Adding dependency manfest file injection controls

This commit is contained in:
Peter Murray
2022-10-28 16:38:02 +00:00
committed by GitHub
parent 3b10bb10a7
commit 0142e0c6d6
7 changed files with 95 additions and 30 deletions
+10
View File
@@ -25,6 +25,16 @@ inputs:
type: string
default: ''
snapshot-include-file-name:
description: Optionally include the file name in the dependency snapshot report to GitHub
type: boolean
default: false
snapshot-dependency-file-name:
description: An optional override to specify the path to the file in the repository that the snapshot should be associated with.
type: string
required: false
token:
description: The GitHub token to use to submit the depedency snapshot to the repository
type: string
+34 -14
View File
@@ -35,10 +35,13 @@ class MavenDependencyGraph {
return this.cache.countPackages();
}
createManifest(filePath) {
// // The project name is not shown in the UI when you utilize a file path currently, but the file path is required to link up to the repository file
// // which is more beneficial at this point.
// const manifest = new Manifest(this.getProjectName(), filePath);
const manifest = new dependency_submission_toolkit_1.Manifest(this.getProjectName());
let manifest;
if (filePath) {
manifest = new dependency_submission_toolkit_1.Manifest(this.getProjectName(), filePath);
}
else {
manifest = new dependency_submission_toolkit_1.Manifest(this.getProjectName());
}
const packageUrlToArtifact = this.packageUrlToArtifact;
this.directDependencies.forEach(depPackage => {
const artifact = this.packageUrlToArtifact[depPackage.packageURL.toString()];
@@ -225,7 +228,9 @@ function run() {
settingsFile: core.getInput('settings-file'),
mavenArgs: core.getInput('maven-args') || '',
};
snapshot = yield (0, snapshot_generator_1.generateSnapshot)(directory, mavenConfig);
const includeFilename = core.getBooleanInput('snapshot-include-file-name');
const manifestFilename = core.getInput('snapshot-dependency-file-name');
snapshot = yield (0, snapshot_generator_1.generateSnapshot)(directory, mavenConfig, { includeManifestFile: includeFilename, manifestFile: manifestFilename });
}
catch (err) {
core.error(err);
@@ -447,15 +452,27 @@ const maven_runner_1 = __nccwpck_require__(7433);
const file_utils_1 = __nccwpck_require__(799);
const version = (__nccwpck_require__(2876)/* .version */ .i8);
const DEPGRAPH_MAVEN_PLUGIN_VERSION = '4.0.2';
function generateSnapshot(directory, mvnConfig, context, job) {
function generateSnapshot(directory, mvnConfig, snapshotConfig) {
return __awaiter(this, void 0, void 0, function* () {
const depgraph = yield generateDependencyGraph(directory, mvnConfig);
try {
const mavenDependencies = new depgraph_1.MavenDependencyGraph(depgraph);
// The filepath to the POM needs to be relative to the root of the GitHub repository for the links to work once uploaded
const pomFile = getRepositoryRelativePath(path.join(directory, 'pom.xml'));
const manifest = mavenDependencies.createManifest(pomFile);
const snapshot = new dependency_submission_toolkit_1.Snapshot(getDetector(), context, job);
let manifest;
if (snapshotConfig === null || snapshotConfig === void 0 ? void 0 : snapshotConfig.includeManifestFile) {
let pomFile;
if (snapshotConfig === null || snapshotConfig === void 0 ? void 0 : snapshotConfig.manifestFile) {
pomFile = snapshotConfig.manifestFile;
}
else {
// The filepath to the POM needs to be relative to the root of the GitHub repository for the links to work once uploaded
pomFile = getRepositoryRelativePath(path.join(directory, 'pom.xml'));
}
manifest = mavenDependencies.createManifest(pomFile);
}
else {
manifest = mavenDependencies.createManifest();
}
const snapshot = new dependency_submission_toolkit_1.Snapshot(getDetector(), snapshotConfig === null || snapshotConfig === void 0 ? void 0 : snapshotConfig.context, snapshotConfig === null || snapshotConfig === void 0 ? void 0 : snapshotConfig.job);
snapshot.addManifest(manifest);
return snapshot;
}
@@ -542,12 +559,15 @@ function getRepositoryRelativePath(file) {
const workspaceDirectory = path.resolve(process.env.GITHUB_WORKSPACE || '.');
const fileResolved = path.resolve(file);
const fileDirectory = path.dirname(fileResolved);
core.debug(`Workspace directory = ${workspaceDirectory}`);
core.debug(`Snapshot file = ${fileResolved}`);
core.debug(`Snapshot directory = ${fileDirectory}`);
let result = fileResolved;
if (fileDirectory.startsWith(workspaceDirectory)) {
return fileResolved.substring(workspaceDirectory.length + path.sep.length);
}
else {
return path.resolve(file);
result = fileResolved.substring(workspaceDirectory.length + path.sep.length);
}
core.debug(`Snapshot relative file = ${result}`);
return result;
}
//# sourceMappingURL=snapshot-generator.js.map
+1 -1
View File
File diff suppressed because one or more lines are too long
+7 -4
View File
@@ -69,10 +69,13 @@ export class MavenDependencyGraph {
}
createManifest(filePath?: string): Manifest {
// // The project name is not shown in the UI when you utilize a file path currently, but the file path is required to link up to the repository file
// // which is more beneficial at this point.
// const manifest = new Manifest(this.getProjectName(), filePath);
const manifest = new Manifest(this.getProjectName());
let manifest: Manifest;
if (filePath) {
manifest = new Manifest(this.getProjectName(), filePath);
} else {
manifest = new Manifest(this.getProjectName());
}
const packageUrlToArtifact = this.packageUrlToArtifact;
this.directDependencies.forEach(depPackage => {
+6 -1
View File
@@ -59,7 +59,12 @@ async function execute() {
mavenArgs: opts.mavenArgs
};
snapshot = await generateSnapshot(opts.directory, mvnConfig, context, job);
const snapshotConfig = {
context,
job,
}
snapshot = await generateSnapshot(opts.directory, mvnConfig, snapshotConfig);
} catch (err: any) {
console.error(`Failed to generate a dependency snapshot, check logs for more details, ${err}`);
+3 -1
View File
@@ -12,8 +12,10 @@ async function run() {
settingsFile: core.getInput('settings-file'),
mavenArgs: core.getInput('maven-args') || '',
}
const includeFilename = core.getBooleanInput('snapshot-include-file-name');
const manifestFilename = core.getInput('snapshot-dependency-file-name');
snapshot = await generateSnapshot(directory, mavenConfig);
snapshot = await generateSnapshot(directory, mavenConfig, {includeManifestFile: includeFilename, manifestFile: manifestFilename});
} catch (err: any) {
core.error(err);
core.setFailed(`Failed to generate a dependency snapshot, check logs for more details, ${err}`);
+34 -9
View File
@@ -1,7 +1,7 @@
import * as core from '@actions/core';
import * as path from 'path';
import { Snapshot } from '@github/dependency-submission-toolkit';
import { Manifest, Snapshot } from '@github/dependency-submission-toolkit';
import { Depgraph, MavenDependencyGraph, parseDependencyJson } from './depgraph';
import { MavenRunner } from './maven-runner';
import { loadFileContents } from './utils/file-utils';
@@ -16,15 +16,34 @@ export type MavenConfiguration = {
mavenArgs?: string;
}
export async function generateSnapshot(directory: string, mvnConfig?: MavenConfiguration, context?: any, job?: any) {
export type SnapshotConfig = {
includeManifestFile?: boolean;
manifestFile?: string;
context?: any;
job?: any
};
export async function generateSnapshot(directory: string, mvnConfig?: MavenConfiguration, snapshotConfig?: SnapshotConfig) {
const depgraph = await generateDependencyGraph(directory, mvnConfig);
try {
const mavenDependencies = new MavenDependencyGraph(depgraph);
// The filepath to the POM needs to be relative to the root of the GitHub repository for the links to work once uploaded
const pomFile = getRepositoryRelativePath(path.join(directory, 'pom.xml'));
const manifest = mavenDependencies.createManifest(pomFile);
const snapshot = new Snapshot(getDetector(), context, job);
let manifest: Manifest;
if (snapshotConfig?.includeManifestFile) {
let pomFile;
if (snapshotConfig?.manifestFile) {
pomFile = snapshotConfig.manifestFile;
} else {
// The filepath to the POM needs to be relative to the root of the GitHub repository for the links to work once uploaded
pomFile = getRepositoryRelativePath(path.join(directory, 'pom.xml'));
}
manifest = mavenDependencies.createManifest(pomFile);
} else {
manifest = mavenDependencies.createManifest();
}
const snapshot = new Snapshot(getDetector(), snapshotConfig?.context, snapshotConfig?.job);
snapshot.addManifest(manifest);
return snapshot;
@@ -118,9 +137,15 @@ function getRepositoryRelativePath(file) {
const fileResolved = path.resolve(file);
const fileDirectory = path.dirname(fileResolved);
core.debug(`Workspace directory = ${workspaceDirectory}`);
core.debug(`Snapshot file = ${fileResolved}`);
core.debug(`Snapshot directory = ${fileDirectory}`);
let result = fileResolved;
if (fileDirectory.startsWith(workspaceDirectory)) {
return fileResolved.substring(workspaceDirectory.length + path.sep.length);
} else {
return path.resolve(file);
result = fileResolved.substring(workspaceDirectory.length + path.sep.length);
}
core.debug(`Snapshot relative file = ${result}`);
return result;
}