diff --git a/CHANGELOG.md b/CHANGELOG.md index 0f0f00f..8ea6e60 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,14 +1,13 @@ # Changelog -## v7.0.1 -* Skip running unsafe pr check if input is default by @aiqiaoy in https://github.com/actions/checkout/pull/2518 -* Trim only ascii whitespace for branch by @aiqiaoy in https://github.com/actions/checkout/pull/2521 -* Escape values passed to --unset by @aiqiaoy in https://github.com/actions/checkout/pull/2530 -* Various dependency updates - ## v7.0.0 * Block checking out fork PR for pull_request_target and workflow_run by @aiqiaoy in https://github.com/actions/checkout/pull/2454 -* Various dependency updates +* Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by @dependabot[bot] in https://github.com/actions/checkout/pull/2458 +* Bump flatted from 3.3.1 to 3.4.2 by @dependabot[bot] in https://github.com/actions/checkout/pull/2460 +* Bump js-yaml from 4.1.0 to 4.2.0 by @dependabot[bot] in https://github.com/actions/checkout/pull/2461 +* Bump @actions/core and @actions/tool-cache and Remove uuid by @dependabot[bot] in https://github.com/actions/checkout/pull/2459 +* upgrade module to esm and update dependencies by @aiqiaoy in https://github.com/actions/checkout/pull/2463 +* Bump the minor-npm-dependencies group across 1 directory with 3 updates by @dependabot[bot] in https://github.com/actions/checkout/pull/2462 ## v6.0.3 * Fix checkout init for SHA-256 repositories by @yaananth in https://github.com/actions/checkout/pull/2439 diff --git a/__test__/input-helper.test.ts b/__test__/input-helper.test.ts index afe30fb..27b023c 100644 --- a/__test__/input-helper.test.ts +++ b/__test__/input-helper.test.ts @@ -24,20 +24,9 @@ const mockGithubContext: any = { payload: {} } -// Replicate @actions/core getInput behavior: it trims whitespace by default -// (String.prototype.trim(), which strips characters such as a leading U+FEFF BOM) -// unless trimWhitespace is explicitly set to false. -const getInputImpl = (name: string, options?: {trimWhitespace?: boolean}) => { - const val = inputs[name] ?? '' - if (options && options.trimWhitespace === false) { - return val - } - return typeof val === 'string' ? val.trim() : val -} - // Mock @actions/core before loading input-helper jest.unstable_mockModule('@actions/core', () => ({ - getInput: jest.fn(getInputImpl), + getInput: jest.fn((name: string) => inputs[name]), getBooleanInput: jest.fn((name: string) => inputs[name]), getMultilineInput: jest.fn((name: string) => inputs[name] ? String(inputs[name]).split('\n').filter(Boolean) : [] @@ -87,7 +76,9 @@ describe('input-helper tests', () => { inputs = {} jest.clearAllMocks() // Re-apply default mocks - ;(core.getInput as jest.Mock).mockImplementation(getInputImpl as any) + ;(core.getInput as jest.Mock).mockImplementation( + (name: string) => inputs[name] + ) mockDirectoryExistsSync.mockImplementation( (p: string) => p === gitHubWorkspace ) @@ -185,36 +176,6 @@ describe('input-helper tests', () => { expect(settings.commit).toBeFalsy() }) - it('does not reclassify a ref as sha when a BOM is prefixed', async () => { - // A fork branch named "" + 40 hex chars. core.getInput trims the - // BOM by default, which previously collapsed this into a bare SHA and - // bypassed the unsafe fork PR checkout guard. - inputs.ref = '\uFEFF522d932fae5296da51fdf431934425ecf891c6a2' - const settings: IGitSourceSettings = await inputHelper.getInputs() - expect(settings.commit).toBeFalsy() - expect(settings.ref).toBe('522d932fae5296da51fdf431934425ecf891c6a2') - }) - - it('does not reclassify a sha-256 ref as sha when a BOM is prefixed', async () => { - inputs.ref = - '\uFEFF1111111111222222222233333333334444444444555555555566666666667777' - const settings: IGitSourceSettings = await inputHelper.getInputs() - expect(settings.commit).toBeFalsy() - expect(settings.ref).toBe( - '1111111111222222222233333333334444444444555555555566666666667777' - ) - }) - - it('treats a sha surrounded by ascii whitespace as a commit', async () => { - // ASCII whitespace can only come from the workflow author's YAML (git ref - // names cannot contain it), so trimming it and treating the value as a - // commit is safe. - inputs.ref = ' 1111111111222222222233333333334444444444 ' - const settings: IGitSourceSettings = await inputHelper.getInputs() - expect(settings.ref).toBeFalsy() - expect(settings.commit).toBe('1111111111222222222233333333334444444444') - }) - it('sets workflow organization ID', async () => { const settings: IGitSourceSettings = await inputHelper.getInputs() expect(settings.workflowOrganizationId).toBe(123456) diff --git a/dist/index.js b/dist/index.js index 06ae5d2..cc25215 100644 --- a/dist/index.js +++ b/dist/index.js @@ -35913,7 +35913,7 @@ class GitCommandManager { else { args.push(globalConfig ? '--global' : '--local'); } - args.push('--unset', configKey, regexp_helper_escape(configValue)); + args.push('--unset', configKey, configValue); const output = await this.execGit(args, true); return output.exitCode === 0; } @@ -42100,22 +42100,6 @@ async function getInputs() { `${github_context.repo.owner}/${github_context.repo.repo}`.toUpperCase(); // Source branch, source version result.ref = getInput('ref'); - // core.getInput()'s default trim strips a range of Unicode characters such as a - // leading BOM (U+FEFF) or NBSP (U+00A0). Those are valid in a git ref name, so - // a fork branch named "" + 40 hex chars would trim down to a bare SHA and - // be silently reclassified as a commit, bypassing the unsafe fork PR checkout - // guard. - // - // The trim below strips only the ASCII whitespace characters which are all forbidden - // in a git branch name. - // \t U+0009 horizontal tab - ASCII control, forbidden in ref names - // \n U+000A line feed - ASCII control, forbidden in ref names - // \v U+000B vertical tab - ASCII control, forbidden in ref names - // \f U+000C form feed - ASCII control, forbidden in ref names - // \r U+000D carriage return - ASCII control, forbidden in ref names - // ' ' U+0020 space - forbidden in ref names - const asciiTrimmedRef = getInput('ref', { trimWhitespace: false }) - .replace(/^[\t\n\v\f\r ]+|[\t\n\v\f\r ]+$/g, ''); if (!result.ref) { if (isWorkflowRepository) { result.ref = github_context.ref; @@ -42128,8 +42112,8 @@ async function getInputs() { } } // SHA? - else if (asciiTrimmedRef.match(/^(?:[0-9a-fA-F]{40}|[0-9a-fA-F]{64})$/)) { - result.commit = asciiTrimmedRef; + else if (result.ref.match(/^(?:[0-9a-fA-F]{40}|[0-9a-fA-F]{64})$/)) { + result.commit = result.ref; result.ref = ''; } core_debug(`ref = '${result.ref}'`); diff --git a/package-lock.json b/package-lock.json index faf0e22..09a72c4 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "checkout", - "version": "7.0.1", + "version": "7.0.0", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "checkout", - "version": "7.0.1", + "version": "7.0.0", "license": "MIT", "dependencies": { "@actions/core": "^3.0.1", diff --git a/package.json b/package.json index 9b02e96..4a38df9 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "checkout", - "version": "7.0.1", + "version": "7.0.0", "description": "checkout action", "type": "module", "main": "lib/main.js", diff --git a/src/git-command-manager.ts b/src/git-command-manager.ts index 8431658..36cdb47 100644 --- a/src/git-command-manager.ts +++ b/src/git-command-manager.ts @@ -510,7 +510,7 @@ class GitCommandManager { } else { args.push(globalConfig ? '--global' : '--local') } - args.push('--unset', configKey, regexpHelper.escape(configValue)) + args.push('--unset', configKey, configValue) const output = await this.execGit(args, true) return output.exitCode === 0 diff --git a/src/input-helper.ts b/src/input-helper.ts index 9a98b86..87b2800 100644 --- a/src/input-helper.ts +++ b/src/input-helper.ts @@ -59,23 +59,6 @@ export async function getInputs(): Promise { // Source branch, source version result.ref = core.getInput('ref') - // core.getInput()'s default trim strips a range of Unicode characters such as a - // leading BOM (U+FEFF) or NBSP (U+00A0). Those are valid in a git ref name, so - // a fork branch named "" + 40 hex chars would trim down to a bare SHA and - // be silently reclassified as a commit, bypassing the unsafe fork PR checkout - // guard. - // - // The trim below strips only the ASCII whitespace characters which are all forbidden - // in a git branch name. - // \t U+0009 horizontal tab - ASCII control, forbidden in ref names - // \n U+000A line feed - ASCII control, forbidden in ref names - // \v U+000B vertical tab - ASCII control, forbidden in ref names - // \f U+000C form feed - ASCII control, forbidden in ref names - // \r U+000D carriage return - ASCII control, forbidden in ref names - // ' ' U+0020 space - forbidden in ref names - const asciiTrimmedRef = core - .getInput('ref', {trimWhitespace: false}) - .replace(/^[\t\n\v\f\r ]+|[\t\n\v\f\r ]+$/g, '') if (!result.ref) { if (isWorkflowRepository) { result.ref = github.context.ref @@ -89,8 +72,8 @@ export async function getInputs(): Promise { } } // SHA? - else if (asciiTrimmedRef.match(/^(?:[0-9a-fA-F]{40}|[0-9a-fA-F]{64})$/)) { - result.commit = asciiTrimmedRef + else if (result.ref.match(/^(?:[0-9a-fA-F]{40}|[0-9a-fA-F]{64})$/)) { + result.commit = result.ref result.ref = '' } core.debug(`ref = '${result.ref}'`)