Fix import-safe checks when scripts are run from a path with symlinks (#1265)

* Fix import-safe checks when scripts are run from a path with symlinks

In v6, setup-java was made "import-safe" to facilitate testing. This
prevents setup-java & cleanup-java from doing anything when their
sources get imported.

This works fine in the general case, but actually invoking the script
(`node setup-java/index.js`) when the path to the script contains
symlinks led to the script incorrectly believing it was imported, and
refuse to actually run.

To fix this, we pass `process.argv[1]` through `fs.realpathSync`, which
resolves symlinks in the path.

Fixes #1264

* Preserve import safety when resolving symlink entrypoints

Share entrypoint detection between setup and cleanup, handle non-file entrypoints safely, and normalize both paths for preserved symlinks. Add real-process regression coverage and rebuild action bundles.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 831c32f2-a275-45bd-a92b-c387372a1554

* Update js-yaml to fix merge-source denial of service

Bump the transitive development dependency from 3.15.1 to 3.15.2 to address GHSA-2883-xcg3-v3hh without changing dependency ranges or CI checks.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 831c32f2-a275-45bd-a92b-c387372a1554

---------

Co-authored-by: Bruno Borges <brborges@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 831c32f2-a275-45bd-a92b-c387372a1554
This commit is contained in:
otaconix
2026-09-09 02:20:21 -04:00
committed by GitHub
co-authored by Copilot App Bruno Borges
parent 0781fc6af3
commit 134912a529
10 changed files with 226 additions and 8 deletions
+2 -1
View File
@@ -12,6 +12,7 @@ import {getJavaDistribution} from './distributions/distribution-factory.js';
import {JavaInstallerOptions} from './distributions/base-models.js';
import {configureProblemMatcher} from './problem-matcher.js';
import {validateToolchainIds} from './toolchain-ids.js';
import {isMainModule} from './is-main-module.js';
export async function run() {
const versions = core.getMultilineInput(constants.INPUT_JAVA_VERSION);
@@ -172,7 +173,7 @@ function settle<T>(promise: Promise<T>): Promise<PromiseSettledResult<T>> {
);
}
if (process.argv[1] === fileURLToPath(import.meta.url)) {
if (isMainModule(import.meta.url)) {
run();
} else {
// https://nodejs.org/api/modules.html#modules_accessing_the_main_module