clock.
|
||||||
|
|
||||||
|
## Development lifecycle
|
||||||
|
|
||||||
|
Ready to contribute to `dependency-review-action`? Here is some information to help you get started.
|
||||||
|
|
||||||
|
### High level overview of the action
|
||||||
|
|
||||||
|
This action makes an authenticated query to the [Dependency Review API](https://docs.github.com/en/rest/dependency-graph/dependency-review) endpoint (`GET /repos/{owner}/{repo}/dependency-graph/compare/{basehead}`) to find out the set of added and removed dependencies for each manifest.
|
||||||
|
|
||||||
|
The action then evaluates the differences between the pushes based on the the rules defined in the action configuration, and summarizes the differences and any violations of the rules you have defined as a comment in the pull request that triggered it and the action outputs.
|
||||||
|
|
||||||
|
### Local Development
|
||||||
|
|
||||||
|
Before you begin, you need to have [Node.js](https://nodejs.org/en/) installed, minimum version 18.
|
||||||
|
|
||||||
|
#### Bootstrapping the project
|
||||||
|
|
||||||
|
0. [Fork][fork] and clone the repository
|
||||||
|
1. Change to the working directory: `cd dependency-review-action`
|
||||||
|
2. Install the dependencies: `npm install`
|
||||||
|
3. Make sure the tests pass on your machine: `npm run test`
|
||||||
|
|
||||||
|
#### Manually testing for vulnerabilities
|
||||||
|
|
||||||
It is recommended to have atleast [Node 18](https://nodejs.org/en/) installed.
|
|
||||||
We have a script to scan a given PR for vulnerabilities, this will
|
We have a script to scan a given PR for vulnerabilities, this will
|
||||||
help you test your local changes. Make sure to [grab a Personal Access Token (PAT)](https://github.com/settings/tokens) before proceeding (you'll need `repo` permissions for private repos):
|
help you test your local changes. Make sure to [grab a Personal Access Token (PAT)](https://github.com/settings/tokens) before proceeding (you'll need `repo` permissions for private repos):
|
||||||
|
|
||||||
@@ -53,7 +64,7 @@ $ GITHUB_TOKEN=<token> ./scripts/scan_pr <pr_url>
|
|||||||
Like this:
|
Like this:
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
$ GITHUB_TOKEN=my-secret-token ./scripts/scan_pr https://github.com/actions/dependency-review-action/pull/3
|
$ GITHUB_TOKEN=<token> ./scripts/scan_pr https://github.com/actions/dependency-review-action/pull/3
|
||||||
```
|
```
|
||||||
|
|
||||||
[Configuration options](README.md#configuration-options) can be set by
|
[Configuration options](README.md#configuration-options) can be set by
|
||||||
@@ -64,16 +75,20 @@ passing an external YAML [configuration file](README.md#configuration-file) to t
|
|||||||
$ GITHUB_TOKEN=<token> ./scripts/scan_pr --config-file my_custom_config.yml <pr_url>
|
$ GITHUB_TOKEN=<token> ./scripts/scan_pr --config-file my_custom_config.yml <pr_url>
|
||||||
```
|
```
|
||||||
|
|
||||||
## Submitting a pull request
|
#### Running unit tests
|
||||||
|
|
||||||
0. [Fork][fork] and clone the repository
|
```
|
||||||
1. Configure and install the dependencies: `npm install`
|
npm run test
|
||||||
2. Make sure the tests pass on your machine: `npm run test`
|
```
|
||||||
3. Create a new branch: `git checkout -b my-branch-name`
|
|
||||||
4. Make your change, add tests, and make sure the tests still pass
|
_Note_: We don't a very comprehensive test suite, so any contributions to the existing tests are welcome!
|
||||||
5. Make sure to build and package before pushing: `npm run build && npm run package`
|
|
||||||
6. Push to your fork and [submit a pull request][pr]
|
### Submitting a pull request
|
||||||
7. Pat your self on the back and wait for your pull request to be reviewed and merged.
|
|
||||||
|
1. Create a new branch: `git checkout -b my-branch-name`
|
||||||
|
2. Make your change, add tests, and make sure the tests still pass
|
||||||
|
3. Make sure to build and package before pushing: `npm run build && npm run package`
|
||||||
|
4. Push to your fork and [submit a pull request][pr]
|
||||||
|
|
||||||
Here are a few things you can do that will increase the likelihood of your pull request being accepted:
|
Here are a few things you can do that will increase the likelihood of your pull request being accepted:
|
||||||
|
|
||||||
@@ -82,9 +97,14 @@ Here are a few things you can do that will increase the likelihood of your pull
|
|||||||
- Write a [good commit message](https://tbaggery.com/2008/04/19/a-note-about-git-commit-messages.html).
|
- Write a [good commit message](https://tbaggery.com/2008/04/19/a-note-about-git-commit-messages.html).
|
||||||
- Add examples of the usage to [examples.md](docs/examples.md)
|
- Add examples of the usage to [examples.md](docs/examples.md)
|
||||||
- Link to a sample PR in a custom repository running your version of the Action.
|
- Link to a sample PR in a custom repository running your version of the Action.
|
||||||
|
- Please be responsive to any questions and feedback that you get from a maintainer of the repo!
|
||||||
|
|
||||||
## Cutting a new release
|
## Cutting a new release
|
||||||
|
|
||||||
|
<details>
|
||||||
|
|
||||||
|
_Note: these instructions are for maintainers_
|
||||||
|
|
||||||
1. Update the version number in [package.json](https://github.com/actions/dependency-review-action/blob/main/package.json) and run `npm i` to update the lockfile.
|
1. Update the version number in [package.json](https://github.com/actions/dependency-review-action/blob/main/package.json) and run `npm i` to update the lockfile.
|
||||||
1. Go to [Draft a new
|
1. Go to [Draft a new
|
||||||
release](https://github.com/actions/dependency-review-action/releases/new)
|
release](https://github.com/actions/dependency-review-action/releases/new)
|
||||||
@@ -117,13 +137,11 @@ To do this just checkout `main`, force-create a new annotated tag, and push it:
|
|||||||
git tag -fa v4 -m "Updating v4 to 4.0.1"
|
git tag -fa v4 -m "Updating v4 to 4.0.1"
|
||||||
git push origin v4 --force
|
git push origin v4 --force
|
||||||
```
|
```
|
||||||
|
</details>
|
||||||
|
|
||||||
## Stalebot
|
|
||||||
|
|
||||||
We have begun using a [Stalebot action](https://github.com/actions/stale) to help keep the Issues and Pull requests backlogs tidy. You can see the configuration [here](.github/workflows/stalebot.yml). If you'd like to keep an issue open after getting a stalebot warning, simply comment on it and it'll reset the clock.
|
|
||||||
|
|
||||||
## Resources
|
## Resources
|
||||||
|
|
||||||
|
- [Creating JavaScript GitHub actions](https://docs.github.com/en/actions/creating-actions/creating-a-javascript-action)
|
||||||
- [How to Contribute to Open Source](https://opensource.guide/how-to-contribute/)
|
- [How to Contribute to Open Source](https://opensource.guide/how-to-contribute/)
|
||||||
- [Using Pull Requests](https://help.github.com/articles/about-pull-requests/)
|
- [Using Pull Requests](https://help.github.com/articles/about-pull-requests/)
|
||||||
- [GitHub Help](https://help.github.com)
|
|
||||||
|
|||||||
+1
-1
@@ -1,3 +1,3 @@
|
|||||||
If you discover a security issue in this repo, please submit it through the [GitHub Security Bug Bounty](https://hackerone.com/github)
|
If you discover a security issue in this repo, please submit it through the [GitHub Security Bug Bounty](https://bounty.github.com/)
|
||||||
|
|
||||||
Thanks for helping make GitHub Actions safe for everyone.
|
Thanks for helping make GitHub Actions safe for everyone.
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
fail_on_severity: critical
|
fail_on_severity: critical
|
||||||
allow_licenses:
|
allow_licenses:
|
||||||
- "BSD"
|
- 'BSD'
|
||||||
- "GPL 2"
|
- 'GPL 2'
|
||||||
|
|||||||
@@ -1 +1 @@
|
|||||||
allow-licenses: "MIT, GPL-2.0-only"
|
allow-licenses: 'MIT, GPL-2.0-only'
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
import {expect, jest, test} from '@jest/globals'
|
import {expect, jest, test} from '@jest/globals'
|
||||||
import {Changes, ConfigurationOptions, Scorecard} from '../src/schemas'
|
import {Change, Changes, ConfigurationOptions, Scorecard} from '../src/schemas'
|
||||||
import * as summary from '../src/summary'
|
import * as summary from '../src/summary'
|
||||||
import * as core from '@actions/core'
|
import * as core from '@actions/core'
|
||||||
import {createTestChange} from './fixtures/create-test-change'
|
import {createTestChange} from './fixtures/create-test-change'
|
||||||
@@ -109,6 +109,80 @@ test('prints headline as h1', () => {
|
|||||||
expect(text).toContain('<h1>Dependency Review</h1>')
|
expect(text).toContain('<h1>Dependency Review</h1>')
|
||||||
})
|
})
|
||||||
|
|
||||||
|
test('returns minimal summary in case the core.summary is too large for a PR comment', () => {
|
||||||
|
let changes: Changes = [
|
||||||
|
createTestChange({name: 'lodash', version: '1.2.3'}),
|
||||||
|
createTestChange({name: 'colors', version: '2.3.4'}),
|
||||||
|
createTestChange({name: '@foo/bar', version: '*'})
|
||||||
|
]
|
||||||
|
|
||||||
|
let minSummary: string = summary.addSummaryToSummary(
|
||||||
|
changes,
|
||||||
|
emptyInvalidLicenseChanges,
|
||||||
|
emptyChanges,
|
||||||
|
scorecard,
|
||||||
|
defaultConfig
|
||||||
|
)
|
||||||
|
|
||||||
|
// side effect DR report into core.summary as happens in main.ts
|
||||||
|
summary.addScannedDependencies(changes)
|
||||||
|
const text = core.summary.stringify()
|
||||||
|
|
||||||
|
expect(text).toContain('<h1>Dependency Review</h1>')
|
||||||
|
expect(minSummary).toContain('# Dependency Review')
|
||||||
|
|
||||||
|
expect(text).toContain('❌ 3 vulnerable package(s)')
|
||||||
|
expect(text).not.toContain('* ❌ 3 vulnerable package(s)')
|
||||||
|
expect(text).toContain('lodash')
|
||||||
|
expect(text).toContain('colors')
|
||||||
|
expect(text).toContain('@foo/bar')
|
||||||
|
|
||||||
|
expect(minSummary).toContain('* ❌ 3 vulnerable package(s)')
|
||||||
|
expect(minSummary).not.toContain('lodash')
|
||||||
|
expect(minSummary).not.toContain('colors')
|
||||||
|
expect(minSummary).not.toContain('@foo/bar')
|
||||||
|
|
||||||
|
expect(text.length).toBeGreaterThan(minSummary.length)
|
||||||
|
})
|
||||||
|
|
||||||
|
test('returns minimal summary formatted for posting as a PR comment', () => {
|
||||||
|
const OLD_ENV = process.env
|
||||||
|
|
||||||
|
let changes: Changes = [
|
||||||
|
createTestChange({name: 'lodash', version: '1.2.3'}),
|
||||||
|
createTestChange({name: 'colors', version: '2.3.4'}),
|
||||||
|
createTestChange({name: '@foo/bar', version: '*'})
|
||||||
|
]
|
||||||
|
|
||||||
|
process.env.GITHUB_SERVER_URL = 'https://github.com'
|
||||||
|
process.env.GITHUB_REPOSITORY = 'owner/repo'
|
||||||
|
process.env.GITHUB_RUN_ID = 'abc-123-xyz'
|
||||||
|
|
||||||
|
let minSummary: string = summary.addSummaryToSummary(
|
||||||
|
changes,
|
||||||
|
emptyInvalidLicenseChanges,
|
||||||
|
emptyChanges,
|
||||||
|
scorecard,
|
||||||
|
defaultConfig
|
||||||
|
)
|
||||||
|
|
||||||
|
process.env = OLD_ENV
|
||||||
|
|
||||||
|
// note: no Actions context values in unit test env
|
||||||
|
const expected = `
|
||||||
|
# Dependency Review
|
||||||
|
The following issues were found:
|
||||||
|
* ❌ 3 vulnerable package(s)
|
||||||
|
* ✅ 0 package(s) with incompatible licenses
|
||||||
|
* ✅ 0 package(s) with invalid SPDX license definitions
|
||||||
|
* ✅ 0 package(s) with unknown licenses.
|
||||||
|
|
||||||
|
[View full job summary](https://github.com/owner/repo/actions/runs/abc-123-xyz)
|
||||||
|
`.trim()
|
||||||
|
|
||||||
|
expect(minSummary).toEqual(expected)
|
||||||
|
})
|
||||||
|
|
||||||
test('only includes "No vulnerabilities or license issues found"-message if both are configured and nothing was found', () => {
|
test('only includes "No vulnerabilities or license issues found"-message if both are configured and nothing was found', () => {
|
||||||
summary.addSummaryToSummary(
|
summary.addSummaryToSummary(
|
||||||
emptyChanges,
|
emptyChanges,
|
||||||
|
|||||||
+38
-15
@@ -46,20 +46,19 @@ var __asyncValues = (this && this.__asyncValues) || function (o) {
|
|||||||
function settle(resolve, reject, d, v) { Promise.resolve(v).then(function(v) { resolve({ value: v, done: d }); }, reject); }
|
function settle(resolve, reject, d, v) { Promise.resolve(v).then(function(v) { resolve({ value: v, done: d }); }, reject); }
|
||||||
};
|
};
|
||||||
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
Object.defineProperty(exports, "__esModule", ({ value: true }));
|
||||||
exports.commentPr = void 0;
|
exports.commentPr = exports.MAX_COMMENT_LENGTH = void 0;
|
||||||
const github = __importStar(__nccwpck_require__(5438));
|
const github = __importStar(__nccwpck_require__(5438));
|
||||||
const core = __importStar(__nccwpck_require__(2186));
|
const core = __importStar(__nccwpck_require__(2186));
|
||||||
const githubUtils = __importStar(__nccwpck_require__(3030));
|
const githubUtils = __importStar(__nccwpck_require__(3030));
|
||||||
const retry = __importStar(__nccwpck_require__(6298));
|
const retry = __importStar(__nccwpck_require__(6298));
|
||||||
const request_error_1 = __nccwpck_require__(537);
|
const request_error_1 = __nccwpck_require__(537);
|
||||||
|
exports.MAX_COMMENT_LENGTH = 65536;
|
||||||
const retryingOctokit = githubUtils.GitHub.plugin(retry.retry);
|
const retryingOctokit = githubUtils.GitHub.plugin(retry.retry);
|
||||||
const octo = new retryingOctokit(githubUtils.getOctokitOptions(core.getInput('repo-token', { required: true })));
|
const octo = new retryingOctokit(githubUtils.getOctokitOptions(core.getInput('repo-token', { required: true })));
|
||||||
// Comment Marker to identify an existing comment to update, so we don't spam the PR with comments
|
// Comment Marker to identify an existing comment to update, so we don't spam the PR with comments
|
||||||
const COMMENT_MARKER = '<!-- dependency-review-pr-comment-marker -->';
|
const COMMENT_MARKER = '<!-- dependency-review-pr-comment-marker -->';
|
||||||
function commentPr(summary, config) {
|
function commentPr(commentContent, config) {
|
||||||
return __awaiter(this, void 0, void 0, function* () {
|
return __awaiter(this, void 0, void 0, function* () {
|
||||||
const commentContent = summary.stringify();
|
|
||||||
core.setOutput('comment-content', commentContent);
|
|
||||||
if (!(config.comment_summary_in_pr === 'always' ||
|
if (!(config.comment_summary_in_pr === 'always' ||
|
||||||
(config.comment_summary_in_pr === 'on-failure' &&
|
(config.comment_summary_in_pr === 'on-failure' &&
|
||||||
process.exitCode === core.ExitCode.Failure))) {
|
process.exitCode === core.ExitCode.Failure))) {
|
||||||
@@ -648,7 +647,7 @@ function run() {
|
|||||||
core.debug(`Config Deny Packages: ${JSON.stringify(config)}`);
|
core.debug(`Config Deny Packages: ${JSON.stringify(config)}`);
|
||||||
const deniedChanges = yield (0, deny_1.getDeniedChanges)(filteredChanges, config.deny_packages, config.deny_groups);
|
const deniedChanges = yield (0, deny_1.getDeniedChanges)(filteredChanges, config.deny_packages, config.deny_groups);
|
||||||
const scorecard = yield (0, scorecard_1.getScorecardLevels)(filteredChanges);
|
const scorecard = yield (0, scorecard_1.getScorecardLevels)(filteredChanges);
|
||||||
summary.addSummaryToSummary(vulnerableChanges, invalidLicenseChanges, deniedChanges, scorecard, config);
|
const minSummary = summary.addSummaryToSummary(vulnerableChanges, invalidLicenseChanges, deniedChanges, scorecard, config);
|
||||||
if (snapshot_warnings) {
|
if (snapshot_warnings) {
|
||||||
summary.addSnapshotWarnings(config, snapshot_warnings);
|
summary.addSnapshotWarnings(config, snapshot_warnings);
|
||||||
}
|
}
|
||||||
@@ -675,7 +674,16 @@ function run() {
|
|||||||
core.setOutput('dependency-changes', JSON.stringify(changes));
|
core.setOutput('dependency-changes', JSON.stringify(changes));
|
||||||
summary.addScannedDependencies(changes);
|
summary.addScannedDependencies(changes);
|
||||||
printScannedDependencies(changes);
|
printScannedDependencies(changes);
|
||||||
yield (0, comment_pr_1.commentPr)(core.summary, config);
|
// include full summary in output; Actions will truncate if oversized
|
||||||
|
let rendered = core.summary.stringify();
|
||||||
|
core.setOutput('comment-content', rendered);
|
||||||
|
// if the summary is oversized, replace with minimal version
|
||||||
|
if (rendered.length >= comment_pr_1.MAX_COMMENT_LENGTH) {
|
||||||
|
core.debug('The comment was too big for the GitHub API. Falling back on a minimum comment');
|
||||||
|
rendered = minSummary;
|
||||||
|
}
|
||||||
|
// update the PR comment if needed with the right-sized summary
|
||||||
|
yield (0, comment_pr_1.commentPr)(rendered, config);
|
||||||
}
|
}
|
||||||
catch (error) {
|
catch (error) {
|
||||||
if (error instanceof request_error_1.RequestError && error.status === 404) {
|
if (error instanceof request_error_1.RequestError && error.status === 404) {
|
||||||
@@ -1313,10 +1321,15 @@ const icons = {
|
|||||||
cross: '❌',
|
cross: '❌',
|
||||||
warning: '⚠️'
|
warning: '⚠️'
|
||||||
};
|
};
|
||||||
|
// generates the DR report summmary and caches it to the Action's core.summary.
|
||||||
|
// returns the DR summary string, ready to be posted as a PR comment if the
|
||||||
|
// final DR report is too large
|
||||||
function addSummaryToSummary(vulnerableChanges, invalidLicenseChanges, deniedChanges, scorecard, config) {
|
function addSummaryToSummary(vulnerableChanges, invalidLicenseChanges, deniedChanges, scorecard, config) {
|
||||||
|
const out = [];
|
||||||
const scorecardWarnings = countScorecardWarnings(scorecard, config);
|
const scorecardWarnings = countScorecardWarnings(scorecard, config);
|
||||||
const licenseIssues = countLicenseIssues(invalidLicenseChanges);
|
const licenseIssues = countLicenseIssues(invalidLicenseChanges);
|
||||||
core.summary.addHeading('Dependency Review', 1);
|
core.summary.addHeading('Dependency Review', 1);
|
||||||
|
out.push('# Dependency Review');
|
||||||
if (vulnerableChanges.length === 0 &&
|
if (vulnerableChanges.length === 0 &&
|
||||||
licenseIssues === 0 &&
|
licenseIssues === 0 &&
|
||||||
deniedChanges.length === 0 &&
|
deniedChanges.length === 0 &&
|
||||||
@@ -1326,17 +1339,21 @@ function addSummaryToSummary(vulnerableChanges, invalidLicenseChanges, deniedCha
|
|||||||
config.license_check ? 'license issues' : '',
|
config.license_check ? 'license issues' : '',
|
||||||
config.show_openssf_scorecard ? 'OpenSSF Scorecard issues' : ''
|
config.show_openssf_scorecard ? 'OpenSSF Scorecard issues' : ''
|
||||||
];
|
];
|
||||||
|
let msg = '';
|
||||||
if (issueTypes.filter(Boolean).length === 0) {
|
if (issueTypes.filter(Boolean).length === 0) {
|
||||||
core.summary.addRaw(`${icons.check} No issues found.`);
|
msg = `${icons.check} No issues found.`;
|
||||||
}
|
}
|
||||||
else {
|
else {
|
||||||
core.summary.addRaw(`${icons.check} No ${issueTypes.filter(Boolean).join(' or ')} found.`);
|
msg = `${icons.check} No ${issueTypes.filter(Boolean).join(' or ')} found.`;
|
||||||
}
|
}
|
||||||
return;
|
core.summary.addRaw(msg);
|
||||||
|
out.push(msg);
|
||||||
|
return out.join('\n');
|
||||||
}
|
}
|
||||||
core.summary
|
const foundIssuesHeader = 'The following issues were found:';
|
||||||
.addRaw('The following issues were found:')
|
core.summary.addRaw(foundIssuesHeader);
|
||||||
.addList([
|
out.push(foundIssuesHeader);
|
||||||
|
const summaryList = [
|
||||||
...(config.vulnerability_check
|
...(config.vulnerability_check
|
||||||
? [
|
? [
|
||||||
`${checkOrFailIcon(vulnerableChanges.length)} ${vulnerableChanges.length} vulnerable package(s)`
|
`${checkOrFailIcon(vulnerableChanges.length)} ${vulnerableChanges.length} vulnerable package(s)`
|
||||||
@@ -1351,7 +1368,7 @@ function addSummaryToSummary(vulnerableChanges, invalidLicenseChanges, deniedCha
|
|||||||
: []),
|
: []),
|
||||||
...(deniedChanges.length > 0
|
...(deniedChanges.length > 0
|
||||||
? [
|
? [
|
||||||
`${checkOrFailIcon(deniedChanges.length)} ${deniedChanges.length} package(s) denied.`
|
`${checkOrWarnIcon(deniedChanges.length)} ${deniedChanges.length} package(s) denied.`
|
||||||
]
|
]
|
||||||
: []),
|
: []),
|
||||||
...(config.show_openssf_scorecard && scorecardWarnings > 0
|
...(config.show_openssf_scorecard && scorecardWarnings > 0
|
||||||
@@ -1359,8 +1376,14 @@ function addSummaryToSummary(vulnerableChanges, invalidLicenseChanges, deniedCha
|
|||||||
`${checkOrWarnIcon(scorecardWarnings)} ${scorecardWarnings ? scorecardWarnings : 'No'} packages with OpenSSF Scorecard issues.`
|
`${checkOrWarnIcon(scorecardWarnings)} ${scorecardWarnings ? scorecardWarnings : 'No'} packages with OpenSSF Scorecard issues.`
|
||||||
]
|
]
|
||||||
: [])
|
: [])
|
||||||
])
|
];
|
||||||
.addRaw('See the Details below.');
|
core.summary.addList(summaryList);
|
||||||
|
for (const line of summaryList) {
|
||||||
|
out.push(`* ${line}`);
|
||||||
|
}
|
||||||
|
core.summary.addRaw('See the Details below.');
|
||||||
|
out.push(`\n[View full job summary](${process.env.GITHUB_SERVER_URL}/${process.env.GITHUB_REPOSITORY}/actions/runs/${process.env.GITHUB_RUN_ID})`);
|
||||||
|
return out.join('\n');
|
||||||
}
|
}
|
||||||
exports.addSummaryToSummary = addSummaryToSummary;
|
exports.addSummaryToSummary = addSummaryToSummary;
|
||||||
function countScorecardWarnings(scorecard, config) {
|
function countScorecardWarnings(scorecard, config) {
|
||||||
|
|||||||
+1
-1
File diff suppressed because one or more lines are too long
+3
-5
@@ -5,6 +5,8 @@ import * as retry from '@octokit/plugin-retry'
|
|||||||
import {RequestError} from '@octokit/request-error'
|
import {RequestError} from '@octokit/request-error'
|
||||||
import {ConfigurationOptions} from './schemas'
|
import {ConfigurationOptions} from './schemas'
|
||||||
|
|
||||||
|
export const MAX_COMMENT_LENGTH = 65536
|
||||||
|
|
||||||
const retryingOctokit = githubUtils.GitHub.plugin(retry.retry)
|
const retryingOctokit = githubUtils.GitHub.plugin(retry.retry)
|
||||||
const octo = new retryingOctokit(
|
const octo = new retryingOctokit(
|
||||||
githubUtils.getOctokitOptions(core.getInput('repo-token', {required: true}))
|
githubUtils.getOctokitOptions(core.getInput('repo-token', {required: true}))
|
||||||
@@ -14,13 +16,9 @@ const octo = new retryingOctokit(
|
|||||||
const COMMENT_MARKER = '<!-- dependency-review-pr-comment-marker -->'
|
const COMMENT_MARKER = '<!-- dependency-review-pr-comment-marker -->'
|
||||||
|
|
||||||
export async function commentPr(
|
export async function commentPr(
|
||||||
summary: typeof core.summary,
|
commentContent: string,
|
||||||
config: ConfigurationOptions
|
config: ConfigurationOptions
|
||||||
): Promise<void> {
|
): Promise<void> {
|
||||||
const commentContent = summary.stringify()
|
|
||||||
|
|
||||||
core.setOutput('comment-content', commentContent)
|
|
||||||
|
|
||||||
if (
|
if (
|
||||||
!(
|
!(
|
||||||
config.comment_summary_in_pr === 'always' ||
|
config.comment_summary_in_pr === 'always' ||
|
||||||
|
|||||||
+17
-3
@@ -22,7 +22,7 @@ import * as summary from './summary'
|
|||||||
import {getRefs} from './git-refs'
|
import {getRefs} from './git-refs'
|
||||||
|
|
||||||
import {groupDependenciesByManifest} from './utils'
|
import {groupDependenciesByManifest} from './utils'
|
||||||
import {commentPr} from './comment-pr'
|
import {commentPr, MAX_COMMENT_LENGTH} from './comment-pr'
|
||||||
import {getDeniedChanges} from './deny'
|
import {getDeniedChanges} from './deny'
|
||||||
|
|
||||||
async function delay(ms: number): Promise<void> {
|
async function delay(ms: number): Promise<void> {
|
||||||
@@ -127,7 +127,7 @@ async function run(): Promise<void> {
|
|||||||
|
|
||||||
const scorecard = await getScorecardLevels(filteredChanges)
|
const scorecard = await getScorecardLevels(filteredChanges)
|
||||||
|
|
||||||
summary.addSummaryToSummary(
|
const minSummary = summary.addSummaryToSummary(
|
||||||
vulnerableChanges,
|
vulnerableChanges,
|
||||||
invalidLicenseChanges,
|
invalidLicenseChanges,
|
||||||
deniedChanges,
|
deniedChanges,
|
||||||
@@ -166,7 +166,21 @@ async function run(): Promise<void> {
|
|||||||
core.setOutput('dependency-changes', JSON.stringify(changes))
|
core.setOutput('dependency-changes', JSON.stringify(changes))
|
||||||
summary.addScannedDependencies(changes)
|
summary.addScannedDependencies(changes)
|
||||||
printScannedDependencies(changes)
|
printScannedDependencies(changes)
|
||||||
await commentPr(core.summary, config)
|
|
||||||
|
// include full summary in output; Actions will truncate if oversized
|
||||||
|
let rendered = core.summary.stringify()
|
||||||
|
core.setOutput('comment-content', rendered)
|
||||||
|
|
||||||
|
// if the summary is oversized, replace with minimal version
|
||||||
|
if (rendered.length >= MAX_COMMENT_LENGTH) {
|
||||||
|
core.debug(
|
||||||
|
'The comment was too big for the GitHub API. Falling back on a minimum comment'
|
||||||
|
)
|
||||||
|
rendered = minSummary
|
||||||
|
}
|
||||||
|
|
||||||
|
// update the PR comment if needed with the right-sized summary
|
||||||
|
await commentPr(rendered, config)
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
if (error instanceof RequestError && error.status === 404) {
|
if (error instanceof RequestError && error.status === 404) {
|
||||||
core.setFailed(
|
core.setFailed(
|
||||||
|
|||||||
+64
-43
@@ -10,17 +10,23 @@ const icons = {
|
|||||||
warning: '⚠️'
|
warning: '⚠️'
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// generates the DR report summmary and caches it to the Action's core.summary.
|
||||||
|
// returns the DR summary string, ready to be posted as a PR comment if the
|
||||||
|
// final DR report is too large
|
||||||
export function addSummaryToSummary(
|
export function addSummaryToSummary(
|
||||||
vulnerableChanges: Changes,
|
vulnerableChanges: Changes,
|
||||||
invalidLicenseChanges: InvalidLicenseChanges,
|
invalidLicenseChanges: InvalidLicenseChanges,
|
||||||
deniedChanges: Changes,
|
deniedChanges: Changes,
|
||||||
scorecard: Scorecard,
|
scorecard: Scorecard,
|
||||||
config: ConfigurationOptions
|
config: ConfigurationOptions
|
||||||
): void {
|
): string {
|
||||||
|
const out: string[] = []
|
||||||
|
|
||||||
const scorecardWarnings = countScorecardWarnings(scorecard, config)
|
const scorecardWarnings = countScorecardWarnings(scorecard, config)
|
||||||
const licenseIssues = countLicenseIssues(invalidLicenseChanges)
|
const licenseIssues = countLicenseIssues(invalidLicenseChanges)
|
||||||
|
|
||||||
core.summary.addHeading('Dependency Review', 1)
|
core.summary.addHeading('Dependency Review', 1)
|
||||||
|
out.push('# Dependency Review')
|
||||||
|
|
||||||
if (
|
if (
|
||||||
vulnerableChanges.length === 0 &&
|
vulnerableChanges.length === 0 &&
|
||||||
@@ -33,54 +39,69 @@ export function addSummaryToSummary(
|
|||||||
config.license_check ? 'license issues' : '',
|
config.license_check ? 'license issues' : '',
|
||||||
config.show_openssf_scorecard ? 'OpenSSF Scorecard issues' : ''
|
config.show_openssf_scorecard ? 'OpenSSF Scorecard issues' : ''
|
||||||
]
|
]
|
||||||
|
|
||||||
|
let msg = ''
|
||||||
if (issueTypes.filter(Boolean).length === 0) {
|
if (issueTypes.filter(Boolean).length === 0) {
|
||||||
core.summary.addRaw(`${icons.check} No issues found.`)
|
msg = `${icons.check} No issues found.`
|
||||||
} else {
|
} else {
|
||||||
core.summary.addRaw(
|
msg = `${icons.check} No ${issueTypes.filter(Boolean).join(' or ')} found.`
|
||||||
`${icons.check} No ${issueTypes.filter(Boolean).join(' or ')} found.`
|
|
||||||
)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return
|
core.summary.addRaw(msg)
|
||||||
|
out.push(msg)
|
||||||
|
return out.join('\n')
|
||||||
}
|
}
|
||||||
|
|
||||||
core.summary
|
const foundIssuesHeader = 'The following issues were found:'
|
||||||
.addRaw('The following issues were found:')
|
core.summary.addRaw(foundIssuesHeader)
|
||||||
.addList([
|
out.push(foundIssuesHeader)
|
||||||
...(config.vulnerability_check
|
|
||||||
? [
|
const summaryList: string[] = [
|
||||||
`${checkOrFailIcon(vulnerableChanges.length)} ${
|
...(config.vulnerability_check
|
||||||
vulnerableChanges.length
|
? [
|
||||||
} vulnerable package(s)`
|
`${checkOrFailIcon(vulnerableChanges.length)} ${
|
||||||
]
|
vulnerableChanges.length
|
||||||
: []),
|
} vulnerable package(s)`
|
||||||
...(config.license_check
|
]
|
||||||
? [
|
: []),
|
||||||
`${checkOrFailIcon(invalidLicenseChanges.forbidden.length)} ${
|
...(config.license_check
|
||||||
invalidLicenseChanges.forbidden.length
|
? [
|
||||||
} package(s) with incompatible licenses`,
|
`${checkOrFailIcon(invalidLicenseChanges.forbidden.length)} ${
|
||||||
`${checkOrFailIcon(invalidLicenseChanges.unresolved.length)} ${
|
invalidLicenseChanges.forbidden.length
|
||||||
invalidLicenseChanges.unresolved.length
|
} package(s) with incompatible licenses`,
|
||||||
} package(s) with invalid SPDX license definitions`,
|
`${checkOrFailIcon(invalidLicenseChanges.unresolved.length)} ${
|
||||||
`${checkOrWarnIcon(invalidLicenseChanges.unlicensed.length)} ${
|
invalidLicenseChanges.unresolved.length
|
||||||
invalidLicenseChanges.unlicensed.length
|
} package(s) with invalid SPDX license definitions`,
|
||||||
} package(s) with unknown licenses.`
|
`${checkOrWarnIcon(invalidLicenseChanges.unlicensed.length)} ${
|
||||||
]
|
invalidLicenseChanges.unlicensed.length
|
||||||
: []),
|
} package(s) with unknown licenses.`
|
||||||
...(deniedChanges.length > 0
|
]
|
||||||
? [
|
: []),
|
||||||
`${checkOrFailIcon(deniedChanges.length)} ${
|
...(deniedChanges.length > 0
|
||||||
deniedChanges.length
|
? [
|
||||||
} package(s) denied.`
|
`${checkOrWarnIcon(deniedChanges.length)} ${
|
||||||
]
|
deniedChanges.length
|
||||||
: []),
|
} package(s) denied.`
|
||||||
...(config.show_openssf_scorecard && scorecardWarnings > 0
|
]
|
||||||
? [
|
: []),
|
||||||
`${checkOrWarnIcon(scorecardWarnings)} ${scorecardWarnings ? scorecardWarnings : 'No'} packages with OpenSSF Scorecard issues.`
|
...(config.show_openssf_scorecard && scorecardWarnings > 0
|
||||||
]
|
? [
|
||||||
: [])
|
`${checkOrWarnIcon(scorecardWarnings)} ${scorecardWarnings ? scorecardWarnings : 'No'} packages with OpenSSF Scorecard issues.`
|
||||||
])
|
]
|
||||||
.addRaw('See the Details below.')
|
: [])
|
||||||
|
]
|
||||||
|
|
||||||
|
core.summary.addList(summaryList)
|
||||||
|
for (const line of summaryList) {
|
||||||
|
out.push(`* ${line}`)
|
||||||
|
}
|
||||||
|
|
||||||
|
core.summary.addRaw('See the Details below.')
|
||||||
|
out.push(
|
||||||
|
`\n[View full job summary](${process.env.GITHUB_SERVER_URL}/${process.env.GITHUB_REPOSITORY}/actions/runs/${process.env.GITHUB_RUN_ID})`
|
||||||
|
)
|
||||||
|
|
||||||
|
return out.join('\n')
|
||||||
}
|
}
|
||||||
|
|
||||||
function countScorecardWarnings(
|
function countScorecardWarnings(
|
||||||
|
|||||||
Reference in New Issue
Block a user