Compare commits
110
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c77673abe0 | ||
|
|
efd78809f9 | ||
|
|
e91b527bcb | ||
|
|
f508195cbc | ||
|
|
ef8bfcec89 | ||
|
|
31cb4e05f7 | ||
|
|
7920884bc8 | ||
|
|
aae0422a7f | ||
|
|
46d2ba8805 | ||
|
|
7c07c1da42 | ||
|
|
6e3a1cfe9e | ||
|
|
3190101729 | ||
|
|
3576f26c76 | ||
|
|
97fef8f979 | ||
|
|
60e20b95c9 | ||
|
|
e6aba92fb0 | ||
|
|
4b2cf01947 | ||
|
|
33b11b63b3 | ||
|
|
90014ebf46 | ||
|
|
c0fcb40fb5 | ||
|
|
6213daabf8 | ||
|
|
6c62d64ea3 | ||
|
|
6154af02da | ||
|
|
df40ce1edc | ||
|
|
a033837e12 | ||
|
|
d79457303f | ||
|
|
b2f83f35c7 | ||
|
|
389b38eb1a | ||
|
|
e3926a59f5 | ||
|
|
54656aadd8 | ||
|
|
f02b9fb886 | ||
|
|
6587f9feee | ||
|
|
cab2d5f36f | ||
|
|
ef411f3a4c | ||
|
|
589f46e5a2 | ||
|
|
a482eabd84 | ||
|
|
c63a70f2bb | ||
|
|
ea081cab93 | ||
|
|
78231376d4 | ||
|
|
ea38797bf9 | ||
|
|
383b34b013 | ||
|
|
234f1c3e6b | ||
|
|
1aca439347 | ||
|
|
f5231a7139 | ||
|
|
872c5e3689 | ||
|
|
86e4c38e88 | ||
|
|
70a13ae7e3 | ||
|
|
0ff3da6f81 | ||
|
|
6d88398316 | ||
|
|
29022577bf | ||
|
|
a4bf690c47 | ||
|
|
3f67248108 | ||
|
|
e82e9497cb | ||
|
|
945cb4d00a | ||
|
|
459b39211c | ||
|
|
c109d3f46d | ||
|
|
706aa54d76 | ||
|
|
12cfe866a8 | ||
|
|
0caa632377 | ||
|
|
df02ee7d42 | ||
|
|
38e9237630 | ||
|
|
03c7962be5 | ||
|
|
cff3674e25 | ||
|
|
a184554be2 | ||
|
|
660812709b | ||
|
|
d8b4cd80d5 | ||
|
|
8e5d487bb8 | ||
|
|
3e6e055a26 | ||
|
|
1f8d096c90 | ||
|
|
0247f51a25 | ||
|
|
f599dc7887 | ||
|
|
6919a4885f | ||
|
|
8f97494d2e | ||
|
|
08ec176670 | ||
|
|
40a9da4614 | ||
|
|
9ad1f84ed2 | ||
|
|
464e6ac735 | ||
|
|
141e2dae22 | ||
|
|
37bb7a46dd | ||
|
|
5abb42a215 | ||
|
|
5aafbe4a32 | ||
|
|
d623612924 | ||
|
|
08fe899167 | ||
|
|
067e030d27 | ||
|
|
6b47d2662b | ||
|
|
290634fe98 | ||
|
|
352f50a80e | ||
|
|
11310527b4 | ||
|
|
ea0f46928b | ||
|
|
369356e2e7 | ||
|
|
13fe21bc0a | ||
|
|
136c0838bf | ||
|
|
8ed85b3757 | ||
|
|
a952d7b1b7 | ||
|
|
b8e622f102 | ||
|
|
ac059c649c | ||
|
|
93652d7af0 | ||
|
|
ba127cac5e | ||
|
|
1dd7392739 | ||
|
|
8f801ec4bb | ||
|
|
2d265aa7cc | ||
|
|
c57c602135 | ||
|
|
c2097b2a9b | ||
|
|
0a055a6a13 | ||
|
|
3417e62ba2 | ||
|
|
49fecaf158 | ||
|
|
173a4b8d96 | ||
|
|
db1829cd87 | ||
|
|
d87317e782 | ||
|
|
30d5821115 |
@@ -3,12 +3,12 @@ updates:
|
|||||||
- package-ecosystem: github-actions
|
- package-ecosystem: github-actions
|
||||||
directory: /
|
directory: /
|
||||||
schedule:
|
schedule:
|
||||||
interval: daily
|
interval: weekly
|
||||||
|
|
||||||
- package-ecosystem: npm
|
- package-ecosystem: npm
|
||||||
directory: /
|
directory: /
|
||||||
schedule:
|
schedule:
|
||||||
interval: daily
|
interval: weekly
|
||||||
ignore:
|
ignore:
|
||||||
- dependency-name: '@types/node'
|
- dependency-name: '@types/node'
|
||||||
update-types: ['version-update:semver-major']
|
update-types: ['version-update:semver-major']
|
||||||
|
|||||||
@@ -27,6 +27,7 @@ jobs:
|
|||||||
uses: actions/setup-node@v3
|
uses: actions/setup-node@v3
|
||||||
with:
|
with:
|
||||||
node-version: 18.x
|
node-version: 18.x
|
||||||
|
cache: npm
|
||||||
|
|
||||||
- name: Install dependencies
|
- name: Install dependencies
|
||||||
run: npm ci
|
run: npm ci
|
||||||
|
|||||||
+2
-2
@@ -112,8 +112,8 @@ minor/patch updates.
|
|||||||
To do this just checkout `main`, force-create a new annotated tag, and push it:
|
To do this just checkout `main`, force-create a new annotated tag, and push it:
|
||||||
|
|
||||||
```
|
```
|
||||||
git tag -fa v2 -m "Updating v2 to 2.3.4"
|
git tag -fa v3 -m "Updating v3 to 3.0.1"
|
||||||
git push origin v2 --force
|
git push origin v3 --force
|
||||||
```
|
```
|
||||||
|
|
||||||
## Resources
|
## Resources
|
||||||
|
|||||||
@@ -115,7 +115,7 @@ You can use an external configuration file to specify the settings for this acti
|
|||||||
| Option | Usage | Possible values |
|
| Option | Usage | Possible values |
|
||||||
|-----------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------|
|
|-----------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------|
|
||||||
| `config-file` | A path to a file in the current repository or an external repository. Use this syntax for external files: `OWNER/REPOSITORY/FILENAME@BRANCH` | **Local file**: `./.github/dependency-review-config.yml` <br> **External repo**: `github/octorepo/dependency-review-config.yml@main` |
|
| `config-file` | A path to a file in the current repository or an external repository. Use this syntax for external files: `OWNER/REPOSITORY/FILENAME@BRANCH` | **Local file**: `./.github/dependency-review-config.yml` <br> **External repo**: `github/octorepo/dependency-review-config.yml@main` |
|
||||||
| `external-repo-token` | Specifies a token for fetching the configuration file if the file resides in a private external repository. Create a token in [developer settings](https://github.com/settings/tokens). | Any token with `read` permissions to the repository hosting the config file. |
|
| `external-repo-token` | Specifies a token for fetching the configuration file. It is required if the file resides in a private external repository and for all GitHub Enterprise Server repositories. Create a token in [developer settings](https://github.com/settings/tokens). | Any token with `read` permissions to the repository hosting the config file. |
|
||||||
|
|
||||||
#### Example
|
#### Example
|
||||||
|
|
||||||
|
|||||||
@@ -111,9 +111,9 @@ test('it reads an external config file', async () => {
|
|||||||
expect(config.allow_licenses).toEqual(['BSD', 'GPL 2'])
|
expect(config.allow_licenses).toEqual(['BSD', 'GPL 2'])
|
||||||
})
|
})
|
||||||
|
|
||||||
test('raises an error when the the config file was not found', async () => {
|
test('raises an error when the config file was not found', async () => {
|
||||||
setInput('config-file', 'fixtures/i-dont-exist')
|
setInput('config-file', 'fixtures/i-dont-exist')
|
||||||
await expect(readConfig()).rejects.toThrow(/Unable to fetch config file/)
|
await expect(readConfig()).rejects.toThrow(/Unable to fetch/)
|
||||||
})
|
})
|
||||||
|
|
||||||
test('it parses options from both sources', async () => {
|
test('it parses options from both sources', async () => {
|
||||||
@@ -232,6 +232,16 @@ test('it is not possible to disable both checks', async () => {
|
|||||||
)
|
)
|
||||||
})
|
})
|
||||||
|
|
||||||
|
test('it supports comma-separated lists', async () => {
|
||||||
|
setInput(
|
||||||
|
'config-file',
|
||||||
|
'./__tests__/fixtures/inline-license-config-sample.yml'
|
||||||
|
)
|
||||||
|
let config = await readConfig()
|
||||||
|
|
||||||
|
expect(config.allow_licenses).toEqual(['MIT', 'GPL-2.0-only'])
|
||||||
|
})
|
||||||
|
|
||||||
describe('licenses that are not valid SPDX licenses', () => {
|
describe('licenses that are not valid SPDX licenses', () => {
|
||||||
beforeAll(() => {
|
beforeAll(() => {
|
||||||
jest.spyOn(Utils, 'isSPDXValid').mockReturnValue(false)
|
jest.spyOn(Utils, 'isSPDXValid').mockReturnValue(false)
|
||||||
@@ -240,14 +250,14 @@ describe('licenses that are not valid SPDX licenses', () => {
|
|||||||
test('it raises an error for invalid licenses in allow-licenses', async () => {
|
test('it raises an error for invalid licenses in allow-licenses', async () => {
|
||||||
setInput('allow-licenses', ' BSD, GPL 2')
|
setInput('allow-licenses', ' BSD, GPL 2')
|
||||||
await expect(readConfig()).rejects.toThrow(
|
await expect(readConfig()).rejects.toThrow(
|
||||||
'Invalid license(s) in allow-licenses: BSD, GPL 2'
|
'Invalid license(s) in allow-licenses: BSD,GPL 2'
|
||||||
)
|
)
|
||||||
})
|
})
|
||||||
|
|
||||||
test('it raises an error for invalid licenses in deny-licenses', async () => {
|
test('it raises an error for invalid licenses in deny-licenses', async () => {
|
||||||
setInput('deny-licenses', ' BSD, GPL 2')
|
setInput('deny-licenses', ' BSD, GPL 2')
|
||||||
await expect(readConfig()).rejects.toThrow(
|
await expect(readConfig()).rejects.toThrow(
|
||||||
'Invalid license(s) in deny-licenses: BSD, GPL 2'
|
'Invalid license(s) in deny-licenses: BSD,GPL 2'
|
||||||
)
|
)
|
||||||
})
|
})
|
||||||
})
|
})
|
||||||
|
|||||||
@@ -0,0 +1,29 @@
|
|||||||
|
import {RequestError} from '@octokit/request-error'
|
||||||
|
import * as dependencyGraph from '../src/dependency-graph'
|
||||||
|
import * as core from '@actions/core'
|
||||||
|
|
||||||
|
// mock call to core.getInput('repo-token'.. to avoid environment setup - Input required and not supplied: repo-token
|
||||||
|
jest.mock('@actions/core', () => ({
|
||||||
|
getInput: (input: string) => {
|
||||||
|
if (input === 'repo-token') {
|
||||||
|
return 'gh_testtoken'
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}))
|
||||||
|
|
||||||
|
test('it properly catches RequestError type', async () => {
|
||||||
|
const token = core.getInput('repo-token', {required: true})
|
||||||
|
expect(token).toBe('gh_testtoken')
|
||||||
|
|
||||||
|
//Integration test to make an API request using current dependencies and ensure response can parse into RequestError
|
||||||
|
try {
|
||||||
|
await dependencyGraph.compare({
|
||||||
|
owner: 'actions',
|
||||||
|
repo: 'dependency-review-action',
|
||||||
|
baseRef: 'refs/heads/master',
|
||||||
|
headRef: 'refs/heads/master'
|
||||||
|
})
|
||||||
|
} catch (error) {
|
||||||
|
expect(error).toBeInstanceOf(RequestError)
|
||||||
|
}
|
||||||
|
})
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
allow-licenses: MIT, GPL-2.0-only
|
||||||
+1
-1
@@ -30,7 +30,7 @@ inputs:
|
|||||||
description: Comma-separated list of forbidden licenses (e.g. "MIT, GPL 3.0, BSD 2 Clause")
|
description: Comma-separated list of forbidden licenses (e.g. "MIT, GPL 3.0, BSD 2 Clause")
|
||||||
required: false
|
required: false
|
||||||
allow-ghsas:
|
allow-ghsas:
|
||||||
description: Comma-separated list of allowed Github Advisory IDs (e.g. "GHSA-abcd-1234-5679, GHSA-efgh-1234-5679")
|
description: Comma-separated list of allowed GitHub Advisory IDs (e.g. "GHSA-abcd-1234-5679, GHSA-efgh-1234-5679")
|
||||||
required: false
|
required: false
|
||||||
external-repo-token:
|
external-repo-token:
|
||||||
description: A token for fetching external configuration file if it lives in another repository. It is required if the repository is private
|
description: A token for fetching external configuration file if it lives in another repository. It is required if the repository is private
|
||||||
|
|||||||
+20710
-3710
File diff suppressed because one or more lines are too long
+1
-1
File diff suppressed because one or more lines are too long
+3
-234
@@ -1175,240 +1175,9 @@ FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TOR
|
|||||||
ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
||||||
|
|
||||||
|
|
||||||
lodash.includes
|
lodash
|
||||||
MIT
|
MIT
|
||||||
Copyright jQuery Foundation and other contributors <https://jquery.org/>
|
Copyright OpenJS Foundation and other contributors <https://openjsf.org/>
|
||||||
|
|
||||||
Based on Underscore.js, copyright Jeremy Ashkenas,
|
|
||||||
DocumentCloud and Investigative Reporters & Editors <http://underscorejs.org/>
|
|
||||||
|
|
||||||
This software consists of voluntary contributions made by many
|
|
||||||
individuals. For exact contribution history, see the revision history
|
|
||||||
available at https://github.com/lodash/lodash
|
|
||||||
|
|
||||||
The following license applies to all parts of this software except as
|
|
||||||
documented below:
|
|
||||||
|
|
||||||
====
|
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining
|
|
||||||
a copy of this software and associated documentation files (the
|
|
||||||
"Software"), to deal in the Software without restriction, including
|
|
||||||
without limitation the rights to use, copy, modify, merge, publish,
|
|
||||||
distribute, sublicense, and/or sell copies of the Software, and to
|
|
||||||
permit persons to whom the Software is furnished to do so, subject to
|
|
||||||
the following conditions:
|
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be
|
|
||||||
included in all copies or substantial portions of the Software.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
|
||||||
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
|
|
||||||
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
|
|
||||||
NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
|
|
||||||
LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
|
|
||||||
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
|
|
||||||
WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
|
||||||
|
|
||||||
====
|
|
||||||
|
|
||||||
Copyright and related rights for sample code are waived via CC0. Sample
|
|
||||||
code is defined as all source code displayed within the prose of the
|
|
||||||
documentation.
|
|
||||||
|
|
||||||
CC0: http://creativecommons.org/publicdomain/zero/1.0/
|
|
||||||
|
|
||||||
====
|
|
||||||
|
|
||||||
Files located in the node_modules and vendor directories are externally
|
|
||||||
maintained libraries used by this software which have their own
|
|
||||||
licenses; we recommend you read them, as their terms may differ from the
|
|
||||||
terms above.
|
|
||||||
|
|
||||||
|
|
||||||
lodash.isboolean
|
|
||||||
MIT
|
|
||||||
Copyright 2012-2016 The Dojo Foundation <http://dojofoundation.org/>
|
|
||||||
Based on Underscore.js, copyright 2009-2016 Jeremy Ashkenas,
|
|
||||||
DocumentCloud and Investigative Reporters & Editors <http://underscorejs.org/>
|
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining
|
|
||||||
a copy of this software and associated documentation files (the
|
|
||||||
"Software"), to deal in the Software without restriction, including
|
|
||||||
without limitation the rights to use, copy, modify, merge, publish,
|
|
||||||
distribute, sublicense, and/or sell copies of the Software, and to
|
|
||||||
permit persons to whom the Software is furnished to do so, subject to
|
|
||||||
the following conditions:
|
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be
|
|
||||||
included in all copies or substantial portions of the Software.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
|
||||||
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
|
|
||||||
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
|
|
||||||
NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
|
|
||||||
LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
|
|
||||||
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
|
|
||||||
WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
|
||||||
|
|
||||||
|
|
||||||
lodash.isinteger
|
|
||||||
MIT
|
|
||||||
Copyright jQuery Foundation and other contributors <https://jquery.org/>
|
|
||||||
|
|
||||||
Based on Underscore.js, copyright Jeremy Ashkenas,
|
|
||||||
DocumentCloud and Investigative Reporters & Editors <http://underscorejs.org/>
|
|
||||||
|
|
||||||
This software consists of voluntary contributions made by many
|
|
||||||
individuals. For exact contribution history, see the revision history
|
|
||||||
available at https://github.com/lodash/lodash
|
|
||||||
|
|
||||||
The following license applies to all parts of this software except as
|
|
||||||
documented below:
|
|
||||||
|
|
||||||
====
|
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining
|
|
||||||
a copy of this software and associated documentation files (the
|
|
||||||
"Software"), to deal in the Software without restriction, including
|
|
||||||
without limitation the rights to use, copy, modify, merge, publish,
|
|
||||||
distribute, sublicense, and/or sell copies of the Software, and to
|
|
||||||
permit persons to whom the Software is furnished to do so, subject to
|
|
||||||
the following conditions:
|
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be
|
|
||||||
included in all copies or substantial portions of the Software.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
|
||||||
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
|
|
||||||
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
|
|
||||||
NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
|
|
||||||
LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
|
|
||||||
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
|
|
||||||
WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
|
||||||
|
|
||||||
====
|
|
||||||
|
|
||||||
Copyright and related rights for sample code are waived via CC0. Sample
|
|
||||||
code is defined as all source code displayed within the prose of the
|
|
||||||
documentation.
|
|
||||||
|
|
||||||
CC0: http://creativecommons.org/publicdomain/zero/1.0/
|
|
||||||
|
|
||||||
====
|
|
||||||
|
|
||||||
Files located in the node_modules and vendor directories are externally
|
|
||||||
maintained libraries used by this software which have their own
|
|
||||||
licenses; we recommend you read them, as their terms may differ from the
|
|
||||||
terms above.
|
|
||||||
|
|
||||||
|
|
||||||
lodash.isnumber
|
|
||||||
MIT
|
|
||||||
Copyright 2012-2016 The Dojo Foundation <http://dojofoundation.org/>
|
|
||||||
Based on Underscore.js, copyright 2009-2016 Jeremy Ashkenas,
|
|
||||||
DocumentCloud and Investigative Reporters & Editors <http://underscorejs.org/>
|
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining
|
|
||||||
a copy of this software and associated documentation files (the
|
|
||||||
"Software"), to deal in the Software without restriction, including
|
|
||||||
without limitation the rights to use, copy, modify, merge, publish,
|
|
||||||
distribute, sublicense, and/or sell copies of the Software, and to
|
|
||||||
permit persons to whom the Software is furnished to do so, subject to
|
|
||||||
the following conditions:
|
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be
|
|
||||||
included in all copies or substantial portions of the Software.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
|
||||||
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
|
|
||||||
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
|
|
||||||
NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
|
|
||||||
LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
|
|
||||||
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
|
|
||||||
WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
|
||||||
|
|
||||||
|
|
||||||
lodash.isplainobject
|
|
||||||
MIT
|
|
||||||
Copyright jQuery Foundation and other contributors <https://jquery.org/>
|
|
||||||
|
|
||||||
Based on Underscore.js, copyright Jeremy Ashkenas,
|
|
||||||
DocumentCloud and Investigative Reporters & Editors <http://underscorejs.org/>
|
|
||||||
|
|
||||||
This software consists of voluntary contributions made by many
|
|
||||||
individuals. For exact contribution history, see the revision history
|
|
||||||
available at https://github.com/lodash/lodash
|
|
||||||
|
|
||||||
The following license applies to all parts of this software except as
|
|
||||||
documented below:
|
|
||||||
|
|
||||||
====
|
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining
|
|
||||||
a copy of this software and associated documentation files (the
|
|
||||||
"Software"), to deal in the Software without restriction, including
|
|
||||||
without limitation the rights to use, copy, modify, merge, publish,
|
|
||||||
distribute, sublicense, and/or sell copies of the Software, and to
|
|
||||||
permit persons to whom the Software is furnished to do so, subject to
|
|
||||||
the following conditions:
|
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be
|
|
||||||
included in all copies or substantial portions of the Software.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
|
||||||
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
|
|
||||||
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
|
|
||||||
NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
|
|
||||||
LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
|
|
||||||
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
|
|
||||||
WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
|
||||||
|
|
||||||
====
|
|
||||||
|
|
||||||
Copyright and related rights for sample code are waived via CC0. Sample
|
|
||||||
code is defined as all source code displayed within the prose of the
|
|
||||||
documentation.
|
|
||||||
|
|
||||||
CC0: http://creativecommons.org/publicdomain/zero/1.0/
|
|
||||||
|
|
||||||
====
|
|
||||||
|
|
||||||
Files located in the node_modules and vendor directories are externally
|
|
||||||
maintained libraries used by this software which have their own
|
|
||||||
licenses; we recommend you read them, as their terms may differ from the
|
|
||||||
terms above.
|
|
||||||
|
|
||||||
|
|
||||||
lodash.isstring
|
|
||||||
MIT
|
|
||||||
Copyright 2012-2016 The Dojo Foundation <http://dojofoundation.org/>
|
|
||||||
Based on Underscore.js, copyright 2009-2016 Jeremy Ashkenas,
|
|
||||||
DocumentCloud and Investigative Reporters & Editors <http://underscorejs.org/>
|
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining
|
|
||||||
a copy of this software and associated documentation files (the
|
|
||||||
"Software"), to deal in the Software without restriction, including
|
|
||||||
without limitation the rights to use, copy, modify, merge, publish,
|
|
||||||
distribute, sublicense, and/or sell copies of the Software, and to
|
|
||||||
permit persons to whom the Software is furnished to do so, subject to
|
|
||||||
the following conditions:
|
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be
|
|
||||||
included in all copies or substantial portions of the Software.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
|
||||||
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
|
|
||||||
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
|
|
||||||
NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
|
|
||||||
LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
|
|
||||||
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
|
|
||||||
WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
|
||||||
|
|
||||||
|
|
||||||
lodash.once
|
|
||||||
MIT
|
|
||||||
Copyright jQuery Foundation and other contributors <https://jquery.org/>
|
|
||||||
|
|
||||||
Based on Underscore.js, copyright Jeremy Ashkenas,
|
Based on Underscore.js, copyright Jeremy Ashkenas,
|
||||||
DocumentCloud and Investigative Reporters & Editors <http://underscorejs.org/>
|
DocumentCloud and Investigative Reporters & Editors <http://underscorejs.org/>
|
||||||
@@ -1531,7 +1300,7 @@ octokit
|
|||||||
MIT
|
MIT
|
||||||
The MIT License
|
The MIT License
|
||||||
|
|
||||||
Copyright (c) 2018 Octokit contributors
|
Copyright (c) 2023 Octokit contributors
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||||
of this software and associated documentation files (the "Software"), to deal
|
of this software and associated documentation files (the "Software"), to deal
|
||||||
|
|||||||
Generated
+592
-946
File diff suppressed because it is too large
Load Diff
+18
-16
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "dependency-review-action",
|
"name": "dependency-review-action",
|
||||||
"version": "2.5.1",
|
"version": "3.0.2",
|
||||||
"private": true,
|
"private": true,
|
||||||
"description": "A GitHub Action for Dependency Review",
|
"description": "A GitHub Action for Dependency Review",
|
||||||
"main": "lib/main.js",
|
"main": "lib/main.js",
|
||||||
@@ -28,33 +28,35 @@
|
|||||||
"@actions/core": "^1.10.0",
|
"@actions/core": "^1.10.0",
|
||||||
"@actions/github": "^5.1.1",
|
"@actions/github": "^5.1.1",
|
||||||
"@octokit/plugin-retry": "^4.0.3",
|
"@octokit/plugin-retry": "^4.0.3",
|
||||||
"@octokit/request-error": "^3.0.2",
|
"@octokit/request-error": "^2.1.0",
|
||||||
"ansi-styles": "^6.2.1",
|
"ansi-styles": "^6.2.1",
|
||||||
"got": "^12.5.2",
|
"got": "^12.5.3",
|
||||||
"nodemon": "^2.0.20",
|
"nodemon": "^2.0.20",
|
||||||
"octokit": "^2.0.10",
|
"octokit": "^2.0.11",
|
||||||
"spdx-expression-parse": "^3.0.1",
|
"spdx-expression-parse": "^3.0.1",
|
||||||
"spdx-satisfies": "^5.0.1",
|
"spdx-satisfies": "^5.0.1",
|
||||||
"yaml": "^2.1.3",
|
"yaml": "^2.2.1",
|
||||||
"zod": "^3.19.1"
|
"zod": "^3.20.2"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@types/jest": "^27.5.2",
|
"@types/jest": "^27.5.2",
|
||||||
"@types/node": "^16.18.3",
|
"@types/node": "^16.18.11",
|
||||||
"@typescript-eslint/eslint-plugin": "^5.42.1",
|
"@typescript-eslint/eslint-plugin": "^5.45.0",
|
||||||
"@typescript-eslint/parser": "^5.42.1",
|
"@typescript-eslint/parser": "^5.48.0",
|
||||||
"@types/spdx-expression-parse": "^3.0.2",
|
"@types/spdx-expression-parse": "^3.0.2",
|
||||||
"@types/spdx-satisfies": "^0.1.0",
|
"@types/spdx-satisfies": "^0.1.0",
|
||||||
"@vercel/ncc": "^0.34.0",
|
"@typescript-eslint/eslint-plugin": "^5.45.0",
|
||||||
"esbuild-register": "^3.4.1",
|
"@typescript-eslint/parser": "^5.47.1",
|
||||||
"eslint": "^8.27.0",
|
"@vercel/ncc": "^0.36.0",
|
||||||
"eslint-plugin-github": "^4.4.1",
|
"esbuild-register": "^3.4.2",
|
||||||
"eslint-plugin-jest": "^27.1.5",
|
"eslint": "^8.31.0",
|
||||||
|
"eslint-plugin-github": "^4.6.0",
|
||||||
|
"eslint-plugin-jest": "^27.2.1",
|
||||||
"jest": "^27.5.1",
|
"jest": "^27.5.1",
|
||||||
"js-yaml": "^4.1.0",
|
"js-yaml": "^4.1.0",
|
||||||
"nodemon": "^2.0.20",
|
"nodemon": "^2.0.20",
|
||||||
"prettier": "2.7.1",
|
"prettier": "2.8.2",
|
||||||
"ts-jest": "^27.1.4",
|
"ts-jest": "^27.1.4",
|
||||||
"typescript": "^4.8.4"
|
"typescript": "^4.9.4"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+27
-5
@@ -80,12 +80,11 @@ function validateLicenses(
|
|||||||
if (licenses === undefined) {
|
if (licenses === undefined) {
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
const invalid_licenses = licenses.filter(license => !isSPDXValid(license))
|
const invalid_licenses = licenses.filter(license => !isSPDXValid(license))
|
||||||
|
|
||||||
if (invalid_licenses.length > 0) {
|
if (invalid_licenses.length > 0) {
|
||||||
throw new Error(
|
throw new Error(`Invalid license(s) in ${key}: ${invalid_licenses}`)
|
||||||
`Invalid license(s) in ${key}: ${invalid_licenses.join(', ')}`
|
|
||||||
)
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -113,18 +112,41 @@ async function readConfigFile(
|
|||||||
}
|
}
|
||||||
return parseConfigFile(data)
|
return parseConfigFile(data)
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
core.debug(error as string)
|
throw new Error(
|
||||||
throw new Error('Unable to fetch config file')
|
`Unable to fetch or parse config file: ${(error as Error).message}`
|
||||||
|
)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
function parseConfigFile(configData: string): ConfigurationOptionsPartial {
|
function parseConfigFile(configData: string): ConfigurationOptionsPartial {
|
||||||
try {
|
try {
|
||||||
const data = YAML.parse(configData)
|
const data = YAML.parse(configData)
|
||||||
|
|
||||||
|
// These are the options that we support where the user can provide
|
||||||
|
// either a YAML list or a comma-separated string.
|
||||||
|
const listKeys = [
|
||||||
|
'allow-licenses',
|
||||||
|
'deny-licenses',
|
||||||
|
'fail-on-scopes',
|
||||||
|
'allow-ghsas'
|
||||||
|
]
|
||||||
|
|
||||||
for (const key of Object.keys(data)) {
|
for (const key of Object.keys(data)) {
|
||||||
|
// strings can contain list values (e.g. 'MIT, Apache-2.0'). In this
|
||||||
|
// case we need to parse that into a list (e.g. ['MIT', 'Apache-2.0']).
|
||||||
|
if (listKeys.includes(key)) {
|
||||||
|
const val = data[key]
|
||||||
|
|
||||||
|
if (typeof val === 'string') {
|
||||||
|
data[key] = val.split(',').map(x => x.trim())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// perform SPDX validation
|
||||||
if (key === 'allow-licenses' || key === 'deny-licenses') {
|
if (key === 'allow-licenses' || key === 'deny-licenses') {
|
||||||
validateLicenses(key, data[key])
|
validateLicenses(key, data[key])
|
||||||
}
|
}
|
||||||
|
|
||||||
// get rid of the ugly dashes from the actions conventions
|
// get rid of the ugly dashes from the actions conventions
|
||||||
if (key.includes('-')) {
|
if (key.includes('-')) {
|
||||||
data[key.replace(/-/g, '_')] = data[key]
|
data[key.replace(/-/g, '_')] = data[key]
|
||||||
|
|||||||
+1
-1
@@ -76,7 +76,7 @@ async function run(): Promise<void> {
|
|||||||
)
|
)
|
||||||
} else if (error instanceof RequestError && error.status === 403) {
|
} else if (error instanceof RequestError && error.status === 403) {
|
||||||
core.setFailed(
|
core.setFailed(
|
||||||
`Dependency review is not supported on this repository. Please ensure that Dependency graph is enabled, see https://github.com/${github.context.repo.owner}/${github.context.repo.repo}/settings/security_analysis`
|
`Dependency review is not supported on this repository. Please ensure that Dependency graph is enabled along with GitHub Advanced Security on private repositories, see https://github.com/${github.context.repo.owner}/${github.context.repo.repo}/settings/security_analysis`
|
||||||
)
|
)
|
||||||
} else {
|
} else {
|
||||||
if (error instanceof Error) {
|
if (error instanceof Error) {
|
||||||
|
|||||||
+1
-1
@@ -77,4 +77,4 @@ export type Change = z.infer<typeof ChangeSchema>
|
|||||||
export type Changes = z.infer<typeof ChangesSchema>
|
export type Changes = z.infer<typeof ChangesSchema>
|
||||||
export type ConfigurationOptions = z.infer<typeof ConfigurationOptionsSchema>
|
export type ConfigurationOptions = z.infer<typeof ConfigurationOptionsSchema>
|
||||||
export type Severity = z.infer<typeof SeveritySchema>
|
export type Severity = z.infer<typeof SeveritySchema>
|
||||||
export type Scope = typeof SCOPES[number]
|
export type Scope = (typeof SCOPES)[number]
|
||||||
|
|||||||
+1
-1
@@ -35,7 +35,7 @@ export function addChangeVulnerabilitiesToSummary(
|
|||||||
core.summary
|
core.summary
|
||||||
.addHeading('Vulnerabilities')
|
.addHeading('Vulnerabilities')
|
||||||
.addQuote(
|
.addQuote(
|
||||||
`Vulnerabilites were filtered by mininum severity <strong>${severity}</strong>.`
|
`Vulnerabilities were filtered by minimum severity <strong>${severity}</strong>.`
|
||||||
)
|
)
|
||||||
|
|
||||||
if (addedPackages.length === 0) {
|
if (addedPackages.length === 0) {
|
||||||
|
|||||||
@@ -41,6 +41,13 @@ export function isSPDXValid(license: string): boolean {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function isEnterprise(): boolean {
|
||||||
|
const serverUrl = new URL(
|
||||||
|
process.env['GITHUB_SERVER_URL'] ?? 'https://github.com'
|
||||||
|
)
|
||||||
|
return serverUrl.hostname.toLowerCase() !== 'github.com'
|
||||||
|
}
|
||||||
|
|
||||||
export function octokitClient(token = 'repo-token', required = true): Octokit {
|
export function octokitClient(token = 'repo-token', required = true): Octokit {
|
||||||
const opts: Record<string, unknown> = {}
|
const opts: Record<string, unknown> = {}
|
||||||
|
|
||||||
@@ -51,5 +58,11 @@ export function octokitClient(token = 'repo-token', required = true): Octokit {
|
|||||||
opts['auth'] = auth
|
opts['auth'] = auth
|
||||||
}
|
}
|
||||||
|
|
||||||
|
//baseUrl is required for GitHub Enterprise Server
|
||||||
|
//https://github.com/octokit/octokit.js/blob/9c8fa89d5b0bc4ddbd6dec638db00a2f6c94c298/README.md?plain=1#L196
|
||||||
|
if (isEnterprise()) {
|
||||||
|
opts['baseUrl'] = new URL('api/v3', process.env['GITHUB_SERVER_URL'])
|
||||||
|
}
|
||||||
|
|
||||||
return new Octokit(opts)
|
return new Octokit(opts)
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user