Compare commits

..
Author SHA1 Message Date
copilot-swe-agent[bot] b51f2cac4b Initial plan 2026-08-18 00:51:26 +00:00
41 changed files with 359 additions and 1207 deletions
+13 -16
View File
@@ -1,25 +1,22 @@
# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file
version: 2 version: 2
updates: updates:
# Enable version updates for npm
- package-ecosystem: 'npm' - package-ecosystem: 'npm'
# Look for `package.json` and `lock` files in the `root` directory
directory: '/' directory: '/'
# Check the npm registry for updates every day (weekdays)
schedule: schedule:
interval: 'monthly' interval: 'weekly'
cooldown:
default-days: 7
groups:
monthly-npm-updates:
applies-to: 'version-updates'
patterns:
- '*'
# Enable version updates for GitHub Actions
- package-ecosystem: 'github-actions' - package-ecosystem: 'github-actions'
# Workflow files stored in the default location of `.github/workflows`
# You don't need to specify `/.github/workflows` for `directory`. You can use `directory: "/"`.
directory: '/' directory: '/'
schedule: schedule:
interval: 'monthly' interval: 'weekly'
cooldown:
default-days: 7
groups:
monthly-actions-updates:
applies-to: 'version-updates'
patterns:
- '*'
@@ -24,7 +24,6 @@ jobs:
warm-caches: warm-caches:
name: Warm ${{ matrix.tool }} ${{ matrix.profile }} caches (${{ matrix.os }}) name: Warm ${{ matrix.tool }} ${{ matrix.profile }} caches (${{ matrix.os }})
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: write-only
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
@@ -66,7 +65,6 @@ jobs:
name: Benchmark ${{ matrix.tool }} ${{ matrix.profile }} (${{ matrix.os }}) name: Benchmark ${{ matrix.tool }} ${{ matrix.profile }} (${{ matrix.os }})
needs: warm-caches needs: warm-caches
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: read
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
-17
View File
@@ -21,7 +21,6 @@ defaults:
jobs: jobs:
gradle-save: gradle-save:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: write-only
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
@@ -49,7 +48,6 @@ jobs:
bash __tests__/check-dir.sh "$HOME/.gradle/wrapper/dists" bash __tests__/check-dir.sh "$HOME/.gradle/wrapper/dists"
gradle-restore: gradle-restore:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: read
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
@@ -74,7 +72,6 @@ jobs:
run: bash __tests__/check-dir.sh "$HOME/.gradle/wrapper/dists" run: bash __tests__/check-dir.sh "$HOME/.gradle/wrapper/dists"
maven-save: maven-save:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: write-only
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
@@ -100,7 +97,6 @@ jobs:
bash __tests__/check-dir.sh "$HOME/.m2/wrapper/dists" bash __tests__/check-dir.sh "$HOME/.m2/wrapper/dists"
maven-restore: maven-restore:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: read
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
@@ -125,7 +121,6 @@ jobs:
run: bash __tests__/check-dir.sh "$HOME/.m2/wrapper/dists" run: bash __tests__/check-dir.sh "$HOME/.m2/wrapper/dists"
sbt-save: sbt-save:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: write-only
defaults: defaults:
run: run:
shell: bash shell: bash
@@ -165,7 +160,6 @@ jobs:
run: bash "$GITHUB_WORKSPACE/__tests__/check-dir.sh" "$HOME/.cache/coursier" run: bash "$GITHUB_WORKSPACE/__tests__/check-dir.sh" "$HOME/.cache/coursier"
sbt-restore: sbt-restore:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: read
defaults: defaults:
run: run:
shell: bash shell: bash
@@ -200,7 +194,6 @@ jobs:
run: bash "$GITHUB_WORKSPACE/__tests__/check-dir.sh" "$HOME/.cache/coursier" run: bash "$GITHUB_WORKSPACE/__tests__/check-dir.sh" "$HOME/.cache/coursier"
gradle1-save: gradle1-save:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: write-only
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
@@ -229,7 +222,6 @@ jobs:
bash __tests__/check-dir.sh "$HOME/.gradle/wrapper/dists" bash __tests__/check-dir.sh "$HOME/.gradle/wrapper/dists"
gradle1-restore: gradle1-restore:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: read
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
@@ -254,7 +246,6 @@ jobs:
run: bash __tests__/check-dir.sh "$HOME/.gradle/wrapper/dists" run: bash __tests__/check-dir.sh "$HOME/.gradle/wrapper/dists"
gradle2-restore: gradle2-restore:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: read
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
@@ -277,7 +268,6 @@ jobs:
run: bash __tests__/check-dir.sh "$HOME/.gradle/caches" absent run: bash __tests__/check-dir.sh "$HOME/.gradle/caches" absent
maven1-save: maven1-save:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: write-only
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
@@ -304,7 +294,6 @@ jobs:
bash __tests__/check-dir.sh "$HOME/.m2/wrapper/dists" bash __tests__/check-dir.sh "$HOME/.m2/wrapper/dists"
maven1-restore: maven1-restore:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: read
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
@@ -329,7 +318,6 @@ jobs:
run: bash __tests__/check-dir.sh "$HOME/.m2/wrapper/dists" run: bash __tests__/check-dir.sh "$HOME/.m2/wrapper/dists"
maven2-restore: maven2-restore:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: read
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
@@ -354,7 +342,6 @@ jobs:
run: bash __tests__/check-dir.sh "$HOME/.m2/repository" absent run: bash __tests__/check-dir.sh "$HOME/.m2/repository" absent
sbt1-save: sbt1-save:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: write-only
defaults: defaults:
run: run:
shell: bash shell: bash
@@ -395,7 +382,6 @@ jobs:
run: bash "$GITHUB_WORKSPACE/__tests__/check-dir.sh" "$HOME/.cache/coursier" run: bash "$GITHUB_WORKSPACE/__tests__/check-dir.sh" "$HOME/.cache/coursier"
sbt1-restore: sbt1-restore:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: read
defaults: defaults:
run: run:
shell: bash shell: bash
@@ -430,7 +416,6 @@ jobs:
run: bash "$GITHUB_WORKSPACE/__tests__/check-dir.sh" "$HOME/.cache/coursier" run: bash "$GITHUB_WORKSPACE/__tests__/check-dir.sh" "$HOME/.cache/coursier"
sbt2-restore: sbt2-restore:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
cache-mode: read
defaults: defaults:
run: run:
shell: bash shell: bash
@@ -465,7 +450,6 @@ jobs:
run: bash "$GITHUB_WORKSPACE/__tests__/check-dir.sh" "$HOME/.cache/coursier" absent run: bash "$GITHUB_WORKSPACE/__tests__/check-dir.sh" "$HOME/.cache/coursier" absent
custom-maven-path-save: custom-maven-path-save:
runs-on: ubuntu-latest runs-on: ubuntu-latest
cache-mode: write-only
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v7 uses: actions/checkout@v7
@@ -490,7 +474,6 @@ jobs:
bash __tests__/check-dir.sh "$RUNNER_TEMP/setup-java-custom-maven-repository" bash __tests__/check-dir.sh "$RUNNER_TEMP/setup-java-custom-maven-repository"
custom-maven-path-restore: custom-maven-path-restore:
runs-on: ubuntu-latest runs-on: ubuntu-latest
cache-mode: read
needs: custom-maven-path-save needs: custom-maven-path-save
steps: steps:
- name: Checkout - name: Checkout
+3 -4
View File
@@ -71,7 +71,7 @@ jobs:
version: 25 version: 25
- distribution: oracle - distribution: oracle
os: macos-15-intel os: macos-15-intel
version: 21 version: 17
- distribution: oracle - distribution: oracle
os: windows-latest os: windows-latest
version: 21 version: 21
@@ -154,8 +154,8 @@ jobs:
version: ['21', '17'] version: ['21', '17']
steps: steps:
- *checkout_step - *checkout_step
- name: Install bash and GnuPG - name: Install bash
run: apk add --no-cache bash gnupg run: apk add --no-cache bash
- name: setup-java - name: setup-java
uses: ./ uses: ./
id: setup-java id: setup-java
@@ -340,7 +340,6 @@ jobs:
with: with:
java-version: ${{ matrix.version }} java-version: ${{ matrix.version }}
distribution: ${{ matrix.distribution }} distribution: ${{ matrix.distribution }}
verify-signature: ${{ matrix.distribution == 'temurin' && contains(matrix.version, '-ea') && 'false' || '' }}
- name: Verify Java - name: Verify Java
env: env:
JAVA_VERSION: ${{ matrix.version }} JAVA_VERSION: ${{ matrix.version }}
+1 -1
View File
@@ -1,6 +1,6 @@
--- ---
name: fast-xml-parser name: fast-xml-parser
version: 5.11.0 version: 5.10.1
type: npm type: npm
summary: Validate XML, Parse XML, Build XML without C/C++ based libraries summary: Validate XML, Parse XML, Build XML without C/C++ based libraries
homepage: homepage:
+1 -1
View File
@@ -1,6 +1,6 @@
--- ---
name: strnum name: strnum
version: 2.4.2 version: 2.4.1
type: npm type: npm
summary: Parse String to Number based on configuration summary: Parse String to Number based on configuration
homepage: homepage:
+33 -57
View File
@@ -9,13 +9,22 @@ Set up Java for GitHub Actions workflows. `setup-java` installs a requested Java
```yaml ```yaml
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: temurin distribution: temurin
java-version: '25' java-version: '25'
- run: java --version - run: java --version
``` ```
> [!NOTE]
> V6 is still in development on the `main` branch and is not yet recommended for production workflows. To use it, you must explicitly reference the `main` branch in your workflow, as in
>
> ```yaml
> - uses: actions/setup-java@main
> ```
>
> For production workflows, it is recommended to use the latest stable release `v5`.
## Contents ## Contents
- [What it does](#what-it-does) - [What it does](#what-it-does)
@@ -45,20 +54,15 @@ steps:
## What's new ## What's new
### V6 ### V6 (in development)
- Migrated the action implementation to ESM to support the latest `@actions/*` packages. - Migrated the action implementation to ESM to support the latest `@actions/*` packages.
- Added Oracle OpenJDK (`oracle-openjdk`), Red Hat Build of OpenJDK (`redhat`), and Liberica Native Image Kit (`liberica-nik`), and expanded Tencent Kona support through JDK 25. - Added the `oracle-openjdk` distribution for OpenJDK builds from Oracle.
- Added `java-version: latest` to resolve the newest stable GA release from the distribution's remote metadata. - Added `java-version: latest` to resolve the newest stable GA release from the distribution's remote metadata.
- Expanded install compatibility with JEP 322 multi-field versions such as `18.0.1.1`, Temurin `jdk+jmods` packages, and native musl artifacts on Alpine for Dragonwell, Corretto, Zulu, and Liberica. - JDK downloads now automatically verify authoritative checksums for [supported distributions](#download-integrity-and-signatures).
- JDK downloads now automatically verify authoritative checksums. Package signature verification is supported for Temurin and Microsoft builds, with configurable strict enforcement.
- Added `force-download: true` to bypass the tool cache and perform a reproducible fresh install. - Added `force-download: true` to bypass the tool cache and perform a reproducible fresh install.
- Dependency caching now supports custom paths with `cache-path` and restore-only operation with `cache-read-only: true`. - Dependency caching now supports custom paths with `cache-path` and restore-only operation with `cache-read-only: true`.
- Dependency cache keys now include `.mvn/extensions.xml` and `gradle.properties`, preventing stale restores when Maven extensions or Gradle dependency properties change.
- Downloaded JDKs are now [cached](#caching-jdk-installations) automatically when `cache` is set; use `cache-jdk` to enable or disable it independently. - Downloaded JDKs are now [cached](#caching-jdk-installations) automatically when `cache` is set; use `cache-jdk` to enable or disable it independently.
- Warm JDK-cached jobs can reuse cached release metadata, avoiding vendor API calls while retaining a stale-metadata fallback for vendor outages and rate limits.
- Maven configuration now supports multiple server credentials and custom dependency-resolution repositories.
- Maven signing keys are imported into an isolated temporary GPG home instead of the runner's default keyring.
- Set `problem-matcher: false` to disable Java compiler and uncaught-exception annotations. - Set `problem-matcher: false` to disable Java compiler and uncaught-exception annotations.
- GraalVM distributions now set `GRAALVM_HOME` in addition to `JAVA_HOME`. - GraalVM distributions now set `GRAALVM_HOME` in addition to `JAVA_HOME`.
- Invalid boolean values, unsupported distribution/package/platform combinations, and mismatched Maven toolchain ID counts now fail with targeted errors. - Invalid boolean values, unsupported distribution/package/platform combinations, and mismatched Maven toolchain ID counts now fail with targeted errors.
@@ -69,7 +73,6 @@ steps:
- Deprecated aliases still work, but emit warnings. - Deprecated aliases still work, but emit warnings.
- Maven GPG passphrases are now passed through `gpg.passphraseEnvName` instead of a deprecated `gpg.passphrase` server entry in `settings.xml`. This requires `maven-gpg-plugin` 3.2.0 or newer. See [GPG](docs/advanced-usage.md#gpg). - Maven GPG passphrases are now passed through `gpg.passphraseEnvName` instead of a deprecated `gpg.passphrase` server entry in `settings.xml`. This requires `maven-gpg-plugin` 3.2.0 or newer. See [GPG](docs/advanced-usage.md#gpg).
- Legacy AdoptOpenJDK distributions were removed. Use `temurin` instead of `adopt` or `adopt-hotspot`, and `semeru` instead of `adopt-openj9`. - Legacy AdoptOpenJDK distributions were removed. Use `temurin` instead of `adopt` or `adopt-hotspot`, and `semeru` instead of `adopt-openj9`.
- See the [complete V6 release notes](https://github.com/actions/setup-java/releases/tag/v6.0.0) for all enhancements and fixes.
### V5 ### V5
@@ -86,7 +89,7 @@ steps:
### Older versions ### Older versions
> [!WARNING] > [!WARNING]
> `actions/setup-java` versions `v1` through `v4` are deprecated. Upgrade workflows to `actions/setup-java@v6`, the latest stable release. > `actions/setup-java` versions `v1` through `v4` are deprecated. Upgrade workflows to `actions/setup-java@v5`, the latest stable release.
## Usage ## Usage
@@ -95,7 +98,7 @@ steps:
```yaml ```yaml
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: temurin distribution: temurin
java-version: '25' java-version: '25'
@@ -107,7 +110,7 @@ steps:
```yaml ```yaml
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: microsoft distribution: microsoft
java-version: '25' java-version: '25'
@@ -119,7 +122,7 @@ steps:
```yaml ```yaml
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: temurin distribution: temurin
java-version-file: .java-version java-version-file: .java-version
@@ -133,7 +136,7 @@ Supported version files are `.java-version`, `.tool-versions`, and `.sdkmanrc`.
```yaml ```yaml
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: temurin distribution: temurin
java-version: latest java-version: latest
@@ -156,8 +159,8 @@ steps:
| `force-download` | Always download Java and replace any matching version in the tool cache. | `false` | | `force-download` | Always download Java and replace any matching version in the tool cache. | `false` |
| `set-default` | Add Java to `PATH` and set `JAVA_HOME`. When `false`, only version-specific `JAVA_HOME_<major>_<arch>` variables are set. | `true` | | `set-default` | Add Java to `PATH` and set `JAVA_HOME`. When `false`, only version-specific `JAVA_HOME_<major>_<arch>` variables are set. | `true` |
| `problem-matcher` | Register Java compiler and uncaught exception problem matchers. | `true` | | `problem-matcher` | Register Java compiler and uncaught exception problem matchers. | `true` |
| `verify-signature` | Verify downloaded Java package signatures when supported. Explicitly setting this to `true` makes verification failures fatal. | Distribution-dependent; see [Download integrity and signatures](#download-integrity-and-signatures) | | `verify-signature` | Verify downloaded Java package signatures when supported. Currently supported for `temurin` and `microsoft`. | `false` |
| `verify-signature-public-key` | One or more ASCII-armored GPG public keys used for signature verification. Concatenate multiple armored key blocks. Custom keys replace the bundled distribution keys. | | | `verify-signature-public-key` | ASCII-armored GPG public key to use for signature verification. Overrides the bundled key. | |
| `token` | Token for fetching GitHub.com-hosted version manifests, useful on GitHub Enterprise Server when unauthenticated requests are rate-limited. | `${{ github.token }}` on GitHub.com; empty string on GHES | | `token` | Token for fetching GitHub.com-hosted version manifests, useful on GitHub Enterprise Server when unauthenticated requests are rate-limited. | `${{ github.token }}` on GitHub.com; empty string on GHES |
| `cache` | Enable dependency caching for `maven`, `gradle`, or `sbt`. | | | `cache` | Enable dependency caching for `maven`, `gradle`, or `sbt`. | |
| `cache-jdk` | Cache downloaded JDK installations between jobs. When omitted, JDK caching is enabled only if `cache` is set. Set explicitly to `true` or `false` to override. | Enabled when `cache` is set | | `cache-jdk` | Cache downloaded JDK installations between jobs. When omitted, JDK caching is enabled only if `cache` is set. Set explicitly to `true` or `false` to override. | Enabled when `cache` is set |
@@ -247,34 +250,7 @@ GitHub-hosted runners primarily pre-cache Eclipse Temurin JDKs. See the installe
Distributions or individual releases without an authoritative checksum continue to install normally, with the omission reported in debug logs. Installations resolved directly from the runner tool cache — including JDKs preinstalled on the runner image and JDKs installed by an earlier step of the same job — are not downloaded again and are not reverified, even when `verify-signature: true` is set. Use `force-download: true` to always download and verify the archive. Distributions or individual releases without an authoritative checksum continue to install normally, with the omission reported in debug logs. Installations resolved directly from the runner tool cache — including JDKs preinstalled on the runner image and JDKs installed by an earlier step of the same job — are not downloaded again and are not reverified, even when `verify-signature: true` is set. Use `force-download: true` to always download and verify the archive.
Package signature verification is supported for `temurin` and `microsoft`. When `verify-signature` is omitted, the action checks the signature and warns if GPG is unavailable or verification fails, but does not enforce the result. Explicitly setting `verify-signature: true` enforces verification and makes these failures fatal. Setting `verify-signature: true` for an unsupported distribution also fails the workflow. Use `verify-signature: true` to verify package signatures for distributions that support it. Currently supported distributions are `temurin` and `microsoft`; setting it for an unsupported distribution fails the workflow.
> [!WARNING]
> Requesting explicit signature verification with verify-signature can fail a build after an unexpected but legitimate vendor signing-key rotation, because the action's bundled keys may not yet include the new key. Confirm a new key through the vendor's trusted documentation before using it.
After confirming a legitimate rotation, configure the updated key with `verify-signature-public-key`. The input accepts one or more ASCII-armored public keys; concatenate complete armored key blocks when both old and new vendor keys are needed during a transition. Custom keys replace, rather than extend, the keys bundled with the selected distribution.
```yaml
- uses: actions/setup-java@v6
with:
distribution: temurin
java-version: '25'
verify-signature: true
verify-signature-public-key: |
-----BEGIN PGP PUBLIC KEY BLOCK-----
...vendor key material...
-----END PGP PUBLIC KEY BLOCK-----
```
As a temporary fallback while a legitimate rotation is being investigated, set `verify-signature: false`. This disables package signature verification, although authoritative checksum verification still applies when the vendor publishes a checksum.
```yaml
- uses: actions/setup-java@v6
with:
distribution: temurin
java-version: '25'
verify-signature: false
```
## Caching ## Caching
@@ -291,7 +267,7 @@ Set `cache` to `maven`, `gradle`, or `sbt` to cache dependencies with minimal co
```yaml ```yaml
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: temurin distribution: temurin
java-version: '25' java-version: '25'
@@ -310,7 +286,7 @@ The primary dependency cache key is `setup-java-<runner-os>-<node-arch>-<package
Use `cache-dependency-path` to override the files used for key hashing, especially in monorepos: Use `cache-dependency-path` to override the files used for key hashing, especially in monorepos:
```yaml ```yaml
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: temurin distribution: temurin
java-version: '25' java-version: '25'
@@ -323,7 +299,7 @@ Use `cache-dependency-path` to override the files used for key hashing, especial
Use `cache-path` when the build tool stores dependencies outside the default location: Use `cache-path` when the build tool stores dependencies outside the default location:
```yaml ```yaml
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: temurin distribution: temurin
java-version: '25' java-version: '25'
@@ -362,7 +338,7 @@ The JDK cache stores the downloaded JDK installation so later runs skip the down
Set `cache-read-only: true` to restore dependency, wrapper, and JDK caches without saving changes in the post action. This is useful for pull requests, merge queues, short-lived branches, and matrix fan-out jobs that should only consume caches produced elsewhere. Set `cache-read-only: true` to restore dependency, wrapper, and JDK caches without saving changes in the post action. This is useful for pull requests, merge queues, short-lived branches, and matrix fan-out jobs that should only consume caches produced elsewhere.
```yaml ```yaml
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: temurin distribution: temurin
java-version: '25' java-version: '25'
@@ -378,7 +354,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: temurin distribution: temurin
java-version: '25' java-version: '25'
@@ -393,7 +369,7 @@ jobs:
goal: [test, verify, package] goal: [test, verify, package]
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: temurin distribution: temurin
java-version: '25' java-version: '25'
@@ -411,7 +387,7 @@ env:
SEGMENT_DOWNLOAD_TIMEOUT_MINS: '5' SEGMENT_DOWNLOAD_TIMEOUT_MINS: '5'
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: temurin distribution: temurin
java-version: '25' java-version: '25'
@@ -425,7 +401,7 @@ Install multiple Java versions by providing a multiline `java-version` value. Al
```yaml ```yaml
steps: steps:
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: temurin distribution: temurin
java-version: | java-version: |
@@ -452,7 +428,7 @@ jobs:
name: Java ${{ matrix.java }} name: Java ${{ matrix.java }}
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: temurin distribution: temurin
java-version: ${{ matrix.java }} java-version: ${{ matrix.java }}
@@ -469,7 +445,7 @@ jobs:
```yaml ```yaml
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: temurin distribution: temurin
java-version: '25' java-version: '25'
@@ -491,7 +467,7 @@ required. See [Resolving Maven dependencies from custom repositories](docs/advan
```yaml ```yaml
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
- uses: actions/setup-java@v6 - uses: actions/setup-java@v5
with: with:
distribution: temurin distribution: temurin
java-version: '25' java-version: '25'
@@ -546,7 +522,7 @@ The scripts and documentation in this project are released under the [MIT Licens
## Contributions ## Contributions
Contributions are welcome. See our [Contributor's Guide](docs/CONTRIBUTING.md). Contributions are welcome. See our [Contributor's Guide](docs/contributors.md).
## Code of Conduct ## Code of Conduct
+1 -1
View File
@@ -393,7 +393,7 @@ function createRegisteredJdk(version = '21.0.8+9') {
architecture: 'x64', architecture: 'x64',
version, version,
source: `sha256:${path.basename(root)}`, source: `sha256:${path.basename(root)}`,
verification: 'disabled', verification: 'unverified',
path: jdkPath path: jdkPath
}; };
registerJdk(jdk); registerJdk(jdk);
+7 -12
View File
@@ -71,11 +71,8 @@ jest.unstable_mockModule('@actions/tool-cache', () => ({
})); }));
jest.unstable_mockModule('../../src/jdk-cache.js', () => ({ jest.unstable_mockModule('../../src/jdk-cache.js', () => ({
getJdkVerificationIdentity: jest.fn( getJdkVerificationIdentity: jest.fn((verified: boolean, key?: string) =>
(verified: boolean, enforced: boolean, key?: string) => verified ? (key ? 'verified:custom' : 'verified:bundled') : 'unverified'
verified
? `${enforced ? 'enforced' : 'check-and-warn'}:${key ? 'custom' : 'bundled'}`
: 'disabled'
), ),
registerJdk: jest.fn(), registerJdk: jest.fn(),
restoreJdk: jest.fn() restoreJdk: jest.fn()
@@ -398,10 +395,8 @@ describe('setupJava', () => {
beforeEach(() => { beforeEach(() => {
(jdkCache.getJdkVerificationIdentity as jest.Mock).mockImplementation( (jdkCache.getJdkVerificationIdentity as jest.Mock).mockImplementation(
(verified: boolean, enforced: boolean, key?: string) => (verified: boolean, key?: string) =>
verified verified ? (key ? 'verified:custom' : 'verified:bundled') : 'unverified'
? `${enforced ? 'enforced' : 'check-and-warn'}:${key ? 'custom' : 'bundled'}`
: 'disabled'
); );
spyGetToolcachePath = util.getToolcachePath as jest.Mock; spyGetToolcachePath = util.getToolcachePath as jest.Mock;
spyGetToolcachePath.mockImplementation( spyGetToolcachePath.mockImplementation(
@@ -831,7 +826,7 @@ describe('setupJava', () => {
expect(jdkCache.registerJdk).toHaveBeenCalledWith( expect(jdkCache.registerJdk).toHaveBeenCalledWith(
expect.objectContaining({ expect.objectContaining({
version: actualJavaVersion, version: actualJavaVersion,
verification: 'disabled' verification: 'unverified'
}) })
); );
}); });
@@ -891,7 +886,7 @@ describe('setupJava', () => {
architecture: 'x86', architecture: 'x86',
version: actualJavaVersion, version: actualJavaVersion,
source: `some/random_url/java/${actualJavaVersion}`, source: `some/random_url/java/${actualJavaVersion}`,
verification: 'disabled', verification: 'unverified',
path: path.join(toolCachePath, 'Java_Empty_jdk', actualJavaVersion) path: path.join(toolCachePath, 'Java_Empty_jdk', actualJavaVersion)
}); });
expect(downloadTool).not.toHaveBeenCalled(); expect(downloadTool).not.toHaveBeenCalled();
@@ -924,7 +919,7 @@ describe('setupJava', () => {
architecture: 'x86', architecture: 'x86',
version: actualJavaVersion, version: actualJavaVersion,
source: `some/random_url/java/${actualJavaVersion}`, source: `some/random_url/java/${actualJavaVersion}`,
verification: 'disabled', verification: 'unverified',
path: path.join(toolCachePath, 'Java_Empty_jdk', actualJavaVersion) path: path.join(toolCachePath, 'Java_Empty_jdk', actualJavaVersion)
}; };
expect(jdkCache.restoreJdk).toHaveBeenCalledWith(expectedIdentity); expect(jdkCache.restoreJdk).toHaveBeenCalledWith(expectedIdentity);
@@ -78,8 +78,6 @@ function response(
} }
describe('getAvailableVersions', () => { describe('getAvailableVersions', () => {
jest.setTimeout(10_000);
let spyHttpClient: any; let spyHttpClient: any;
let spyCoreError: any; let spyCoreError: any;
const originalGitHubToken = process.env.GITHUB_TOKEN; const originalGitHubToken = process.env.GITHUB_TOKEN;
@@ -58,7 +58,7 @@ jest.unstable_mockModule('@actions/tool-cache', () => ({
})); }));
jest.unstable_mockModule('../../src/jdk-cache.js', () => ({ jest.unstable_mockModule('../../src/jdk-cache.js', () => ({
getJdkVerificationIdentity: jest.fn(() => 'disabled'), getJdkVerificationIdentity: jest.fn(() => 'unverified'),
registerJdk: jest.fn(), registerJdk: jest.fn(),
restoreJdk: jest.fn() restoreJdk: jest.fn()
})); }));
@@ -106,7 +106,7 @@ describe('setupJava', () => {
beforeEach(() => { beforeEach(() => {
(jdkCache.getJdkVerificationIdentity as jest.Mock).mockReturnValue( (jdkCache.getJdkVerificationIdentity as jest.Mock).mockReturnValue(
'disabled' 'unverified'
); );
spyGetToolcachePath = util.getToolcachePath as jest.Mock; spyGetToolcachePath = util.getToolcachePath as jest.Mock;
spyGetToolcachePath.mockImplementation( spyGetToolcachePath.mockImplementation(
@@ -283,7 +283,7 @@ describe('setupJava', () => {
expect.objectContaining({ expect.objectContaining({
distribution: 'jdkfile', distribution: 'jdkfile',
version: actualJavaVersion, version: actualJavaVersion,
verification: 'disabled' verification: 'unverified'
}) })
); );
} finally { } finally {
@@ -398,12 +398,13 @@ describe('downloadTool', () => {
jest.restoreAllMocks(); jest.restoreAllMocks();
}); });
it('verifies signatures by default', async () => { it('verifies signature when enabled', async () => {
const signedDistribution = new MicrosoftDistributions({ const signedDistribution = new MicrosoftDistributions({
version: '17', version: '17',
architecture: 'x64', architecture: 'x64',
packageType: 'jdk', packageType: 'jdk',
checkLatest: false checkLatest: false,
verifySignature: true
}); });
await signedDistribution['downloadTool']({ await signedDistribution['downloadTool']({
@@ -444,64 +445,6 @@ describe('downloadTool', () => {
); );
}); });
it('warns with key rotation recovery guidance when default verification fails', async () => {
spyVerifySignature.mockRejectedValue(new Error('bad signature'));
const signedDistribution = new MicrosoftDistributions({
version: '17',
architecture: 'x64',
packageType: 'jdk',
checkLatest: false
});
await signedDistribution['downloadTool']({
version: '17.0.14+7',
url: 'https://example.com/jdk.tar.gz',
signatureUrl: 'https://example.com/jdk.tar.gz.sig'
});
expect(core.warning).toHaveBeenCalledWith(
expect.stringMatching(
/bad signature.*https:\/\/github\.com\/actions\/setup-java#download-integrity-and-signatures/
)
);
expect(spyExtractJdkFile).toHaveBeenCalled();
});
it('fails with recovery guidance when verification is explicitly enabled', async () => {
spyVerifySignature.mockRejectedValue(new Error('bad signature'));
const signedDistribution = new MicrosoftDistributions({
version: '17',
architecture: 'x64',
packageType: 'jdk',
checkLatest: false,
verifySignature: true
});
await expect(
signedDistribution['downloadTool']({
version: '17.0.14+7',
url: 'https://example.com/jdk.tar.gz',
signatureUrl: 'https://example.com/jdk.tar.gz.sig'
})
).rejects.toThrow(
/bad signature.*https:\/\/github\.com\/actions\/setup-java#download-integrity-and-signatures/
);
expect(spyExtractJdkFile).not.toHaveBeenCalled();
});
it('warns when the signature is missing during default verification', async () => {
await distribution['downloadTool']({
version: '17.0.14+7',
url: 'https://example.com/jdk.tar.gz'
});
expect(core.warning).toHaveBeenCalledWith(
"Input 'verify-signature' is enabled, but no signature URL was found for Microsoft Build of OpenJDK version 17.0.14+7."
);
expect(spyVerifySignature).not.toHaveBeenCalled();
expect(spyExtractJdkFile).toHaveBeenCalled();
});
it('fails when signature is missing and verification is enabled', async () => { it('fails when signature is missing and verification is enabled', async () => {
const signedDistribution = new MicrosoftDistributions({ const signedDistribution = new MicrosoftDistributions({
version: '17', version: '17',
@@ -73,7 +73,6 @@ jest.unstable_mockModule('../../src/util.js', () => ({
jest.unstable_mockModule('../../src/gpg.js', () => ({ jest.unstable_mockModule('../../src/gpg.js', () => ({
importKey: jest.fn(), importKey: jest.fn(),
removeGpgHome: jest.fn(), removeGpgHome: jest.fn(),
isGpgAvailable: jest.fn(),
verifyPackageSignature: jest.fn() verifyPackageSignature: jest.fn()
})); }));
@@ -438,7 +437,6 @@ describe('downloadTool', () => {
beforeEach(() => { beforeEach(() => {
spyDownloadTool = tc.downloadTool as jest.Mock; spyDownloadTool = tc.downloadTool as jest.Mock;
spyDownloadTool.mockResolvedValue('/tmp/jdk.tar.gz'); spyDownloadTool.mockResolvedValue('/tmp/jdk.tar.gz');
(gpg.isGpgAvailable as jest.Mock).mockResolvedValue(true);
spyVerifySignature = gpg.verifyPackageSignature as jest.Mock; spyVerifySignature = gpg.verifyPackageSignature as jest.Mock;
spyVerifySignature.mockResolvedValue(undefined); spyVerifySignature.mockResolvedValue(undefined);
spyExtractJdkFile = util.extractJdkFile as jest.Mock; spyExtractJdkFile = util.extractJdkFile as jest.Mock;
@@ -459,13 +457,14 @@ describe('downloadTool', () => {
jest.restoreAllMocks(); jest.restoreAllMocks();
}); });
it('verifies signatures by default', async () => { it('verifies signature when enabled', async () => {
const distribution = new TemurinDistribution( const distribution = new TemurinDistribution(
{ {
version: '17', version: '17',
architecture: 'x64', architecture: 'x64',
packageType: 'jdk', packageType: 'jdk',
checkLatest: false checkLatest: false,
verifySignature: true
}, },
TemurinImplementation.Hotspot TemurinImplementation.Hotspot
); );
@@ -483,154 +482,6 @@ describe('downloadTool', () => {
); );
}); });
it('does not verify signatures when explicitly disabled', async () => {
const distribution = new TemurinDistribution(
{
version: '17',
architecture: 'x64',
packageType: 'jdk',
checkLatest: false,
verifySignature: false
},
TemurinImplementation.Hotspot
);
await distribution['downloadTool']({
version: '17.0.14+7',
url: 'https://example.com/jdk.tar.gz',
signatureUrl: 'https://example.com/jdk.tar.gz.sig'
});
expect(spyVerifySignature).not.toHaveBeenCalled();
});
it('skips implicit signature verification when gpg is unavailable', async () => {
(gpg.isGpgAvailable as jest.Mock).mockResolvedValue(false);
const distribution = new TemurinDistribution(
{
version: '17',
architecture: 'x64',
packageType: 'jdk',
checkLatest: false
},
TemurinImplementation.Hotspot
);
await expect(
distribution['downloadTool']({
version: '17.0.14+7',
url: 'https://example.com/jdk.tar.gz',
signatureUrl: 'https://example.com/jdk.tar.gz.sig'
})
).resolves.toEqual({version: '17.0.14+7', path: '/tmp/toolcache'});
expect(spyVerifySignature).not.toHaveBeenCalled();
expect(core.warning).toHaveBeenCalledWith(
"Input 'verify-signature' is enabled, but gpg is not available."
);
});
it('fails when signature verification is explicitly enabled without gpg', async () => {
(gpg.isGpgAvailable as jest.Mock).mockResolvedValue(false);
const distribution = new TemurinDistribution(
{
version: '17',
architecture: 'x64',
packageType: 'jdk',
checkLatest: false,
verifySignature: true
},
TemurinImplementation.Hotspot
);
await expect(
distribution['downloadTool']({
version: '17.0.14+7',
url: 'https://example.com/jdk.tar.gz',
signatureUrl: 'https://example.com/jdk.tar.gz.sig'
})
).rejects.toThrow(
"Input 'verify-signature' is enabled, but gpg is not available."
);
expect(spyVerifySignature).not.toHaveBeenCalled();
});
it('warns when implicit signature verification fails', async () => {
spyVerifySignature.mockRejectedValue(new Error('bad signature'));
const distribution = new TemurinDistribution(
{
version: '17',
architecture: 'x64',
packageType: 'jdk',
checkLatest: false
},
TemurinImplementation.Hotspot
);
await expect(
distribution['downloadTool']({
version: '17.0.14+7',
url: 'https://example.com/jdk.tar.gz',
signatureUrl: 'https://example.com/jdk.tar.gz.sig'
})
).resolves.toEqual({version: '17.0.14+7', path: '/tmp/toolcache'});
expect(core.warning).toHaveBeenCalledWith(
expect.stringContaining(
'https://github.com/actions/setup-java#download-integrity-and-signatures'
)
);
});
it('fails when explicitly requested signature verification fails', async () => {
spyVerifySignature.mockRejectedValue(new Error('bad signature'));
const distribution = new TemurinDistribution(
{
version: '17',
architecture: 'x64',
packageType: 'jdk',
checkLatest: false,
verifySignature: true
},
TemurinImplementation.Hotspot
);
await expect(
distribution['downloadTool']({
version: '17.0.14+7',
url: 'https://example.com/jdk.tar.gz',
signatureUrl: 'https://example.com/jdk.tar.gz.sig'
})
).rejects.toThrow(
/Failed to verify signature for Temurin version 17\.0\.14\+7.*bad signature.*https:\/\/github\.com\/actions\/setup-java#download-integrity-and-signatures/
);
});
it('warns when a signature is missing and verification is implicit', async () => {
const distribution = new TemurinDistribution(
{
version: '17',
architecture: 'x64',
packageType: 'jdk',
checkLatest: false
},
TemurinImplementation.Hotspot
);
await expect(
distribution['downloadTool']({
version: '17.0.14+7',
url: 'https://example.com/jdk.tar.gz'
})
).resolves.toEqual({version: '17.0.14+7', path: '/tmp/toolcache'});
expect(core.warning).toHaveBeenCalledWith(
"Input 'verify-signature' is enabled, but no signature URL was found for Temurin version 17.0.14+7."
);
expect(spyVerifySignature).not.toHaveBeenCalled();
});
it('downloads and adds matching JMODs to the JDK', async () => { it('downloads and adds matching JMODs to the JDK', async () => {
spyDownloadTool spyDownloadTool
.mockResolvedValueOnce('/tmp/jdk.tar.gz') .mockResolvedValueOnce('/tmp/jdk.tar.gz')
@@ -648,8 +499,7 @@ describe('downloadTool', () => {
version: '25', version: '25',
architecture: 'x64', architecture: 'x64',
packageType: 'jdk+jmods', packageType: 'jdk+jmods',
checkLatest: false, checkLatest: false
verifySignature: false
}, },
TemurinImplementation.Hotspot TemurinImplementation.Hotspot
); );
+1 -28
View File
@@ -245,7 +245,7 @@ describe('gpg tests', () => {
expect.any(String), expect.any(String),
'--batch', '--batch',
'--import', '--import',
expect.stringContaining('public-key-0.asc') expect.stringContaining('public-key.asc')
], ],
expect.objectContaining({silent: true}) expect.objectContaining({silent: true})
); );
@@ -263,32 +263,5 @@ describe('gpg tests', () => {
expect.objectContaining({silent: true}) expect.objectContaining({silent: true})
); );
}); });
it('imports multiple bundled keys before verifying the package', async () => {
(tc.downloadTool as jest.Mock<any>).mockResolvedValue(
'/tmp/jdk.tar.gz.sig'
);
await gpg.verifyPackageSignature(
'/tmp/jdk.tar.gz',
'https://example.com/jdk.tar.gz.sig',
['public-key-a', 'public-key-b']
);
expect(exec.exec).toHaveBeenNthCalledWith(
1,
'gpg',
[
'--homedir',
expect.any(String),
'--batch',
'--import',
expect.stringContaining('public-key-0.asc'),
expect.stringContaining('public-key-1.asc')
],
expect.objectContaining({silent: true})
);
expect(exec.exec).toHaveBeenCalledTimes(2);
});
}); });
}); });
+18 -45
View File
@@ -43,7 +43,7 @@ const jdk = {
architecture: 'x64', architecture: 'x64',
version: '21.0.8+9', version: '21.0.8+9',
source: 'sha256:abc123', source: 'sha256:abc123',
verification: 'disabled', verification: 'unverified',
path: '/toolcache/Java_temurin_jdk/21.0.8-9' path: '/toolcache/Java_temurin_jdk/21.0.8-9'
}; };
@@ -117,59 +117,32 @@ describe('JDK cache', () => {
); );
}); });
it('separates verification policies and keys', () => { it('separates unverified, bundled-key, and custom-key caches', () => {
const disabled = getJdkVerificationIdentity(false, false); const unverified = getJdkVerificationIdentity(false);
const checkAndWarnBundled = getJdkVerificationIdentity(true, false); const bundled = getJdkVerificationIdentity(true);
const enforcedBundled = getJdkVerificationIdentity(true, true);
const customA = getJdkVerificationIdentity( const customA = getJdkVerificationIdentity(
true,
true, true,
'-----BEGIN PGP PUBLIC KEY BLOCK-----\r\nkey-a\r\n-----END PGP PUBLIC KEY BLOCK-----\r\n' '-----BEGIN PGP PUBLIC KEY BLOCK-----\r\nkey-a\r\n-----END PGP PUBLIC KEY BLOCK-----\r\n'
); );
const customANormalized = getJdkVerificationIdentity( const customANormalized = getJdkVerificationIdentity(
true,
true, true,
'-----BEGIN PGP PUBLIC KEY BLOCK-----\nkey-a\n-----END PGP PUBLIC KEY BLOCK-----' '-----BEGIN PGP PUBLIC KEY BLOCK-----\nkey-a\n-----END PGP PUBLIC KEY BLOCK-----'
); );
const customB = getJdkVerificationIdentity(true, true, 'different-key'); const customB = getJdkVerificationIdentity(true, 'different-key');
const checkAndWarnCustomA = getJdkVerificationIdentity(
true,
false,
'-----BEGIN PGP PUBLIC KEY BLOCK-----\nkey-a\n-----END PGP PUBLIC KEY BLOCK-----'
);
const customList = getJdkVerificationIdentity(true, true, [
'key-a',
'key-b'
]);
const customListWithDifferentBoundary = getJdkVerificationIdentity(
true,
true,
['key-ak', 'ey-b']
);
expect( expect(new Set([unverified, bundled, customA, customB])).toHaveProperty(
new Set([ 'size',
disabled, 4
checkAndWarnBundled, );
enforcedBundled,
customA,
customB
])
).toHaveProperty('size', 5);
expect(disabled).toBe('disabled');
expect(checkAndWarnBundled).toBe('check-and-warn:bundled');
expect(enforcedBundled).toBe('enforced:bundled');
expect(checkAndWarnCustomA).not.toBe(customA);
expect(customA).toBe(customANormalized); expect(customA).toBe(customANormalized);
expect(customA).not.toContain('key-a'); expect(customA).not.toContain('key-a');
expect(customList).not.toBe(customListWithDifferentBoundary);
expect( expect(
new Set( new Set(
[disabled, checkAndWarnBundled, enforcedBundled, customA, customB].map( [unverified, bundled, customA, customB].map(verification =>
verification => buildJdkCacheKey({...jdk, verification}) buildJdkCacheKey({...jdk, verification})
) )
) )
).toHaveProperty('size', 5); ).toHaveProperty('size', 4);
}); });
it('restores and records an exact JDK cache hit', async () => { it('restores and records an exact JDK cache hit', async () => {
@@ -237,12 +210,12 @@ describe('JDK cache', () => {
it('saves only the key matching the installation that occupies the path', async () => { it('saves only the key matching the installation that occupies the path', async () => {
const jdkPath = createInstallation(); const jdkPath = createInstallation();
const enforced = {...jdk, path: jdkPath, verification: 'enforced:bundled'}; const verified = {...jdk, path: jdkPath, verification: 'verified:bundled'};
const disabled = {...jdk, path: jdkPath}; const unverified = {...jdk, path: jdkPath};
registerJdk(enforced); registerJdk(verified);
writeInstallation(jdkPath, 'force-downloaded-without-verification'); writeInstallation(jdkPath, 'force-downloaded-without-verification');
registerJdk(disabled); registerJdk(unverified);
(core.getState as jest.Mock).mockReturnValue(lastState()); (core.getState as jest.Mock).mockReturnValue(lastState());
(cache.saveCache as jest.Mock).mockResolvedValue(1); (cache.saveCache as jest.Mock).mockResolvedValue(1);
@@ -250,11 +223,11 @@ describe('JDK cache', () => {
expect(cache.saveCache).not.toHaveBeenCalledWith( expect(cache.saveCache).not.toHaveBeenCalledWith(
[jdkPath], [jdkPath],
buildJdkCacheKey(enforced) buildJdkCacheKey(verified)
); );
expect(cache.saveCache).toHaveBeenCalledWith( expect(cache.saveCache).toHaveBeenCalledWith(
[jdkPath], [jdkPath],
buildJdkCacheKey(disabled) buildJdkCacheKey(unverified)
); );
}); });
+2 -32
View File
@@ -161,37 +161,6 @@ describe('setup action orchestration', () => {
expect(factory.getJavaDistribution).not.toHaveBeenCalled(); expect(factory.getJavaDistribution).not.toHaveBeenCalled();
}); });
it.each([
['temurin', undefined, undefined],
['zulu', undefined, undefined],
['temurin', false, false],
['zulu', true, true]
])(
'passes signature verification input for %s with explicit value %s as %s',
async (distribution, explicitValue, expectedValue) => {
inputs.set('distribution', distribution);
multilineInputs.set('java-version', ['21']);
if (explicitValue !== undefined) {
inputs.set('verify-signature', String(explicitValue));
booleanInputs.set('verify-signature', explicitValue);
}
(factory.getJavaDistribution as jest.Mock).mockReturnValue({
setupJava: jest.fn(async () => ({
version: '21.0.4+7',
path: '/opt/java/21'
}))
});
await run();
expect(factory.getJavaDistribution).toHaveBeenCalledWith(
distribution,
expect.objectContaining({verifySignature: expectedValue}),
''
);
}
);
it('requires distribution when it cannot be inferred from the version file', async () => { it('requires distribution when it cannot be inferred from the version file', async () => {
inputs.set('java-version-file', '.java-version'); inputs.set('java-version-file', '.java-version');
(fs.readFileSync as jest.Mock).mockReturnValue(Buffer.from('21')); (fs.readFileSync as jest.Mock).mockReturnValue(Buffer.from('21'));
@@ -231,6 +200,7 @@ describe('setup action orchestration', () => {
booleanInputs.set('check-latest', true); booleanInputs.set('check-latest', true);
booleanInputs.set('force-download', true); booleanInputs.set('force-download', true);
booleanInputs.set('set-default', false); booleanInputs.set('set-default', false);
booleanInputs.set('verify-signature', true);
inputs.set('verify-signature-public-key', 'public-key'); inputs.set('verify-signature-public-key', 'public-key');
(fs.readFileSync as jest.Mock).mockReturnValue( (fs.readFileSync as jest.Mock).mockReturnValue(
Buffer.from('java=21.0.5-tem') Buffer.from('java=21.0.5-tem')
@@ -262,7 +232,7 @@ describe('setup action orchestration', () => {
forceDownload: true, forceDownload: true,
cacheJdk: false, cacheJdk: false,
setDefault: false, setDefault: false,
verifySignature: undefined, verifySignature: true,
verifySignaturePublicKey: 'public-key' verifySignaturePublicKey: 'public-key'
}, },
'/tmp/java.tar.gz' '/tmp/java.tar.gz'
+3 -2
View File
@@ -39,10 +39,11 @@ inputs:
required: false required: false
default: true default: true
verify-signature: verify-signature:
description: 'Check downloaded Java package signatures when supported by the selected distribution. When omitted, failures produce warnings. Explicitly setting this to true enforces verification and makes failures fatal, including failures caused by an unexpected vendor signing-key rotation.' description: 'Verify downloaded Java package signatures when supported by the selected distribution'
required: false required: false
default: false
verify-signature-public-key: verify-signature-public-key:
description: 'One or more ASCII-armored GPG public keys used to verify downloaded package signatures. Concatenate multiple armored key blocks. Custom keys replace the bundled keys for the selected distribution.' description: 'ASCII-armored GPG public key used to verify the downloaded package signature. Overrides the default bundled key for the selected distribution.'
required: false required: false
server-id: server-id:
description: 'ID of the distributionManagement repository in the pom.xml description: 'ID of the distributionManagement repository in the pom.xml
+6 -15
View File
@@ -122,25 +122,16 @@ function getInstallationIdentity(jdkPath, architecture) {
return undefined; return undefined;
} }
} }
function getJdkVerificationIdentity(verifySignature, enforceSignatureVerification, publicKey) { function getJdkVerificationIdentity(verifySignature, publicKey) {
if (!verifySignature) { if (!verifySignature) {
return 'disabled'; return 'unverified';
} }
const verificationPolicy = enforceSignatureVerification
? 'enforced'
: 'check-and-warn';
if (!publicKey) { if (!publicKey) {
return `${verificationPolicy}:bundled`; return 'verified:bundled';
} }
const publicKeys = Array.isArray(publicKey) ? publicKey : [publicKey]; const normalizedKey = publicKey.replace(/\r\n?/g, '\n').trim();
const normalizedKeys = publicKeys.map(key => key.replace(/\r\n?/g, '\n').trim()); const fingerprint = createHash('sha256').update(normalizedKey).digest('hex');
const fingerprintSource = Array.isArray(publicKey) return `verified:custom:sha256:${fingerprint}`;
? normalizedKeys.map(key => `${Buffer.byteLength(key)}:${key}`).join('')
: normalizedKeys[0];
const fingerprint = createHash('sha256')
.update(fingerprintSource)
.digest('hex');
return `${verificationPolicy}:custom:sha256:${fingerprint}`;
} }
async function saveJdkCaches() { async function saveJdkCaches() {
const state = lib_core/* getState */.Gu(STATE_JDK_CACHES); const state = lib_core/* getState */.Gu(STATE_JDK_CACHES);
+3 -58
View File
@@ -18680,26 +18680,12 @@ class XmlNode {
this.child.push({ [node.tagname]: node.child }); this.child.push({ [node.tagname]: node.child });
} }
// if requested, add the startIndex // if requested, add the startIndex
this.addStartIndex(startIndex);
}
addStartIndex(startIndex) {
if (startIndex !== undefined) { if (startIndex !== undefined) {
// Note: for now we just overwrite the metadata. If we had more complex metadata, // Note: for now we just overwrite the metadata. If we had more complex metadata,
// we might need to do an object append here: metadata = { ...metadata, startIndex } // we might need to do an object append here: metadata = { ...metadata, startIndex }
this.child[this.child.length - 1][METADATA_SYMBOL] = { startIndex }; this.child[this.child.length - 1][METADATA_SYMBOL] = { startIndex };
} }
} }
addEndIndex(endIndex) {
const lastChild = this.child[this.child.length - 1];
// endIndex is write-once: when updateTag drops a node, the last child is a
// previously completed sibling whose endIndex must not be overwritten
if (lastChild !== undefined && lastChild[METADATA_SYMBOL] !== undefined
&& lastChild[METADATA_SYMBOL].endIndex === undefined) {
lastChild[METADATA_SYMBOL].endIndex = endIndex;
}
}
/** symbol used for metadata */ /** symbol used for metadata */
static getMetaDataSymbol() { static getMetaDataSymbol() {
return METADATA_SYMBOL; return METADATA_SYMBOL;
@@ -18732,23 +18718,8 @@ class DocTypeReader {
i = i + 9; i = i + 9;
let angleBracketsCount = 1; let angleBracketsCount = 1;
let hasBody = false, comment = false; let hasBody = false, comment = false;
let quoteChar = null; // tracks an open SYSTEM/PUBLIC literal before the '[' body
let exp = ""; let exp = "";
for (; i < xmlData.length; i++) { for (; i < xmlData.length; i++) {
// Inside a quoted external-identifier literal — XML allows '<'
// and '>' as plain data here, so they must not be interpreted
// as DOCTYPE structure until the matching quote closes.
if (quoteChar !== null) {
if (xmlData[i] === quoteChar) quoteChar = null;
exp += xmlData[i];
continue;
}
if (!hasBody && !comment && (xmlData[i] === '"' || xmlData[i] === "'")) {
quoteChar = xmlData[i];
exp += xmlData[i];
continue;
}
if (xmlData[i] === '<' && !comment) { //Determine the tag type if (xmlData[i] === '<' && !comment) { //Determine the tag type
if (hasBody && hasSeq(xmlData, "!ENTITY", i)) { if (hasBody && hasSeq(xmlData, "!ENTITY", i)) {
i += 7; i += 7;
@@ -18803,7 +18774,7 @@ class DocTypeReader {
exp += xmlData[i]; exp += xmlData[i];
} }
} }
if (quoteChar !== null || angleBracketsCount !== 0) { if (angleBracketsCount !== 0) {
throw new Error(`Unclosed DOCTYPE`); throw new Error(`Unclosed DOCTYPE`);
} }
} else { } else {
@@ -19518,11 +19489,7 @@ function resolveEnotation(str, trimmedStr, options) {
*/ */
function trimZeros(numStr) { function trimZeros(numStr) {
if (numStr && numStr.indexOf(".") !== -1) {//float if (numStr && numStr.indexOf(".") !== -1) {//float
//remove ending zeros without the O(n^2) backtracking that /0+$/ hits numStr = numStr.replace(/0+$/, ""); //remove ending zeros
//when the string doesn't end in 0 but has a long internal zero-run
let end = numStr.length;
while (end > 0 && numStr.charCodeAt(end - 1) === 48 /* '0' */) end--;
numStr = numStr.slice(0, end);
if (numStr === ".") numStr = "0"; if (numStr === ".") numStr = "0";
else if (numStr[0] === ".") numStr = "0" + numStr; else if (numStr[0] === ".") numStr = "0" + numStr;
else if (numStr[numStr.length - 1] === ".") numStr = numStr.substring(0, numStr.length - 1); else if (numStr[numStr.length - 1] === ".") numStr = numStr.substring(0, numStr.length - 1);
@@ -22998,12 +22965,7 @@ const parseXml = function (xmlData) {
this.matcher.pop(); this.matcher.pop();
this.isCurrentNodeStopNode = false; // Reset flag when closing tag this.isCurrentNodeStopNode = false; // Reset flag when closing tag
//a closing tag with no matching opening tag leaves the stack empty currentNode = this.tagsNodeStack.pop();//avoid recursion, set the parent tag scope
currentNode = this.tagsNodeStack.pop() || xmlObj;//avoid recursion, set the parent tag scope
if (options.captureMetaData && currentNode) {
currentNode.addEndIndex(closeIndex + 1);
}
textData = ""; textData = "";
i = closeIndex; i = closeIndex;
} else if (c1 === 63) { //'?' } else if (c1 === 63) { //'?'
@@ -23029,11 +22991,6 @@ const parseXml = function (xmlData) {
childNode[":@"] = attsMap childNode[":@"] = attsMap
} }
this.addChild(currentNode, childNode, this.readonlyMatcher, i); this.addChild(currentNode, childNode, this.readonlyMatcher, i);
if (options.captureMetaData) {
// closeIndex points at '?' of the closing '?>'
currentNode.addEndIndex(tagData.closeIndex + 2);
}
} }
@@ -23198,10 +23155,6 @@ const parseXml = function (xmlData) {
this.isCurrentNodeStopNode = false; // Reset flag this.isCurrentNodeStopNode = false; // Reset flag
this.addChild(currentNode, childNode, this.readonlyMatcher, startIndex); this.addChild(currentNode, childNode, this.readonlyMatcher, startIndex);
if (options.captureMetaData) {
currentNode.addEndIndex(i + 1);
}
} else { } else {
//selfClosing tag //selfClosing tag
if (isSelfClosing) { if (isSelfClosing) {
@@ -23212,10 +23165,6 @@ const parseXml = function (xmlData) {
childNode[":@"] = prefixedAttrs; childNode[":@"] = prefixedAttrs;
} }
this.addChild(currentNode, childNode, this.readonlyMatcher, startIndex); this.addChild(currentNode, childNode, this.readonlyMatcher, startIndex);
if (options.captureMetaData) {
currentNode.addEndIndex(closeIndex + 1);
}
this.matcher.pop(); // Pop self-closing tag this.matcher.pop(); // Pop self-closing tag
this.isCurrentNodeStopNode = false; // Reset flag this.isCurrentNodeStopNode = false; // Reset flag
} }
@@ -23225,10 +23174,6 @@ const parseXml = function (xmlData) {
childNode[":@"] = prefixedAttrs; childNode[":@"] = prefixedAttrs;
} }
this.addChild(currentNode, childNode, this.readonlyMatcher, startIndex); this.addChild(currentNode, childNode, this.readonlyMatcher, startIndex);
if (options.captureMetaData) {
currentNode.addEndIndex(result.closeIndex + 1);
}
this.matcher.pop(); // Pop unpaired tag this.matcher.pop(); // Pop unpaired tag
this.isCurrentNodeStopNode = false; // Reset flag this.isCurrentNodeStopNode = false; // Reset flag
i = result.closeIndex; i = result.closeIndex;
+8 -18
View File
@@ -30774,7 +30774,7 @@ module.exports = {
/* harmony export */ gk: () => (/* binding */ INPUT_CACHE), /* harmony export */ gk: () => (/* binding */ INPUT_CACHE),
/* harmony export */ wG: () => (/* binding */ INPUT_JOB_STATUS) /* harmony export */ wG: () => (/* binding */ INPUT_JOB_STATUS)
/* harmony export */ }); /* harmony export */ });
/* unused harmony exports MACOS_JAVA_CONTENT_POSTFIX, INPUT_JAVA_VERSION, INPUT_JAVA_VERSION_FILE, INPUT_ARCHITECTURE, INPUT_JAVA_PACKAGE, INPUT_DISTRIBUTION, INPUT_JDK_FILE, INPUT_JDK_FILE_DEPRECATED, INPUT_CHECK_LATEST, INPUT_FORCE_DOWNLOAD, INPUT_SET_DEFAULT, INPUT_PROBLEM_MATCHER, INPUT_VERIFY_SIGNATURE, INPUT_VERIFY_SIGNATURE_PUBLIC_KEY, SIGNATURE_VERIFICATION_DOCUMENTATION_URL, SIGNATURE_VERIFICATION_FAILURE_HELP, INPUT_MVN_SERVER_CREDENTIALS, INPUT_MVN_REPOSITORIES, INPUT_MVN_REPOSITORIES_INCLUDE_CENTRAL, INPUT_MVN_REPOSITORIES_PRIORITIZE_CENTRAL, INPUT_SERVER_ID, INPUT_SERVER_USERNAME_ENV_VAR, INPUT_SERVER_PASSWORD_ENV_VAR, INPUT_SERVER_USERNAME_DEPRECATED, INPUT_SERVER_PASSWORD_DEPRECATED, INPUT_SETTINGS_PATH, INPUT_OVERWRITE_SETTINGS, INPUT_GPG_PRIVATE_KEY, INPUT_GPG_PASSPHRASE_ENV_VAR, INPUT_GPG_PASSPHRASE_DEPRECATED, INPUT_DEFAULT_SERVER_USERNAME, INPUT_DEFAULT_SERVER_PASSWORD, INPUT_DEFAULT_GPG_PRIVATE_KEY, INPUT_DEFAULT_GPG_PASSPHRASE, MAVEN_GPG_PASSPHRASE_DEFAULT_ENV, GPG_PASSPHRASE_PROFILE_ID, MAVEN_REPOSITORIES_PROFILE_ID, MAVEN_CENTRAL_REPOSITORY_ID, MAVEN_CENTRAL_REPOSITORY_URL, INPUT_CACHE_DEPENDENCY_PATH, INPUT_CACHE_PATH, M2_DIR, MVN_SETTINGS_FILE, MVN_TOOLCHAINS_FILE, INPUT_MVN_TOOLCHAIN_ID, INPUT_MVN_TOOLCHAIN_VENDOR, INPUT_SHOW_DOWNLOAD_PROGRESS, MAVEN_ARGS_ENV, MAVEN_NO_TRANSFER_PROGRESS_FLAG, MAVEN_NO_TRANSFER_PROGRESS_LONG_FLAG, DISTRIBUTIONS_ONLY_MAJOR_VERSION */ /* unused harmony exports MACOS_JAVA_CONTENT_POSTFIX, INPUT_JAVA_VERSION, INPUT_JAVA_VERSION_FILE, INPUT_ARCHITECTURE, INPUT_JAVA_PACKAGE, INPUT_DISTRIBUTION, INPUT_JDK_FILE, INPUT_JDK_FILE_DEPRECATED, INPUT_CHECK_LATEST, INPUT_FORCE_DOWNLOAD, INPUT_SET_DEFAULT, INPUT_PROBLEM_MATCHER, INPUT_VERIFY_SIGNATURE, INPUT_VERIFY_SIGNATURE_PUBLIC_KEY, INPUT_MVN_SERVER_CREDENTIALS, INPUT_MVN_REPOSITORIES, INPUT_MVN_REPOSITORIES_INCLUDE_CENTRAL, INPUT_MVN_REPOSITORIES_PRIORITIZE_CENTRAL, INPUT_SERVER_ID, INPUT_SERVER_USERNAME_ENV_VAR, INPUT_SERVER_PASSWORD_ENV_VAR, INPUT_SERVER_USERNAME_DEPRECATED, INPUT_SERVER_PASSWORD_DEPRECATED, INPUT_SETTINGS_PATH, INPUT_OVERWRITE_SETTINGS, INPUT_GPG_PRIVATE_KEY, INPUT_GPG_PASSPHRASE_ENV_VAR, INPUT_GPG_PASSPHRASE_DEPRECATED, INPUT_DEFAULT_SERVER_USERNAME, INPUT_DEFAULT_SERVER_PASSWORD, INPUT_DEFAULT_GPG_PRIVATE_KEY, INPUT_DEFAULT_GPG_PASSPHRASE, MAVEN_GPG_PASSPHRASE_DEFAULT_ENV, GPG_PASSPHRASE_PROFILE_ID, MAVEN_REPOSITORIES_PROFILE_ID, MAVEN_CENTRAL_REPOSITORY_ID, MAVEN_CENTRAL_REPOSITORY_URL, INPUT_CACHE_DEPENDENCY_PATH, INPUT_CACHE_PATH, M2_DIR, MVN_SETTINGS_FILE, MVN_TOOLCHAINS_FILE, INPUT_MVN_TOOLCHAIN_ID, INPUT_MVN_TOOLCHAIN_VENDOR, INPUT_SHOW_DOWNLOAD_PROGRESS, MAVEN_ARGS_ENV, MAVEN_NO_TRANSFER_PROGRESS_FLAG, MAVEN_NO_TRANSFER_PROGRESS_LONG_FLAG, DISTRIBUTIONS_ONLY_MAJOR_VERSION */
const MACOS_JAVA_CONTENT_POSTFIX = 'Contents/Home'; const MACOS_JAVA_CONTENT_POSTFIX = 'Contents/Home';
const INPUT_JAVA_VERSION = 'java-version'; const INPUT_JAVA_VERSION = 'java-version';
const INPUT_JAVA_VERSION_FILE = 'java-version-file'; const INPUT_JAVA_VERSION_FILE = 'java-version-file';
@@ -30789,8 +30789,6 @@ const INPUT_SET_DEFAULT = 'set-default';
const INPUT_PROBLEM_MATCHER = 'problem-matcher'; const INPUT_PROBLEM_MATCHER = 'problem-matcher';
const INPUT_VERIFY_SIGNATURE = 'verify-signature'; const INPUT_VERIFY_SIGNATURE = 'verify-signature';
const INPUT_VERIFY_SIGNATURE_PUBLIC_KEY = 'verify-signature-public-key'; const INPUT_VERIFY_SIGNATURE_PUBLIC_KEY = 'verify-signature-public-key';
const SIGNATURE_VERIFICATION_DOCUMENTATION_URL = 'https://github.com/actions/setup-java#download-integrity-and-signatures';
const SIGNATURE_VERIFICATION_FAILURE_HELP = (/* unused pure expression or super */ null && (`If this is a legitimate vendor signing-key rotation, see ${SIGNATURE_VERIFICATION_DOCUMENTATION_URL} for instructions to configure the updated public key or temporarily disable signature verification.`));
const INPUT_MVN_SERVER_CREDENTIALS = 'mvn-server-credentials'; const INPUT_MVN_SERVER_CREDENTIALS = 'mvn-server-credentials';
const INPUT_MVN_REPOSITORIES = 'mvn-repositories'; const INPUT_MVN_REPOSITORIES = 'mvn-repositories';
const INPUT_MVN_REPOSITORIES_INCLUDE_CENTRAL = 'mvn-repositories-include-central'; const INPUT_MVN_REPOSITORIES_INCLUDE_CENTRAL = 'mvn-repositories-include-central';
@@ -35577,9 +35575,6 @@ function _unique(values) {
/******/ __nccwpck_require__.m = __webpack_modules__; /******/ __nccwpck_require__.m = __webpack_modules__;
/******/ /******/
/************************************************************************/ /************************************************************************/
/******/ /* webpack/runtime/asset-relocator-loader */
/******/ if (typeof __nccwpck_require__ !== 'undefined') __nccwpck_require__.ab = decodeURIComponent(new URL('.', import.meta.url).pathname).slice(import.meta.url.match(/^file:\/\/\/\w:/) ? 1 : 0, -1) + "/";
/******/
/******/ /* webpack/runtime/compat get default export */ /******/ /* webpack/runtime/compat get default export */
/******/ (() => { /******/ (() => {
/******/ // getDefaultExport function for compatibility with non-harmony modules /******/ // getDefaultExport function for compatibility with non-harmony modules
@@ -35672,6 +35667,10 @@ function _unique(values) {
/******/ }; /******/ };
/******/ })(); /******/ })();
/******/ /******/
/******/ /* webpack/runtime/compat */
/******/
/******/ if (typeof __nccwpck_require__ !== 'undefined') __nccwpck_require__.ab = new URL('.', import.meta.url).pathname.slice(import.meta.url.match(/^file:\/\/\/\w:/) ? 1 : 0, -1) + "/";
/******/
/******/ /* webpack/runtime/import chunk loading */ /******/ /* webpack/runtime/import chunk loading */
/******/ (() => { /******/ (() => {
/******/ // no baseURI /******/ // no baseURI
@@ -35769,9 +35768,6 @@ var src_util = __nccwpck_require__(4527);
const GPG_HOME_PREFIX = 'setup-java-gpg-'; const GPG_HOME_PREFIX = 'setup-java-gpg-';
const VERIFY_GPG_HOME_PREFIX = 'verify-signature-gpg-home-'; const VERIFY_GPG_HOME_PREFIX = 'verify-signature-gpg-home-';
async function isGpgAvailable() {
return Boolean(await io.which('gpg', false));
}
// Convert a Windows path (D:\a\_temp\...) to a POSIX path (/d/a/_temp/...). // Convert a Windows path (D:\a\_temp\...) to a POSIX path (/d/a/_temp/...).
// The Git-bundled GPG on Windows (MSYS2-based) uses POSIX path conventions // The Git-bundled GPG on Windows (MSYS2-based) uses POSIX path conventions
// internally. Passing Windows paths with backslashes can cause fatal GPG errors // internally. Passing Windows paths with backslashes can cause fatal GPG errors
@@ -35855,21 +35851,15 @@ async function verifyPackageSignature(archivePath, signatureUrl, publicKeyConten
throw new Error(`Failed to create temporary GPG home directory for signature verification: ${error.message}`, { cause: error }); throw new Error(`Failed to create temporary GPG home directory for signature verification: ${error.message}`, { cause: error });
} }
try { try {
const publicKeys = Array.isArray(publicKeyContent) const publicKeyFile = path.join(gpgHome, 'public-key.asc');
? publicKeyContent fs.writeFileSync(publicKeyFile, publicKeyContent, { encoding: 'utf-8' });
: [publicKeyContent];
const publicKeyFiles = publicKeys.map((publicKey, index) => {
const publicKeyFile = path.join(gpgHome, `public-key-${index}.asc`);
fs.writeFileSync(publicKeyFile, publicKey, { encoding: 'utf-8' });
return toGpgPath(publicKeyFile);
});
const options = { silent: true }; const options = { silent: true };
await exec.exec('gpg', [ await exec.exec('gpg', [
'--homedir', '--homedir',
toGpgPath(gpgHome), toGpgPath(gpgHome),
'--batch', '--batch',
'--import', '--import',
...publicKeyFiles toGpgPath(publicKeyFile)
], options); ], options);
await exec.exec('gpg', [ await exec.exec('gpg', [
'--homedir', '--homedir',
+1 -1
View File
@@ -65,7 +65,7 @@ class LocalDistribution extends _base_installer_js__WEBPACK_IMPORTED_MODULE_3__/
architecture: this.architecture, architecture: this.architecture,
version: this.version, version: this.version,
source, source,
verification: getJdkVerificationIdentity(false, false), verification: getJdkVerificationIdentity(false),
path: this.getJdkCachePath(this.version) path: this.getJdkCachePath(this.version)
}; };
} }
+5 -26
View File
@@ -42,8 +42,6 @@ Fa133tP85xzJEq1XeXm8WeLFo2wV
=rHCS =rHCS
-----END PGP PUBLIC KEY BLOCK-----`; -----END PGP PUBLIC KEY BLOCK-----`;
// EXTERNAL MODULE: ./src/constants.ts
var constants = __webpack_require__(7242);
// EXTERNAL MODULE: ./node_modules/@actions/core/lib/core.js + 7 modules // EXTERNAL MODULE: ./node_modules/@actions/core/lib/core.js + 7 modules
var core = __webpack_require__(3838); var core = __webpack_require__(3838);
// EXTERNAL MODULE: ./node_modules/@actions/tool-cache/lib/tool-cache.js + 2 modules // EXTERNAL MODULE: ./node_modules/@actions/tool-cache/lib/tool-cache.js + 2 modules
@@ -64,7 +62,6 @@ var external_path_default = /*#__PURE__*/__webpack_require__.n(external_path_);
class MicrosoftDistributions extends base_installer/* JavaBase */.O { class MicrosoftDistributions extends base_installer/* JavaBase */.O {
constructor(installerOptions) { constructor(installerOptions) {
super('Microsoft', installerOptions); super('Microsoft', installerOptions);
@@ -73,7 +70,6 @@ class MicrosoftDistributions extends base_installer/* JavaBase */.O {
core/* info */.pq(`Downloading Java ${javaRelease.version} (${this.distribution}) from ${javaRelease.url} ...`); core/* info */.pq(`Downloading Java ${javaRelease.version} (${this.distribution}) from ${javaRelease.url} ...`);
let javaArchivePath = await this.downloadAndVerify(javaRelease); let javaArchivePath = await this.downloadAndVerify(javaRelease);
if (this.verifySignature) { if (this.verifySignature) {
try {
if (!javaRelease.signatureUrl) { if (!javaRelease.signatureUrl) {
throw new Error(`Input 'verify-signature' is enabled, but no signature URL was found for Microsoft Build of OpenJDK version ${javaRelease.version}.`); throw new Error(`Input 'verify-signature' is enabled, but no signature URL was found for Microsoft Build of OpenJDK version ${javaRelease.version}.`);
} }
@@ -82,14 +78,7 @@ class MicrosoftDistributions extends base_installer/* JavaBase */.O {
await gpg/* verifyPackageSignature */.Yi(javaArchivePath, javaRelease.signatureUrl, this.verifySignaturePublicKey ?? MICROSOFT_PUBLIC_KEY); await gpg/* verifyPackageSignature */.Yi(javaArchivePath, javaRelease.signatureUrl, this.verifySignaturePublicKey ?? MICROSOFT_PUBLIC_KEY);
} }
catch (error) { catch (error) {
throw new Error(`Failed to verify signature for Microsoft Build of OpenJDK version ${javaRelease.version}. Signature URL: ${javaRelease.signatureUrl}. Error: ${error.message} ${constants/* SIGNATURE_VERIFICATION_FAILURE_HELP */.kQ}`, { cause: error }); throw new Error(`Failed to verify signature for Microsoft Build of OpenJDK version ${javaRelease.version}. Signature URL: ${javaRelease.signatureUrl}. Error: ${error.message}`, { cause: error });
}
}
catch (error) {
if (this.verifySignatureExplicitlyRequested) {
throw error;
}
core/* warning */.$e(error instanceof Error ? error.message : `Unknown error: ${error}`);
} }
} }
core/* info */.pq(`Extracting Java archive...`); core/* info */.pq(`Extracting Java archive...`);
@@ -178,8 +167,7 @@ class MicrosoftDistributions extends base_installer/* JavaBase */.O {
/* harmony export */ Fh: () => (/* binding */ importKey), /* harmony export */ Fh: () => (/* binding */ importKey),
/* harmony export */ Yi: () => (/* binding */ verifyPackageSignature), /* harmony export */ Yi: () => (/* binding */ verifyPackageSignature),
/* harmony export */ mS: () => (/* binding */ removeGpgHome), /* harmony export */ mS: () => (/* binding */ removeGpgHome),
/* harmony export */ nY: () => (/* binding */ toGpgPath), /* harmony export */ nY: () => (/* binding */ toGpgPath)
/* harmony export */ o6: () => (/* binding */ isGpgAvailable)
/* harmony export */ }); /* harmony export */ });
/* unused harmony export GPG_HOME_PREFIX */ /* unused harmony export GPG_HOME_PREFIX */
/* harmony import */ var fs__WEBPACK_IMPORTED_MODULE_0__ = __webpack_require__(9896); /* harmony import */ var fs__WEBPACK_IMPORTED_MODULE_0__ = __webpack_require__(9896);
@@ -201,9 +189,6 @@ class MicrosoftDistributions extends base_installer/* JavaBase */.O {
const GPG_HOME_PREFIX = 'setup-java-gpg-'; const GPG_HOME_PREFIX = 'setup-java-gpg-';
const VERIFY_GPG_HOME_PREFIX = 'verify-signature-gpg-home-'; const VERIFY_GPG_HOME_PREFIX = 'verify-signature-gpg-home-';
async function isGpgAvailable() {
return Boolean(await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .which */ .K7('gpg', false));
}
// Convert a Windows path (D:\a\_temp\...) to a POSIX path (/d/a/_temp/...). // Convert a Windows path (D:\a\_temp\...) to a POSIX path (/d/a/_temp/...).
// The Git-bundled GPG on Windows (MSYS2-based) uses POSIX path conventions // The Git-bundled GPG on Windows (MSYS2-based) uses POSIX path conventions
// internally. Passing Windows paths with backslashes can cause fatal GPG errors // internally. Passing Windows paths with backslashes can cause fatal GPG errors
@@ -287,21 +272,15 @@ async function verifyPackageSignature(archivePath, signatureUrl, publicKeyConten
throw new Error(`Failed to create temporary GPG home directory for signature verification: ${error.message}`, { cause: error }); throw new Error(`Failed to create temporary GPG home directory for signature verification: ${error.message}`, { cause: error });
} }
try { try {
const publicKeys = Array.isArray(publicKeyContent) const publicKeyFile = path__WEBPACK_IMPORTED_MODULE_1__.join(gpgHome, 'public-key.asc');
? publicKeyContent fs__WEBPACK_IMPORTED_MODULE_0__.writeFileSync(publicKeyFile, publicKeyContent, { encoding: 'utf-8' });
: [publicKeyContent];
const publicKeyFiles = publicKeys.map((publicKey, index) => {
const publicKeyFile = path__WEBPACK_IMPORTED_MODULE_1__.join(gpgHome, `public-key-${index}.asc`);
fs__WEBPACK_IMPORTED_MODULE_0__.writeFileSync(publicKeyFile, publicKey, { encoding: 'utf-8' });
return toGpgPath(publicKeyFile);
});
const options = { silent: true }; const options = { silent: true };
await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpg', [ await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpg', [
'--homedir', '--homedir',
toGpgPath(gpgHome), toGpgPath(gpgHome),
'--batch', '--batch',
'--import', '--import',
...publicKeyFiles toGpgPath(publicKeyFile)
], options); ], options);
await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpg', [ await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpg', [
'--homedir', '--homedir',
+2 -6
View File
@@ -226,7 +226,6 @@ class JavaBase {
floatingVersionVerified = false; floatingVersionVerified = false;
setDefault; setDefault;
verifySignature; verifySignature;
verifySignatureExplicitlyRequested;
verifySignaturePublicKey; verifySignaturePublicKey;
constructor(distribution, installerOptions) { constructor(distribution, installerOptions) {
this.distribution = distribution; this.distribution = distribution;
@@ -245,10 +244,7 @@ class JavaBase {
installerOptions.setDefault !== undefined installerOptions.setDefault !== undefined
? installerOptions.setDefault ? installerOptions.setDefault
: true; : true;
this.verifySignature = this.verifySignature = installerOptions.verifySignature ?? false;
installerOptions.verifySignature ?? this.supportsSignatureVerification();
this.verifySignatureExplicitlyRequested =
installerOptions.verifySignature === true;
this.verifySignaturePublicKey = installerOptions.verifySignaturePublicKey; this.verifySignaturePublicKey = installerOptions.verifySignaturePublicKey;
} }
async downloadAndVerify(javaRelease) { async downloadAndVerify(javaRelease) {
@@ -484,7 +480,7 @@ class JavaBase {
architecture: this.architecture, architecture: this.architecture,
version: javaRelease.version, version: javaRelease.version,
source: this.getJdkReleaseIdentity(javaRelease), source: this.getJdkReleaseIdentity(javaRelease),
verification: getJdkVerificationIdentity(this.verifySignature, this.verifySignatureExplicitlyRequested, this.verifySignaturePublicKey), verification: getJdkVerificationIdentity(this.verifySignature, this.verifySignaturePublicKey),
path: this.getJdkCachePath(javaRelease.version) path: this.getJdkCachePath(javaRelease.version)
}; };
} }
+5 -32
View File
@@ -159,10 +159,6 @@ class TemurinDistribution extends base_installer/* JavaBase */.O {
async downloadPackage(release) { async downloadPackage(release) {
const archivePath = await this.downloadAndVerify(release); const archivePath = await this.downloadAndVerify(release);
if (this.verifySignature) { if (this.verifySignature) {
try {
if (!(await gpg/* isGpgAvailable */.o6())) {
throw new Error("Input 'verify-signature' is enabled, but gpg is not available.");
}
if (!release.signatureUrl) { if (!release.signatureUrl) {
throw new Error(`Input 'verify-signature' is enabled, but no signature URL was found for Temurin version ${release.version}.`); throw new Error(`Input 'verify-signature' is enabled, but no signature URL was found for Temurin version ${release.version}.`);
} }
@@ -171,20 +167,7 @@ class TemurinDistribution extends base_installer/* JavaBase */.O {
await gpg/* verifyPackageSignature */.Yi(archivePath, release.signatureUrl, this.verifySignaturePublicKey ?? ADOPTIUM_PUBLIC_KEY); await gpg/* verifyPackageSignature */.Yi(archivePath, release.signatureUrl, this.verifySignaturePublicKey ?? ADOPTIUM_PUBLIC_KEY);
} }
catch (error) { catch (error) {
const verificationError = new Error(`Failed to verify signature for Temurin version ${release.version} from ${release.signatureUrl}: ${error.message} ${constants/* SIGNATURE_VERIFICATION_FAILURE_HELP */.kQ}`, { cause: error }); throw new Error(`Failed to verify signature for Temurin version ${release.version} from ${release.signatureUrl}: ${error.message}`, { cause: error });
if (this.verifySignatureExplicitlyRequested) {
throw verificationError;
}
else {
core/* warning */.$e(verificationError.message);
}
}
}
catch (error) {
if (this.verifySignatureExplicitlyRequested) {
throw error;
}
core/* warning */.$e(error instanceof Error ? error.message : `Unknown error: ${error}`);
} }
} }
return archivePath; return archivePath;
@@ -290,8 +273,7 @@ class TemurinDistribution extends base_installer/* JavaBase */.O {
/* harmony export */ Fh: () => (/* binding */ importKey), /* harmony export */ Fh: () => (/* binding */ importKey),
/* harmony export */ Yi: () => (/* binding */ verifyPackageSignature), /* harmony export */ Yi: () => (/* binding */ verifyPackageSignature),
/* harmony export */ mS: () => (/* binding */ removeGpgHome), /* harmony export */ mS: () => (/* binding */ removeGpgHome),
/* harmony export */ nY: () => (/* binding */ toGpgPath), /* harmony export */ nY: () => (/* binding */ toGpgPath)
/* harmony export */ o6: () => (/* binding */ isGpgAvailable)
/* harmony export */ }); /* harmony export */ });
/* unused harmony export GPG_HOME_PREFIX */ /* unused harmony export GPG_HOME_PREFIX */
/* harmony import */ var fs__WEBPACK_IMPORTED_MODULE_0__ = __webpack_require__(9896); /* harmony import */ var fs__WEBPACK_IMPORTED_MODULE_0__ = __webpack_require__(9896);
@@ -313,9 +295,6 @@ class TemurinDistribution extends base_installer/* JavaBase */.O {
const GPG_HOME_PREFIX = 'setup-java-gpg-'; const GPG_HOME_PREFIX = 'setup-java-gpg-';
const VERIFY_GPG_HOME_PREFIX = 'verify-signature-gpg-home-'; const VERIFY_GPG_HOME_PREFIX = 'verify-signature-gpg-home-';
async function isGpgAvailable() {
return Boolean(await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .which */ .K7('gpg', false));
}
// Convert a Windows path (D:\a\_temp\...) to a POSIX path (/d/a/_temp/...). // Convert a Windows path (D:\a\_temp\...) to a POSIX path (/d/a/_temp/...).
// The Git-bundled GPG on Windows (MSYS2-based) uses POSIX path conventions // The Git-bundled GPG on Windows (MSYS2-based) uses POSIX path conventions
// internally. Passing Windows paths with backslashes can cause fatal GPG errors // internally. Passing Windows paths with backslashes can cause fatal GPG errors
@@ -399,21 +378,15 @@ async function verifyPackageSignature(archivePath, signatureUrl, publicKeyConten
throw new Error(`Failed to create temporary GPG home directory for signature verification: ${error.message}`, { cause: error }); throw new Error(`Failed to create temporary GPG home directory for signature verification: ${error.message}`, { cause: error });
} }
try { try {
const publicKeys = Array.isArray(publicKeyContent) const publicKeyFile = path__WEBPACK_IMPORTED_MODULE_1__.join(gpgHome, 'public-key.asc');
? publicKeyContent fs__WEBPACK_IMPORTED_MODULE_0__.writeFileSync(publicKeyFile, publicKeyContent, { encoding: 'utf-8' });
: [publicKeyContent];
const publicKeyFiles = publicKeys.map((publicKey, index) => {
const publicKeyFile = path__WEBPACK_IMPORTED_MODULE_1__.join(gpgHome, `public-key-${index}.asc`);
fs__WEBPACK_IMPORTED_MODULE_0__.writeFileSync(publicKeyFile, publicKey, { encoding: 'utf-8' });
return toGpgPath(publicKeyFile);
});
const options = { silent: true }; const options = { silent: true };
await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpg', [ await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpg', [
'--homedir', '--homedir',
toGpgPath(gpgHome), toGpgPath(gpgHome),
'--batch', '--batch',
'--import', '--import',
...publicKeyFiles toGpgPath(publicKeyFile)
], options); ], options);
await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpg', [ await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpg', [
'--homedir', '--homedir',
+6 -15
View File
@@ -127,25 +127,16 @@ function getInstallationIdentity(jdkPath, architecture) {
return undefined; return undefined;
} }
} }
function getJdkVerificationIdentity(verifySignature, enforceSignatureVerification, publicKey) { function getJdkVerificationIdentity(verifySignature, publicKey) {
if (!verifySignature) { if (!verifySignature) {
return 'disabled'; return 'unverified';
} }
const verificationPolicy = enforceSignatureVerification
? 'enforced'
: 'check-and-warn';
if (!publicKey) { if (!publicKey) {
return `${verificationPolicy}:bundled`; return 'verified:bundled';
} }
const publicKeys = Array.isArray(publicKey) ? publicKey : [publicKey]; const normalizedKey = publicKey.replace(/\r\n?/g, '\n').trim();
const normalizedKeys = publicKeys.map(key => key.replace(/\r\n?/g, '\n').trim()); const fingerprint = (0,crypto__WEBPACK_IMPORTED_MODULE_0__.createHash)('sha256').update(normalizedKey).digest('hex');
const fingerprintSource = Array.isArray(publicKey) return `verified:custom:sha256:${fingerprint}`;
? normalizedKeys.map(key => `${Buffer.byteLength(key)}:${key}`).join('')
: normalizedKeys[0];
const fingerprint = (0,crypto__WEBPACK_IMPORTED_MODULE_0__.createHash)('sha256')
.update(fingerprintSource)
.digest('hex');
return `${verificationPolicy}:custom:sha256:${fingerprint}`;
} }
async function saveJdkCaches() { async function saveJdkCaches() {
const state = _actions_core__WEBPACK_IMPORTED_MODULE_4__/* .getState */ .Gu(STATE_JDK_CACHES); const state = _actions_core__WEBPACK_IMPORTED_MODULE_4__/* .getState */ .Gu(STATE_JDK_CACHES);
+4 -14
View File
@@ -265,8 +265,7 @@ async function write(directory, settings, overwriteSettings) {
/* harmony export */ Fh: () => (/* binding */ importKey), /* harmony export */ Fh: () => (/* binding */ importKey),
/* harmony export */ Yi: () => (/* binding */ verifyPackageSignature), /* harmony export */ Yi: () => (/* binding */ verifyPackageSignature),
/* harmony export */ mS: () => (/* binding */ removeGpgHome), /* harmony export */ mS: () => (/* binding */ removeGpgHome),
/* harmony export */ nY: () => (/* binding */ toGpgPath), /* harmony export */ nY: () => (/* binding */ toGpgPath)
/* harmony export */ o6: () => (/* binding */ isGpgAvailable)
/* harmony export */ }); /* harmony export */ });
/* unused harmony export GPG_HOME_PREFIX */ /* unused harmony export GPG_HOME_PREFIX */
/* harmony import */ var fs__WEBPACK_IMPORTED_MODULE_0__ = __webpack_require__(9896); /* harmony import */ var fs__WEBPACK_IMPORTED_MODULE_0__ = __webpack_require__(9896);
@@ -288,9 +287,6 @@ async function write(directory, settings, overwriteSettings) {
const GPG_HOME_PREFIX = 'setup-java-gpg-'; const GPG_HOME_PREFIX = 'setup-java-gpg-';
const VERIFY_GPG_HOME_PREFIX = 'verify-signature-gpg-home-'; const VERIFY_GPG_HOME_PREFIX = 'verify-signature-gpg-home-';
async function isGpgAvailable() {
return Boolean(await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .which */ .K7('gpg', false));
}
// Convert a Windows path (D:\a\_temp\...) to a POSIX path (/d/a/_temp/...). // Convert a Windows path (D:\a\_temp\...) to a POSIX path (/d/a/_temp/...).
// The Git-bundled GPG on Windows (MSYS2-based) uses POSIX path conventions // The Git-bundled GPG on Windows (MSYS2-based) uses POSIX path conventions
// internally. Passing Windows paths with backslashes can cause fatal GPG errors // internally. Passing Windows paths with backslashes can cause fatal GPG errors
@@ -374,21 +370,15 @@ async function verifyPackageSignature(archivePath, signatureUrl, publicKeyConten
throw new Error(`Failed to create temporary GPG home directory for signature verification: ${error.message}`, { cause: error }); throw new Error(`Failed to create temporary GPG home directory for signature verification: ${error.message}`, { cause: error });
} }
try { try {
const publicKeys = Array.isArray(publicKeyContent) const publicKeyFile = path__WEBPACK_IMPORTED_MODULE_1__.join(gpgHome, 'public-key.asc');
? publicKeyContent fs__WEBPACK_IMPORTED_MODULE_0__.writeFileSync(publicKeyFile, publicKeyContent, { encoding: 'utf-8' });
: [publicKeyContent];
const publicKeyFiles = publicKeys.map((publicKey, index) => {
const publicKeyFile = path__WEBPACK_IMPORTED_MODULE_1__.join(gpgHome, `public-key-${index}.asc`);
fs__WEBPACK_IMPORTED_MODULE_0__.writeFileSync(publicKeyFile, publicKey, { encoding: 'utf-8' });
return toGpgPath(publicKeyFile);
});
const options = { silent: true }; const options = { silent: true };
await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpg', [ await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpg', [
'--homedir', '--homedir',
toGpgPath(gpgHome), toGpgPath(gpgHome),
'--batch', '--batch',
'--import', '--import',
...publicKeyFiles toGpgPath(publicKeyFile)
], options); ], options);
await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpg', [ await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpg', [
'--homedir', '--homedir',
+3 -58
View File
@@ -741,26 +741,12 @@ class XmlNode {
this.child.push({ [node.tagname]: node.child }); this.child.push({ [node.tagname]: node.child });
} }
// if requested, add the startIndex // if requested, add the startIndex
this.addStartIndex(startIndex);
}
addStartIndex(startIndex) {
if (startIndex !== undefined) { if (startIndex !== undefined) {
// Note: for now we just overwrite the metadata. If we had more complex metadata, // Note: for now we just overwrite the metadata. If we had more complex metadata,
// we might need to do an object append here: metadata = { ...metadata, startIndex } // we might need to do an object append here: metadata = { ...metadata, startIndex }
this.child[this.child.length - 1][METADATA_SYMBOL] = { startIndex }; this.child[this.child.length - 1][METADATA_SYMBOL] = { startIndex };
} }
} }
addEndIndex(endIndex) {
const lastChild = this.child[this.child.length - 1];
// endIndex is write-once: when updateTag drops a node, the last child is a
// previously completed sibling whose endIndex must not be overwritten
if (lastChild !== undefined && lastChild[METADATA_SYMBOL] !== undefined
&& lastChild[METADATA_SYMBOL].endIndex === undefined) {
lastChild[METADATA_SYMBOL].endIndex = endIndex;
}
}
/** symbol used for metadata */ /** symbol used for metadata */
static getMetaDataSymbol() { static getMetaDataSymbol() {
return METADATA_SYMBOL; return METADATA_SYMBOL;
@@ -795,23 +781,8 @@ class DocTypeReader {
i = i + 9; i = i + 9;
let angleBracketsCount = 1; let angleBracketsCount = 1;
let hasBody = false, comment = false; let hasBody = false, comment = false;
let quoteChar = null; // tracks an open SYSTEM/PUBLIC literal before the '[' body
let exp = ""; let exp = "";
for (; i < xmlData.length; i++) { for (; i < xmlData.length; i++) {
// Inside a quoted external-identifier literal — XML allows '<'
// and '>' as plain data here, so they must not be interpreted
// as DOCTYPE structure until the matching quote closes.
if (quoteChar !== null) {
if (xmlData[i] === quoteChar) quoteChar = null;
exp += xmlData[i];
continue;
}
if (!hasBody && !comment && (xmlData[i] === '"' || xmlData[i] === "'")) {
quoteChar = xmlData[i];
exp += xmlData[i];
continue;
}
if (xmlData[i] === '<' && !comment) { //Determine the tag type if (xmlData[i] === '<' && !comment) { //Determine the tag type
if (hasBody && hasSeq(xmlData, "!ENTITY", i)) { if (hasBody && hasSeq(xmlData, "!ENTITY", i)) {
i += 7; i += 7;
@@ -866,7 +837,7 @@ class DocTypeReader {
exp += xmlData[i]; exp += xmlData[i];
} }
} }
if (quoteChar !== null || angleBracketsCount !== 0) { if (angleBracketsCount !== 0) {
throw new Error(`Unclosed DOCTYPE`); throw new Error(`Unclosed DOCTYPE`);
} }
} else { } else {
@@ -1581,11 +1552,7 @@ function resolveEnotation(str, trimmedStr, options) {
*/ */
function trimZeros(numStr) { function trimZeros(numStr) {
if (numStr && numStr.indexOf(".") !== -1) {//float if (numStr && numStr.indexOf(".") !== -1) {//float
//remove ending zeros without the O(n^2) backtracking that /0+$/ hits numStr = numStr.replace(/0+$/, ""); //remove ending zeros
//when the string doesn't end in 0 but has a long internal zero-run
let end = numStr.length;
while (end > 0 && numStr.charCodeAt(end - 1) === 48 /* '0' */) end--;
numStr = numStr.slice(0, end);
if (numStr === ".") numStr = "0"; if (numStr === ".") numStr = "0";
else if (numStr[0] === ".") numStr = "0" + numStr; else if (numStr[0] === ".") numStr = "0" + numStr;
else if (numStr[numStr.length - 1] === ".") numStr = numStr.substring(0, numStr.length - 1); else if (numStr[numStr.length - 1] === ".") numStr = numStr.substring(0, numStr.length - 1);
@@ -5065,12 +5032,7 @@ const parseXml = function (xmlData) {
this.matcher.pop(); this.matcher.pop();
this.isCurrentNodeStopNode = false; // Reset flag when closing tag this.isCurrentNodeStopNode = false; // Reset flag when closing tag
//a closing tag with no matching opening tag leaves the stack empty currentNode = this.tagsNodeStack.pop();//avoid recursion, set the parent tag scope
currentNode = this.tagsNodeStack.pop() || xmlObj;//avoid recursion, set the parent tag scope
if (options.captureMetaData && currentNode) {
currentNode.addEndIndex(closeIndex + 1);
}
textData = ""; textData = "";
i = closeIndex; i = closeIndex;
} else if (c1 === 63) { //'?' } else if (c1 === 63) { //'?'
@@ -5096,11 +5058,6 @@ const parseXml = function (xmlData) {
childNode[":@"] = attsMap childNode[":@"] = attsMap
} }
this.addChild(currentNode, childNode, this.readonlyMatcher, i); this.addChild(currentNode, childNode, this.readonlyMatcher, i);
if (options.captureMetaData) {
// closeIndex points at '?' of the closing '?>'
currentNode.addEndIndex(tagData.closeIndex + 2);
}
} }
@@ -5265,10 +5222,6 @@ const parseXml = function (xmlData) {
this.isCurrentNodeStopNode = false; // Reset flag this.isCurrentNodeStopNode = false; // Reset flag
this.addChild(currentNode, childNode, this.readonlyMatcher, startIndex); this.addChild(currentNode, childNode, this.readonlyMatcher, startIndex);
if (options.captureMetaData) {
currentNode.addEndIndex(i + 1);
}
} else { } else {
//selfClosing tag //selfClosing tag
if (isSelfClosing) { if (isSelfClosing) {
@@ -5279,10 +5232,6 @@ const parseXml = function (xmlData) {
childNode[":@"] = prefixedAttrs; childNode[":@"] = prefixedAttrs;
} }
this.addChild(currentNode, childNode, this.readonlyMatcher, startIndex); this.addChild(currentNode, childNode, this.readonlyMatcher, startIndex);
if (options.captureMetaData) {
currentNode.addEndIndex(closeIndex + 1);
}
this.matcher.pop(); // Pop self-closing tag this.matcher.pop(); // Pop self-closing tag
this.isCurrentNodeStopNode = false; // Reset flag this.isCurrentNodeStopNode = false; // Reset flag
} }
@@ -5292,10 +5241,6 @@ const parseXml = function (xmlData) {
childNode[":@"] = prefixedAttrs; childNode[":@"] = prefixedAttrs;
} }
this.addChild(currentNode, childNode, this.readonlyMatcher, startIndex); this.addChild(currentNode, childNode, this.readonlyMatcher, startIndex);
if (options.captureMetaData) {
currentNode.addEndIndex(result.closeIndex + 1);
}
this.matcher.pop(); // Pop unpaired tag this.matcher.pop(); // Pop unpaired tag
this.isCurrentNodeStopNode = false; // Reset flag this.isCurrentNodeStopNode = false; // Reset flag
i = result.closeIndex; i = result.closeIndex;
+6 -14
View File
@@ -30801,7 +30801,6 @@ module.exports = {
/* harmony export */ jv: () => (/* binding */ MAVEN_CENTRAL_REPOSITORY_URL), /* harmony export */ jv: () => (/* binding */ MAVEN_CENTRAL_REPOSITORY_URL),
/* harmony export */ kM: () => (/* binding */ INPUT_JDK_FILE), /* harmony export */ kM: () => (/* binding */ INPUT_JDK_FILE),
/* harmony export */ kN: () => (/* binding */ MAVEN_NO_TRANSFER_PROGRESS_LONG_FLAG), /* harmony export */ kN: () => (/* binding */ MAVEN_NO_TRANSFER_PROGRESS_LONG_FLAG),
/* harmony export */ kQ: () => (/* binding */ SIGNATURE_VERIFICATION_FAILURE_HELP),
/* harmony export */ ko: () => (/* binding */ MAVEN_GPG_PASSPHRASE_DEFAULT_ENV), /* harmony export */ ko: () => (/* binding */ MAVEN_GPG_PASSPHRASE_DEFAULT_ENV),
/* harmony export */ m7: () => (/* binding */ INPUT_MVN_TOOLCHAIN_VENDOR), /* harmony export */ m7: () => (/* binding */ INPUT_MVN_TOOLCHAIN_VENDOR),
/* harmony export */ nr: () => (/* binding */ INPUT_MVN_TOOLCHAIN_ID), /* harmony export */ nr: () => (/* binding */ INPUT_MVN_TOOLCHAIN_ID),
@@ -30822,7 +30821,7 @@ module.exports = {
/* harmony export */ xg: () => (/* binding */ MAVEN_CENTRAL_REPOSITORY_ID), /* harmony export */ xg: () => (/* binding */ MAVEN_CENTRAL_REPOSITORY_ID),
/* harmony export */ xp: () => (/* binding */ INPUT_DEFAULT_SERVER_PASSWORD) /* harmony export */ xp: () => (/* binding */ INPUT_DEFAULT_SERVER_PASSWORD)
/* harmony export */ }); /* harmony export */ });
/* unused harmony exports SIGNATURE_VERIFICATION_DOCUMENTATION_URL, INPUT_CACHE_READ_ONLY, INPUT_JOB_STATUS */ /* unused harmony exports INPUT_CACHE_READ_ONLY, INPUT_JOB_STATUS */
const MACOS_JAVA_CONTENT_POSTFIX = 'Contents/Home'; const MACOS_JAVA_CONTENT_POSTFIX = 'Contents/Home';
const INPUT_JAVA_VERSION = 'java-version'; const INPUT_JAVA_VERSION = 'java-version';
const INPUT_JAVA_VERSION_FILE = 'java-version-file'; const INPUT_JAVA_VERSION_FILE = 'java-version-file';
@@ -30837,8 +30836,6 @@ const INPUT_SET_DEFAULT = 'set-default';
const INPUT_PROBLEM_MATCHER = 'problem-matcher'; const INPUT_PROBLEM_MATCHER = 'problem-matcher';
const INPUT_VERIFY_SIGNATURE = 'verify-signature'; const INPUT_VERIFY_SIGNATURE = 'verify-signature';
const INPUT_VERIFY_SIGNATURE_PUBLIC_KEY = 'verify-signature-public-key'; const INPUT_VERIFY_SIGNATURE_PUBLIC_KEY = 'verify-signature-public-key';
const SIGNATURE_VERIFICATION_DOCUMENTATION_URL = 'https://github.com/actions/setup-java#download-integrity-and-signatures';
const SIGNATURE_VERIFICATION_FAILURE_HELP = `If this is a legitimate vendor signing-key rotation, see ${SIGNATURE_VERIFICATION_DOCUMENTATION_URL} for instructions to configure the updated public key or temporarily disable signature verification.`;
const INPUT_MVN_SERVER_CREDENTIALS = 'mvn-server-credentials'; const INPUT_MVN_SERVER_CREDENTIALS = 'mvn-server-credentials';
const INPUT_MVN_REPOSITORIES = 'mvn-repositories'; const INPUT_MVN_REPOSITORIES = 'mvn-repositories';
const INPUT_MVN_REPOSITORIES_INCLUDE_CENTRAL = 'mvn-repositories-include-central'; const INPUT_MVN_REPOSITORIES_INCLUDE_CENTRAL = 'mvn-repositories-include-central';
@@ -36068,9 +36065,6 @@ function _unique(values) {
/******/ __nccwpck_require__.m = __webpack_modules__; /******/ __nccwpck_require__.m = __webpack_modules__;
/******/ /******/
/************************************************************************/ /************************************************************************/
/******/ /* webpack/runtime/asset-relocator-loader */
/******/ if (typeof __nccwpck_require__ !== 'undefined') __nccwpck_require__.ab = decodeURIComponent(new URL('.', import.meta.url).pathname).slice(import.meta.url.match(/^file:\/\/\/\w:/) ? 1 : 0, -1) + "/";
/******/
/******/ /* webpack/runtime/compat get default export */ /******/ /* webpack/runtime/compat get default export */
/******/ (() => { /******/ (() => {
/******/ // getDefaultExport function for compatibility with non-harmony modules /******/ // getDefaultExport function for compatibility with non-harmony modules
@@ -36163,6 +36157,10 @@ function _unique(values) {
/******/ }; /******/ };
/******/ })(); /******/ })();
/******/ /******/
/******/ /* webpack/runtime/compat */
/******/
/******/ if (typeof __nccwpck_require__ !== 'undefined') __nccwpck_require__.ab = new URL('.', import.meta.url).pathname.slice(import.meta.url.match(/^file:\/\/\/\w:/) ? 1 : 0, -1) + "/";
/******/
/******/ /* webpack/runtime/import chunk loading */ /******/ /* webpack/runtime/import chunk loading */
/******/ (() => { /******/ (() => {
/******/ // no baseURI /******/ // no baseURI
@@ -36378,6 +36376,7 @@ async function run() {
const checkLatest = (0,util/* getBooleanInput */.Vt)(constants/* INPUT_CHECK_LATEST */.YM, false); const checkLatest = (0,util/* getBooleanInput */.Vt)(constants/* INPUT_CHECK_LATEST */.YM, false);
const forceDownload = (0,util/* getBooleanInput */.Vt)(constants/* INPUT_FORCE_DOWNLOAD */.I9, false); const forceDownload = (0,util/* getBooleanInput */.Vt)(constants/* INPUT_FORCE_DOWNLOAD */.I9, false);
const setDefault = (0,util/* getBooleanInput */.Vt)(constants/* INPUT_SET_DEFAULT */.E8, true); const setDefault = (0,util/* getBooleanInput */.Vt)(constants/* INPUT_SET_DEFAULT */.E8, true);
const verifySignature = (0,util/* getBooleanInput */.Vt)(constants/* INPUT_VERIFY_SIGNATURE */.qy, false);
const verifySignaturePublicKey = setup_java_core/* getInput */.V4(constants/* INPUT_VERIFY_SIGNATURE_PUBLIC_KEY */.u) || undefined; const verifySignaturePublicKey = setup_java_core/* getInput */.V4(constants/* INPUT_VERIFY_SIGNATURE_PUBLIC_KEY */.u) || undefined;
const toolchainIds = setup_java_core/* getMultilineInput */.q3(constants/* INPUT_MVN_TOOLCHAIN_ID */.nr); const toolchainIds = setup_java_core/* getMultilineInput */.q3(constants/* INPUT_MVN_TOOLCHAIN_ID */.nr);
let actionError; let actionError;
@@ -36405,7 +36404,6 @@ async function run() {
else if (!distributionName) { else if (!distributionName) {
throw new Error('distribution input is required when not specified in the version file'); throw new Error('distribution input is required when not specified in the version file');
} }
const verifySignature = getVerifySignatureInput();
const installerInputsOptions = { const installerInputsOptions = {
architecture, architecture,
packageType, packageType,
@@ -36430,7 +36428,6 @@ async function run() {
if (!distributionName) { if (!distributionName) {
throw new Error('distribution input is required'); throw new Error('distribution input is required');
} }
const verifySignature = getVerifySignatureInput();
const installerInputsOptions = { const installerInputsOptions = {
architecture, architecture,
packageType, packageType,
@@ -36495,11 +36492,6 @@ function getJdkFileInput() {
} }
return jdkFile || deprecatedJdkFile; return jdkFile || deprecatedJdkFile;
} }
function getVerifySignatureInput() {
return setup_java_core/* getInput */.V4(constants/* INPUT_VERIFY_SIGNATURE */.qy).trim()
? (0,util/* getBooleanInput */.Vt)(constants/* INPUT_VERIFY_SIGNATURE */.qy)
: undefined;
}
async function installVersion(version, options, toolchainId = 0) { async function installVersion(version, options, toolchainId = 0) {
const { distributionName, jdkFile, architecture, packageType, checkLatest, forceDownload, cacheJdk, setDefault, verifySignature, verifySignaturePublicKey, toolchainIds } = options; const { distributionName, jdkFile, architecture, packageType, checkLatest, forceDownload, cacheJdk, setDefault, verifySignature, verifySignaturePublicKey, toolchainIds } = options;
const installerOptions = { const installerOptions = {
+19 -19
View File
@@ -39,6 +39,15 @@
See [action.yml](../action.yml) for more details on task inputs. See [action.yml](../action.yml) for more details on task inputs.
> [!NOTE]
> The examples on this page reference `actions/setup-java@v6`, which is still in
> development on the `main` branch and is not yet published as a release tag. To
> try the V6 features documented here (`cache-jdk`, `force-download`,
> `problem-matcher`, `cache-path`, `cache-read-only`, `java-version: latest`,
> `oracle-openjdk`, and the `*-env-var` input names), reference
> `actions/setup-java@main`. For production workflows use the latest stable
> release, `actions/setup-java@v5`, as shown in the [README](../README.md).
## Selecting a Java distribution ## Selecting a Java distribution
`java-version` and `distribution` select what gets installed. `java-version` may be replaced by `java-version-file`, and `distribution` is optional only when `java-version-file` points to a `.sdkmanrc` or `.tool-versions` file that carries a recognized vendor identifier. In every other case both inputs must be provided. See [Supported distributions](../README.md#Supported-distributions) for a list of available options. `java-version` and `distribution` select what gets installed. `java-version` may be replaced by `java-version-file`, and `distribution` is optional only when `java-version-file` points to a `.sdkmanrc` or `.tool-versions` file that carries a recognized vendor identifier. In every other case both inputs must be provided. See [Supported distributions](../README.md#Supported-distributions) for a list of available options.
@@ -539,27 +548,18 @@ tool-cache installation short-circuits setup, so a changed `jdk-file` is not
re-extracted for a version that is already installed. Use re-extracted for a version that is already installed. Use
`force-download: true` when the archive contents change but the version does not. `force-download: true` when the archive contents change but the version does not.
The verification identity separates requests that disable signature verification, The verification identity separates unverified downloads from packages verified
check and warn without enforcement, or explicitly enforce verification. Disabled with the distribution's bundled signing key and from packages verified with each
and check-and-warn requests have the same non-enforcement guarantee, but they are custom key. Custom public keys are represented by a SHA-256 fingerprint of
kept separate so an entry downloaded with verification disabled cannot prevent a normalized key material; the key itself is not placed in the cache key, the logs,
later check-and-warn request from attempting verification. The identity also or action state. A verified exact-key hit reuses content that was
separates the distribution's bundled signing keys from custom keys. Custom signature-verified when it was downloaded by the run that saved the entry,
public-key sets are represented by a SHA-256 fingerprint of normalized, instead of downloading and verifying it again.
boundary-delimited key material; the keys themselves are not placed in the cache
key, the logs, or action state. Enforced requests only restore entries created by
an enforced request whose signature verification succeeded. Check-and-warn entries
may have been saved after verification succeeded or after a verification failure
was reported as a warning.
For signature-verification defaults, enforced failure behavior, and recovery from
a legitimate vendor signing-key rotation, see
[Download integrity and signatures](../README.md#download-integrity-and-signatures).
> [!IMPORTANT] > [!IMPORTANT]
> The JDK cache **key** isolates disabled, check-and-warn, and enforced verification > The JDK cache **key** is what isolates verification modes and release
> modes as well as release identity. A check-and-warn entry can never be restored > identity: a JDK cache entry created by an unverified download can never be
> for a request that sets `verify-signature: true`, and vice versa. > restored for a request that sets `verify-signature: true`, and vice versa.
> `cache-jdk` does not change how the runner tool cache is used. setup-java > `cache-jdk` does not change how the runner tool cache is used. setup-java
> first looks for an installation in the runner tool cache — a preinstalled > first looks for an installation in the runner tool cache — a preinstalled
> JDK, or one installed by an earlier step of the same job — and uses it as-is. Such an installation is not downloaded again, and its checksum > JDK, or one installed by an earlier step of the same job — and uses it as-is. Such an installation is not downloaded again, and its checksum
@@ -1,4 +1,4 @@
# Contributing # Contributors
Thank you for contributing! Thank you for contributing!
+127 -352
View File
@@ -16,22 +16,22 @@
"@actions/http-client": "^4.0.1", "@actions/http-client": "^4.0.1",
"@actions/io": "^3.0.2", "@actions/io": "^3.0.2",
"@actions/tool-cache": "^4.0.0", "@actions/tool-cache": "^4.0.0",
"fast-xml-parser": "^5.11.0", "fast-xml-parser": "^5.10.1",
"semver": "^7.8.5" "semver": "^7.8.5"
}, },
"devDependencies": { "devDependencies": {
"@eslint/js": "^10.0.1", "@eslint/js": "^10.0.1",
"@jest/globals": "^30.4.1", "@jest/globals": "^30.4.1",
"@types/node": "^26.2.0", "@types/node": "^26.1.1",
"@types/semver": "^7.8.0", "@types/semver": "^7.8.0",
"@typescript-eslint/eslint-plugin": "^8.67.0", "@typescript-eslint/eslint-plugin": "^8.67.0",
"@typescript-eslint/parser": "^8.65.0", "@typescript-eslint/parser": "^8.65.0",
"@vercel/ncc": "^0.45.0", "@vercel/ncc": "^0.44.0",
"eslint": "^10.8.1", "eslint": "^10.7.0",
"eslint-config-prettier": "^10.1.8", "eslint-config-prettier": "^10.1.8",
"eslint-plugin-jest": "^29.16.1", "eslint-plugin-jest": "^29.15.4",
"eslint-plugin-n": "^18.3.0", "eslint-plugin-n": "^18.2.2",
"globals": "^17.11.0", "globals": "^17.9.0",
"husky": "^9.1.7", "husky": "^9.1.7",
"jest": "^30.4.2", "jest": "^30.4.2",
"lint-staged": "^17.3.0", "lint-staged": "^17.3.0",
@@ -1726,9 +1726,9 @@
"license": "MIT" "license": "MIT"
}, },
"node_modules/@types/node": { "node_modules/@types/node": {
"version": "26.2.0", "version": "26.1.2",
"resolved": "https://registry.npmjs.org/@types/node/-/node-26.2.0.tgz", "resolved": "https://registry.npmjs.org/@types/node/-/node-26.1.2.tgz",
"integrity": "sha512-5IviulTZeRNp2vAJ514cc/HUlY5nZ9fCbq9DMyC52BrhFZACo3nI0R7qBxhQmo/d27NFe96ur/b7Wwxklda+kg==", "integrity": "sha512-Vu4a5UFA9rIIFJ7rB/Vaafh9lrCQszopTCx6KjFboXTGQbPNasehVR5TEiithSDGyd1DEiUByggTZsg8jukeIg==",
"dev": true, "dev": true,
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
@@ -1795,189 +1795,6 @@
"typescript": ">=4.8.4 <6.1.0" "typescript": ">=4.8.4 <6.1.0"
} }
}, },
"node_modules/@typescript-eslint/eslint-plugin/node_modules/@typescript-eslint/type-utils": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/type-utils/-/type-utils-8.67.0.tgz",
"integrity": "sha512-aVWDXbRmdXO9siTfX4ditQI1T9+zVcNazT48EJCD0v40/9RIFoUgZ05CmGEq9H2gixRpjUn/iplwvlcvutJW/Q==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/types": "8.67.0",
"@typescript-eslint/typescript-estree": "8.67.0",
"@typescript-eslint/utils": "8.67.0",
"debug": "^4.4.3",
"ts-api-utils": "^2.5.0"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"eslint": "^8.57.0 || ^9.0.0 || ^10.0.0",
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/@typescript-eslint/eslint-plugin/node_modules/@typescript-eslint/type-utils/node_modules/@typescript-eslint/typescript-estree": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/typescript-estree/-/typescript-estree-8.67.0.tgz",
"integrity": "sha512-EKQBCE9yNlRJYm7jdTW5AhDacDUmSwQb0FAJAmK2EKYrNXIsa2vxcSZx6PvJ/dEdI6lS+Y9W+EXckLj0iPFGcw==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/project-service": "8.67.0",
"@typescript-eslint/tsconfig-utils": "8.67.0",
"@typescript-eslint/types": "8.67.0",
"@typescript-eslint/visitor-keys": "8.67.0",
"debug": "^4.4.3",
"minimatch": "^10.2.2",
"semver": "^7.7.3",
"tinyglobby": "^0.2.15",
"ts-api-utils": "^2.5.0"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/@typescript-eslint/eslint-plugin/node_modules/@typescript-eslint/type-utils/node_modules/@typescript-eslint/typescript-estree/node_modules/@typescript-eslint/project-service": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/project-service/-/project-service-8.67.0.tgz",
"integrity": "sha512-cvE8c7ulYeXN9fYuszhCeCsbzyVEXuhrRCybnBre7TUmqb5nRmBfQAwCj0O3WJFDeyAZt4VYv51vMCC9LHSdYw==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/tsconfig-utils": "^8.67.0",
"@typescript-eslint/types": "^8.67.0",
"debug": "^4.4.3"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/@typescript-eslint/eslint-plugin/node_modules/@typescript-eslint/type-utils/node_modules/@typescript-eslint/typescript-estree/node_modules/@typescript-eslint/tsconfig-utils": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/tsconfig-utils/-/tsconfig-utils-8.67.0.tgz",
"integrity": "sha512-vV+LUSv5njUWsknE71fqKTlXUva+R76SaeORd6Zojcunk/6DvKFXONU3BrAs2H49mbygUXt6gbYunzwqNwlhdg==",
"dev": true,
"license": "MIT",
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/@typescript-eslint/eslint-plugin/node_modules/@typescript-eslint/utils": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/utils/-/utils-8.67.0.tgz",
"integrity": "sha512-U9D1FdwEWBwok3hxxSdhclMb0twvt9QnjIQ0VfQ1AiX2epnpSgv2ubVDsayOFyY8K6FX+AQ7E0FKWVG3iKsj1A==",
"dev": true,
"license": "MIT",
"dependencies": {
"@eslint-community/eslint-utils": "^4.9.1",
"@typescript-eslint/scope-manager": "8.67.0",
"@typescript-eslint/types": "8.67.0",
"@typescript-eslint/typescript-estree": "8.67.0"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"eslint": "^8.57.0 || ^9.0.0 || ^10.0.0",
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/@typescript-eslint/eslint-plugin/node_modules/@typescript-eslint/utils/node_modules/@typescript-eslint/typescript-estree": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/typescript-estree/-/typescript-estree-8.67.0.tgz",
"integrity": "sha512-EKQBCE9yNlRJYm7jdTW5AhDacDUmSwQb0FAJAmK2EKYrNXIsa2vxcSZx6PvJ/dEdI6lS+Y9W+EXckLj0iPFGcw==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/project-service": "8.67.0",
"@typescript-eslint/tsconfig-utils": "8.67.0",
"@typescript-eslint/types": "8.67.0",
"@typescript-eslint/visitor-keys": "8.67.0",
"debug": "^4.4.3",
"minimatch": "^10.2.2",
"semver": "^7.7.3",
"tinyglobby": "^0.2.15",
"ts-api-utils": "^2.5.0"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/@typescript-eslint/eslint-plugin/node_modules/@typescript-eslint/utils/node_modules/@typescript-eslint/typescript-estree/node_modules/@typescript-eslint/project-service": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/project-service/-/project-service-8.67.0.tgz",
"integrity": "sha512-cvE8c7ulYeXN9fYuszhCeCsbzyVEXuhrRCybnBre7TUmqb5nRmBfQAwCj0O3WJFDeyAZt4VYv51vMCC9LHSdYw==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/tsconfig-utils": "^8.67.0",
"@typescript-eslint/types": "^8.67.0",
"debug": "^4.4.3"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/@typescript-eslint/eslint-plugin/node_modules/@typescript-eslint/utils/node_modules/@typescript-eslint/typescript-estree/node_modules/@typescript-eslint/tsconfig-utils": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/tsconfig-utils/-/tsconfig-utils-8.67.0.tgz",
"integrity": "sha512-vV+LUSv5njUWsknE71fqKTlXUva+R76SaeORd6Zojcunk/6DvKFXONU3BrAs2H49mbygUXt6gbYunzwqNwlhdg==",
"dev": true,
"license": "MIT",
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/@typescript-eslint/parser": { "node_modules/@typescript-eslint/parser": {
"version": "8.67.0", "version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/parser/-/parser-8.67.0.tgz", "resolved": "https://registry.npmjs.org/@typescript-eslint/parser/-/parser-8.67.0.tgz",
@@ -2003,35 +1820,7 @@
"typescript": ">=4.8.4 <6.1.0" "typescript": ">=4.8.4 <6.1.0"
} }
}, },
"node_modules/@typescript-eslint/parser/node_modules/@typescript-eslint/typescript-estree": { "node_modules/@typescript-eslint/project-service": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/typescript-estree/-/typescript-estree-8.67.0.tgz",
"integrity": "sha512-EKQBCE9yNlRJYm7jdTW5AhDacDUmSwQb0FAJAmK2EKYrNXIsa2vxcSZx6PvJ/dEdI6lS+Y9W+EXckLj0iPFGcw==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/project-service": "8.67.0",
"@typescript-eslint/tsconfig-utils": "8.67.0",
"@typescript-eslint/types": "8.67.0",
"@typescript-eslint/visitor-keys": "8.67.0",
"debug": "^4.4.3",
"minimatch": "^10.2.2",
"semver": "^7.7.3",
"tinyglobby": "^0.2.15",
"ts-api-utils": "^2.5.0"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/@typescript-eslint/parser/node_modules/@typescript-eslint/typescript-estree/node_modules/@typescript-eslint/project-service": {
"version": "8.67.0", "version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/project-service/-/project-service-8.67.0.tgz", "resolved": "https://registry.npmjs.org/@typescript-eslint/project-service/-/project-service-8.67.0.tgz",
"integrity": "sha512-cvE8c7ulYeXN9fYuszhCeCsbzyVEXuhrRCybnBre7TUmqb5nRmBfQAwCj0O3WJFDeyAZt4VYv51vMCC9LHSdYw==", "integrity": "sha512-cvE8c7ulYeXN9fYuszhCeCsbzyVEXuhrRCybnBre7TUmqb5nRmBfQAwCj0O3WJFDeyAZt4VYv51vMCC9LHSdYw==",
@@ -2053,23 +1842,6 @@
"typescript": ">=4.8.4 <6.1.0" "typescript": ">=4.8.4 <6.1.0"
} }
}, },
"node_modules/@typescript-eslint/parser/node_modules/@typescript-eslint/typescript-estree/node_modules/@typescript-eslint/tsconfig-utils": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/tsconfig-utils/-/tsconfig-utils-8.67.0.tgz",
"integrity": "sha512-vV+LUSv5njUWsknE71fqKTlXUva+R76SaeORd6Zojcunk/6DvKFXONU3BrAs2H49mbygUXt6gbYunzwqNwlhdg==",
"dev": true,
"license": "MIT",
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/@typescript-eslint/scope-manager": { "node_modules/@typescript-eslint/scope-manager": {
"version": "8.67.0", "version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/scope-manager/-/scope-manager-8.67.0.tgz", "resolved": "https://registry.npmjs.org/@typescript-eslint/scope-manager/-/scope-manager-8.67.0.tgz",
@@ -2088,6 +1860,48 @@
"url": "https://opencollective.com/typescript-eslint" "url": "https://opencollective.com/typescript-eslint"
} }
}, },
"node_modules/@typescript-eslint/tsconfig-utils": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/tsconfig-utils/-/tsconfig-utils-8.67.0.tgz",
"integrity": "sha512-vV+LUSv5njUWsknE71fqKTlXUva+R76SaeORd6Zojcunk/6DvKFXONU3BrAs2H49mbygUXt6gbYunzwqNwlhdg==",
"dev": true,
"license": "MIT",
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/@typescript-eslint/type-utils": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/type-utils/-/type-utils-8.67.0.tgz",
"integrity": "sha512-aVWDXbRmdXO9siTfX4ditQI1T9+zVcNazT48EJCD0v40/9RIFoUgZ05CmGEq9H2gixRpjUn/iplwvlcvutJW/Q==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/types": "8.67.0",
"@typescript-eslint/typescript-estree": "8.67.0",
"@typescript-eslint/utils": "8.67.0",
"debug": "^4.4.3",
"ts-api-utils": "^2.5.0"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"eslint": "^8.57.0 || ^9.0.0 || ^10.0.0",
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/@typescript-eslint/types": { "node_modules/@typescript-eslint/types": {
"version": "8.67.0", "version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/types/-/types-8.67.0.tgz", "resolved": "https://registry.npmjs.org/@typescript-eslint/types/-/types-8.67.0.tgz",
@@ -2102,6 +1916,58 @@
"url": "https://opencollective.com/typescript-eslint" "url": "https://opencollective.com/typescript-eslint"
} }
}, },
"node_modules/@typescript-eslint/typescript-estree": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/typescript-estree/-/typescript-estree-8.67.0.tgz",
"integrity": "sha512-EKQBCE9yNlRJYm7jdTW5AhDacDUmSwQb0FAJAmK2EKYrNXIsa2vxcSZx6PvJ/dEdI6lS+Y9W+EXckLj0iPFGcw==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/project-service": "8.67.0",
"@typescript-eslint/tsconfig-utils": "8.67.0",
"@typescript-eslint/types": "8.67.0",
"@typescript-eslint/visitor-keys": "8.67.0",
"debug": "^4.4.3",
"minimatch": "^10.2.2",
"semver": "^7.7.3",
"tinyglobby": "^0.2.15",
"ts-api-utils": "^2.5.0"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/@typescript-eslint/utils": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/utils/-/utils-8.67.0.tgz",
"integrity": "sha512-U9D1FdwEWBwok3hxxSdhclMb0twvt9QnjIQ0VfQ1AiX2epnpSgv2ubVDsayOFyY8K6FX+AQ7E0FKWVG3iKsj1A==",
"dev": true,
"license": "MIT",
"dependencies": {
"@eslint-community/eslint-utils": "^4.9.1",
"@typescript-eslint/scope-manager": "8.67.0",
"@typescript-eslint/types": "8.67.0",
"@typescript-eslint/typescript-estree": "8.67.0"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"eslint": "^8.57.0 || ^9.0.0 || ^10.0.0",
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/@typescript-eslint/visitor-keys": { "node_modules/@typescript-eslint/visitor-keys": {
"version": "8.67.0", "version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/visitor-keys/-/visitor-keys-8.67.0.tgz", "resolved": "https://registry.npmjs.org/@typescript-eslint/visitor-keys/-/visitor-keys-8.67.0.tgz",
@@ -2498,9 +2364,9 @@
] ]
}, },
"node_modules/@vercel/ncc": { "node_modules/@vercel/ncc": {
"version": "0.45.0", "version": "0.44.1",
"resolved": "https://registry.npmjs.org/@vercel/ncc/-/ncc-0.45.0.tgz", "resolved": "https://registry.npmjs.org/@vercel/ncc/-/ncc-0.44.1.tgz",
"integrity": "sha512-8zPi1yO2mHpoKTD+e+Bf0ZT3e+sWHSOyGapm9s7b5R0gxJi3CiFTqmeQiMEyu6ejrz2s09M8JkEoUaTWjBJPQQ==", "integrity": "sha512-cUjIE5P2YY1n+Kt9rFIazMMpGoPn1Fic04rOmTkElMkiDP5oszGfERMpo2shVkFKDL7rVppdM2pqJKC59shQWQ==",
"dev": true, "dev": true,
"license": "MIT", "license": "MIT",
"bin": { "bin": {
@@ -3144,9 +3010,9 @@
} }
}, },
"node_modules/eslint": { "node_modules/eslint": {
"version": "10.8.1", "version": "10.8.0",
"resolved": "https://registry.npmjs.org/eslint/-/eslint-10.8.1.tgz", "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.8.0.tgz",
"integrity": "sha512-wqA7W2jbsC/BnV9Iv1UZpKVFkO1AdNoSmYW8NWG4HNOBbkAMvIqDZ27pI2f07dqn583NcIC44ckjAcOXDL1QbQ==", "integrity": "sha512-nuKKvN+oIBO0koN7Tm7dlkmnkc21mtt0QJLwAKzjLq14y6lRTdVG36MZHJ8eQHwdJMwZbQNMlPOYedMq/oVJvQ==",
"dev": true, "dev": true,
"license": "MIT", "license": "MIT",
"workspaces": [ "workspaces": [
@@ -3257,9 +3123,9 @@
} }
}, },
"node_modules/eslint-plugin-jest": { "node_modules/eslint-plugin-jest": {
"version": "29.16.1", "version": "29.16.0",
"resolved": "https://registry.npmjs.org/eslint-plugin-jest/-/eslint-plugin-jest-29.16.1.tgz", "resolved": "https://registry.npmjs.org/eslint-plugin-jest/-/eslint-plugin-jest-29.16.0.tgz",
"integrity": "sha512-tfxOIsjzaBud+f74aLbBMRcnrztt5eCIgnAdeoGdnzMAQ4IdAa/s/p8Ls55mk9MC79N3j2jbv4Qetz6Hclbcfw==", "integrity": "sha512-0WFBxDHlT2ratGQfnFQEVIsgQJ5cfd+0IV8Kc6U3X2onB8ATLG23voD2Ch5G9fCkEpCPmCMuzW0tbS0kYb8biw==",
"dev": true, "dev": true,
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
@@ -3286,101 +3152,10 @@
} }
} }
}, },
"node_modules/eslint-plugin-jest/node_modules/@typescript-eslint/utils": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/utils/-/utils-8.67.0.tgz",
"integrity": "sha512-U9D1FdwEWBwok3hxxSdhclMb0twvt9QnjIQ0VfQ1AiX2epnpSgv2ubVDsayOFyY8K6FX+AQ7E0FKWVG3iKsj1A==",
"dev": true,
"license": "MIT",
"dependencies": {
"@eslint-community/eslint-utils": "^4.9.1",
"@typescript-eslint/scope-manager": "8.67.0",
"@typescript-eslint/types": "8.67.0",
"@typescript-eslint/typescript-estree": "8.67.0"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"eslint": "^8.57.0 || ^9.0.0 || ^10.0.0",
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/eslint-plugin-jest/node_modules/@typescript-eslint/utils/node_modules/@typescript-eslint/typescript-estree": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/typescript-estree/-/typescript-estree-8.67.0.tgz",
"integrity": "sha512-EKQBCE9yNlRJYm7jdTW5AhDacDUmSwQb0FAJAmK2EKYrNXIsa2vxcSZx6PvJ/dEdI6lS+Y9W+EXckLj0iPFGcw==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/project-service": "8.67.0",
"@typescript-eslint/tsconfig-utils": "8.67.0",
"@typescript-eslint/types": "8.67.0",
"@typescript-eslint/visitor-keys": "8.67.0",
"debug": "^4.4.3",
"minimatch": "^10.2.2",
"semver": "^7.7.3",
"tinyglobby": "^0.2.15",
"ts-api-utils": "^2.5.0"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/eslint-plugin-jest/node_modules/@typescript-eslint/utils/node_modules/@typescript-eslint/typescript-estree/node_modules/@typescript-eslint/project-service": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/project-service/-/project-service-8.67.0.tgz",
"integrity": "sha512-cvE8c7ulYeXN9fYuszhCeCsbzyVEXuhrRCybnBre7TUmqb5nRmBfQAwCj0O3WJFDeyAZt4VYv51vMCC9LHSdYw==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/tsconfig-utils": "^8.67.0",
"@typescript-eslint/types": "^8.67.0",
"debug": "^4.4.3"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/eslint-plugin-jest/node_modules/@typescript-eslint/utils/node_modules/@typescript-eslint/typescript-estree/node_modules/@typescript-eslint/tsconfig-utils": {
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/tsconfig-utils/-/tsconfig-utils-8.67.0.tgz",
"integrity": "sha512-vV+LUSv5njUWsknE71fqKTlXUva+R76SaeORd6Zojcunk/6DvKFXONU3BrAs2H49mbygUXt6gbYunzwqNwlhdg==",
"dev": true,
"license": "MIT",
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/eslint-plugin-n": { "node_modules/eslint-plugin-n": {
"version": "18.3.0", "version": "18.2.2",
"resolved": "https://registry.npmjs.org/eslint-plugin-n/-/eslint-plugin-n-18.3.0.tgz", "resolved": "https://registry.npmjs.org/eslint-plugin-n/-/eslint-plugin-n-18.2.2.tgz",
"integrity": "sha512-cPVguuDe6DrIPb/qUXHf8P89MaVTUmiYWwpt5gX5AILsvRIiZAxMFXcFR6QHYBksqKJpjfUBlL/RleCJUWcD7w==", "integrity": "sha512-gOO0lIqwEjZ750kv9/SptCWArUoAZXJoBr0vYWTO2dCBxctHUXlBIigiC8xuxxr/NKqgIT6Ehz1xRcilj8a5cA==",
"dev": true, "dev": true,
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
@@ -3688,9 +3463,9 @@
} }
}, },
"node_modules/fast-xml-parser": { "node_modules/fast-xml-parser": {
"version": "5.11.0", "version": "5.10.1",
"resolved": "https://registry.npmjs.org/fast-xml-parser/-/fast-xml-parser-5.11.0.tgz", "resolved": "https://registry.npmjs.org/fast-xml-parser/-/fast-xml-parser-5.10.1.tgz",
"integrity": "sha512-9IGxMqvqLOnqP+Egi1nqDHKv5k8aZ7r9n558enxcucmyVGEBNPAU+MOg/8jPIS7rO7sSq4gFm1/nHtiaubMruw==", "integrity": "sha512-IEMIf7298kXuZSRFoGfMYrl7is8LpavODgbNz1cwIudv7KwVFnuU+UsMporfq6PD6aXSlawZlARiA3UywCTfMw==",
"funding": [ "funding": [
{ {
"type": "github", "type": "github",
@@ -3703,7 +3478,7 @@
"fast-xml-builder": "^1.2.0", "fast-xml-builder": "^1.2.0",
"is-unsafe": "^2.0.0", "is-unsafe": "^2.0.0",
"path-expression-matcher": "^1.6.2", "path-expression-matcher": "^1.6.2",
"strnum": "^2.4.2", "strnum": "^2.4.1",
"xml-naming": "^0.3.0" "xml-naming": "^0.3.0"
}, },
"bin": { "bin": {
@@ -3916,9 +3691,9 @@
} }
}, },
"node_modules/globals": { "node_modules/globals": {
"version": "17.11.0", "version": "17.9.0",
"resolved": "https://registry.npmjs.org/globals/-/globals-17.11.0.tgz", "resolved": "https://registry.npmjs.org/globals/-/globals-17.9.0.tgz",
"integrity": "sha512-Z2I8hM+PbJDXQDq3Icgpzv+mPdwr68iZUU9d5WW4FuXfDUQfkZaZuvjMv42/5crNyw154+9+VWXbYrUgDXbxNw==", "integrity": "sha512-m/MvAW61QVU5VDNF1Vj8axt016h8w7L5TU1e9zlab7XIttAT2YAlCwl75K1fOqvMM9apmD7lbCIRhpfkhmxhCg==",
"dev": true, "dev": true,
"license": "MIT", "license": "MIT",
"engines": { "engines": {
@@ -5755,9 +5530,9 @@
} }
}, },
"node_modules/strnum": { "node_modules/strnum": {
"version": "2.4.2", "version": "2.4.1",
"resolved": "https://registry.npmjs.org/strnum/-/strnum-2.4.2.tgz", "resolved": "https://registry.npmjs.org/strnum/-/strnum-2.4.1.tgz",
"integrity": "sha512-rDG3Ah4TV0k1hWvLSzkZtMmLN9+eS+h3knq4MP6A42Y3Yh5qGNnOUs1jJkoSr8FG5dsL28c7KgkIBzSEykqtuw==", "integrity": "sha512-M9eUSMT2dCB2cTNPG7UYj6KuK7RJR2SN2+yCV/fTW3xzTCS6EaGZ5pSMgDIjB7r8zSfTGk+dvvn9rTjpVS9Mwg==",
"funding": [ "funding": [
{ {
"type": "github", "type": "github",
+7 -7
View File
@@ -49,22 +49,22 @@
"@actions/http-client": "^4.0.1", "@actions/http-client": "^4.0.1",
"@actions/io": "^3.0.2", "@actions/io": "^3.0.2",
"@actions/tool-cache": "^4.0.0", "@actions/tool-cache": "^4.0.0",
"fast-xml-parser": "^5.11.0", "fast-xml-parser": "^5.10.1",
"semver": "^7.8.5" "semver": "^7.8.5"
}, },
"devDependencies": { "devDependencies": {
"@eslint/js": "^10.0.1", "@eslint/js": "^10.0.1",
"@jest/globals": "^30.4.1", "@jest/globals": "^30.4.1",
"@types/node": "^26.2.0", "@types/node": "^26.1.1",
"@types/semver": "^7.8.0", "@types/semver": "^7.8.0",
"@typescript-eslint/eslint-plugin": "^8.67.0", "@typescript-eslint/eslint-plugin": "^8.67.0",
"@typescript-eslint/parser": "^8.65.0", "@typescript-eslint/parser": "^8.65.0",
"@vercel/ncc": "^0.45.0", "@vercel/ncc": "^0.44.0",
"eslint": "^10.8.1", "eslint": "^10.7.0",
"eslint-config-prettier": "^10.1.8", "eslint-config-prettier": "^10.1.8",
"eslint-plugin-jest": "^29.16.1", "eslint-plugin-jest": "^29.15.4",
"eslint-plugin-n": "^18.3.0", "eslint-plugin-n": "^18.2.2",
"globals": "^17.11.0", "globals": "^17.9.0",
"husky": "^9.1.7", "husky": "^9.1.7",
"jest": "^30.4.2", "jest": "^30.4.2",
"lint-staged": "^17.3.0", "lint-staged": "^17.3.0",
-3
View File
@@ -12,9 +12,6 @@ export const INPUT_SET_DEFAULT = 'set-default';
export const INPUT_PROBLEM_MATCHER = 'problem-matcher'; export const INPUT_PROBLEM_MATCHER = 'problem-matcher';
export const INPUT_VERIFY_SIGNATURE = 'verify-signature'; export const INPUT_VERIFY_SIGNATURE = 'verify-signature';
export const INPUT_VERIFY_SIGNATURE_PUBLIC_KEY = 'verify-signature-public-key'; export const INPUT_VERIFY_SIGNATURE_PUBLIC_KEY = 'verify-signature-public-key';
export const SIGNATURE_VERIFICATION_DOCUMENTATION_URL =
'https://github.com/actions/setup-java#download-integrity-and-signatures';
export const SIGNATURE_VERIFICATION_FAILURE_HELP = `If this is a legitimate vendor signing-key rotation, see ${SIGNATURE_VERIFICATION_DOCUMENTATION_URL} for instructions to configure the updated public key or temporarily disable signature verification.`;
export const INPUT_MVN_SERVER_CREDENTIALS = 'mvn-server-credentials'; export const INPUT_MVN_SERVER_CREDENTIALS = 'mvn-server-credentials';
export const INPUT_MVN_REPOSITORIES = 'mvn-repositories'; export const INPUT_MVN_REPOSITORIES = 'mvn-repositories';
export const INPUT_MVN_REPOSITORIES_INCLUDE_CENTRAL = export const INPUT_MVN_REPOSITORIES_INCLUDE_CENTRAL =
+4 -10
View File
@@ -9,13 +9,12 @@ import {
getToolcachePath, getToolcachePath,
isVersionSatisfies isVersionSatisfies
} from '../util.js'; } from '../util.js';
import type { import {
ChecksumAlgorithm, ChecksumAlgorithm,
ChecksumMetadata, ChecksumMetadata,
JavaDownloadRelease, JavaDownloadRelease,
JavaInstallerOptions, JavaInstallerOptions,
JavaInstallerResults, JavaInstallerResults
SignatureVerificationKey
} from './base-models.js'; } from './base-models.js';
import {MACOS_JAVA_CONTENT_POSTFIX} from '../constants.js'; import {MACOS_JAVA_CONTENT_POSTFIX} from '../constants.js';
import {RetryingHttpClient} from '../retrying-http-client.js'; import {RetryingHttpClient} from '../retrying-http-client.js';
@@ -45,8 +44,7 @@ export abstract class JavaBase {
private floatingVersionVerified = false; private floatingVersionVerified = false;
protected setDefault: boolean; protected setDefault: boolean;
protected verifySignature: boolean; protected verifySignature: boolean;
protected verifySignatureExplicitlyRequested: boolean; protected verifySignaturePublicKey: string | undefined;
protected verifySignaturePublicKey: SignatureVerificationKey | undefined;
constructor( constructor(
protected distribution: string, protected distribution: string,
@@ -70,10 +68,7 @@ export abstract class JavaBase {
installerOptions.setDefault !== undefined installerOptions.setDefault !== undefined
? installerOptions.setDefault ? installerOptions.setDefault
: true; : true;
this.verifySignature = this.verifySignature = installerOptions.verifySignature ?? false;
installerOptions.verifySignature ?? this.supportsSignatureVerification();
this.verifySignatureExplicitlyRequested =
installerOptions.verifySignature === true;
this.verifySignaturePublicKey = installerOptions.verifySignaturePublicKey; this.verifySignaturePublicKey = installerOptions.verifySignaturePublicKey;
} }
@@ -373,7 +368,6 @@ export abstract class JavaBase {
source: this.getJdkReleaseIdentity(javaRelease), source: this.getJdkReleaseIdentity(javaRelease),
verification: getJdkVerificationIdentity( verification: getJdkVerificationIdentity(
this.verifySignature, this.verifySignature,
this.verifySignatureExplicitlyRequested,
this.verifySignaturePublicKey this.verifySignaturePublicKey
), ),
path: this.getJdkCachePath(javaRelease.version) path: this.getJdkCachePath(javaRelease.version)
+1 -3
View File
@@ -1,5 +1,3 @@
export type SignatureVerificationKey = string | readonly string[];
export interface JavaInstallerOptions { export interface JavaInstallerOptions {
version: string; version: string;
architecture: string; architecture: string;
@@ -9,7 +7,7 @@ export interface JavaInstallerOptions {
cacheJdk?: boolean; cacheJdk?: boolean;
setDefault?: boolean; setDefault?: boolean;
verifySignature?: boolean; verifySignature?: boolean;
verifySignaturePublicKey?: SignatureVerificationKey; verifySignaturePublicKey?: string;
} }
export interface JavaInstallerResults { export interface JavaInstallerResults {
+1 -1
View File
@@ -65,7 +65,7 @@ export class LocalDistribution extends JavaBase {
architecture: this.architecture, architecture: this.architecture,
version: this.version, version: this.version,
source, source,
verification: getJdkVerificationIdentity(false, false), verification: getJdkVerificationIdentity(false),
path: this.getJdkCachePath(this.version) path: this.getJdkCachePath(this.version)
}; };
} }
+1 -11
View File
@@ -12,7 +12,6 @@ import {
} from '../../util.js'; } from '../../util.js';
import * as gpg from '../../gpg.js'; import * as gpg from '../../gpg.js';
import {MICROSOFT_PUBLIC_KEY} from './microsoft-key.js'; import {MICROSOFT_PUBLIC_KEY} from './microsoft-key.js';
import {SIGNATURE_VERIFICATION_FAILURE_HELP} from '../../constants.js';
import * as core from '@actions/core'; import * as core from '@actions/core';
import * as tc from '@actions/tool-cache'; import * as tc from '@actions/tool-cache';
import fs from 'fs'; import fs from 'fs';
@@ -35,7 +34,6 @@ export class MicrosoftDistributions extends JavaBase {
let javaArchivePath = await this.downloadAndVerify(javaRelease); let javaArchivePath = await this.downloadAndVerify(javaRelease);
if (this.verifySignature) { if (this.verifySignature) {
try {
if (!javaRelease.signatureUrl) { if (!javaRelease.signatureUrl) {
throw new Error( throw new Error(
`Input 'verify-signature' is enabled, but no signature URL was found for Microsoft Build of OpenJDK version ${javaRelease.version}.` `Input 'verify-signature' is enabled, but no signature URL was found for Microsoft Build of OpenJDK version ${javaRelease.version}.`
@@ -50,18 +48,10 @@ export class MicrosoftDistributions extends JavaBase {
); );
} catch (error) { } catch (error) {
throw new Error( throw new Error(
`Failed to verify signature for Microsoft Build of OpenJDK version ${javaRelease.version}. Signature URL: ${javaRelease.signatureUrl}. Error: ${(error as Error).message} ${SIGNATURE_VERIFICATION_FAILURE_HELP}`, `Failed to verify signature for Microsoft Build of OpenJDK version ${javaRelease.version}. Signature URL: ${javaRelease.signatureUrl}. Error: ${(error as Error).message}`,
{cause: error} {cause: error}
); );
} }
} catch (error) {
if (this.verifySignatureExplicitlyRequested) {
throw error;
}
core.warning(
error instanceof Error ? error.message : `Unknown error: ${error}`
);
}
} }
core.info(`Extracting Java archive...`); core.info(`Extracting Java archive...`);
+5 -25
View File
@@ -8,10 +8,7 @@ import * as gpg from '../../gpg.js';
import {ADOPTIUM_PUBLIC_KEY} from './adoptium-key.js'; import {ADOPTIUM_PUBLIC_KEY} from './adoptium-key.js';
import {JavaBase} from '../base-installer.js'; import {JavaBase} from '../base-installer.js';
import {ITemurinAvailableVersions} from './models.js'; import {ITemurinAvailableVersions} from './models.js';
import { import {MACOS_JAVA_CONTENT_POSTFIX} from '../../constants.js';
MACOS_JAVA_CONTENT_POSTFIX,
SIGNATURE_VERIFICATION_FAILURE_HELP
} from '../../constants.js';
import { import {
JavaDownloadRelease, JavaDownloadRelease,
JavaInstallerOptions, JavaInstallerOptions,
@@ -144,12 +141,6 @@ export class TemurinDistribution extends JavaBase {
const archivePath = await this.downloadAndVerify(release); const archivePath = await this.downloadAndVerify(release);
if (this.verifySignature) { if (this.verifySignature) {
try {
if (!(await gpg.isGpgAvailable())) {
throw new Error(
"Input 'verify-signature' is enabled, but gpg is not available."
);
}
if (!release.signatureUrl) { if (!release.signatureUrl) {
throw new Error( throw new Error(
`Input 'verify-signature' is enabled, but no signature URL was found for Temurin version ${release.version}.` `Input 'verify-signature' is enabled, but no signature URL was found for Temurin version ${release.version}.`
@@ -163,23 +154,12 @@ export class TemurinDistribution extends JavaBase {
this.verifySignaturePublicKey ?? ADOPTIUM_PUBLIC_KEY this.verifySignaturePublicKey ?? ADOPTIUM_PUBLIC_KEY
); );
} catch (error) { } catch (error) {
const verificationError = new Error( throw new Error(
`Failed to verify signature for Temurin version ${release.version} from ${release.signatureUrl}: ${(error as Error).message} ${SIGNATURE_VERIFICATION_FAILURE_HELP}`, `Failed to verify signature for Temurin version ${release.version} from ${release.signatureUrl}: ${
(error as Error).message
}`,
{cause: error} {cause: error}
); );
if (this.verifySignatureExplicitlyRequested) {
throw verificationError;
} else {
core.warning(verificationError.message);
}
}
} catch (error) {
if (this.verifySignatureExplicitlyRequested) {
throw error;
}
core.warning(
error instanceof Error ? error.message : `Unknown error: ${error}`
);
} }
} }
+5 -16
View File
@@ -5,16 +5,11 @@ import * as io from '@actions/io';
import * as exec from '@actions/exec'; import * as exec from '@actions/exec';
import * as tc from '@actions/tool-cache'; import * as tc from '@actions/tool-cache';
import * as util from './util.js'; import * as util from './util.js';
import type {ExecOptions} from '@actions/exec'; import {ExecOptions} from '@actions/exec';
import type {SignatureVerificationKey} from './distributions/base-models.js';
export const GPG_HOME_PREFIX = 'setup-java-gpg-'; export const GPG_HOME_PREFIX = 'setup-java-gpg-';
const VERIFY_GPG_HOME_PREFIX = 'verify-signature-gpg-home-'; const VERIFY_GPG_HOME_PREFIX = 'verify-signature-gpg-home-';
export async function isGpgAvailable(): Promise<boolean> {
return Boolean(await io.which('gpg', false));
}
// Convert a Windows path (D:\a\_temp\...) to a POSIX path (/d/a/_temp/...). // Convert a Windows path (D:\a\_temp\...) to a POSIX path (/d/a/_temp/...).
// The Git-bundled GPG on Windows (MSYS2-based) uses POSIX path conventions // The Git-bundled GPG on Windows (MSYS2-based) uses POSIX path conventions
// internally. Passing Windows paths with backslashes can cause fatal GPG errors // internally. Passing Windows paths with backslashes can cause fatal GPG errors
@@ -102,7 +97,7 @@ export async function removeGpgHome(gpgHome: string): Promise<void> {
export async function verifyPackageSignature( export async function verifyPackageSignature(
archivePath: string, archivePath: string,
signatureUrl: string, signatureUrl: string,
publicKeyContent: SignatureVerificationKey publicKeyContent: string
) { ) {
const signaturePath = await tc.downloadTool(signatureUrl); const signaturePath = await tc.downloadTool(signatureUrl);
let gpgHome: string; let gpgHome: string;
@@ -122,14 +117,8 @@ export async function verifyPackageSignature(
); );
} }
try { try {
const publicKeys = Array.isArray(publicKeyContent) const publicKeyFile = path.join(gpgHome, 'public-key.asc');
? publicKeyContent fs.writeFileSync(publicKeyFile, publicKeyContent, {encoding: 'utf-8'});
: [publicKeyContent];
const publicKeyFiles = publicKeys.map((publicKey, index) => {
const publicKeyFile = path.join(gpgHome, `public-key-${index}.asc`);
fs.writeFileSync(publicKeyFile, publicKey, {encoding: 'utf-8'});
return toGpgPath(publicKeyFile);
});
const options: ExecOptions = {silent: true}; const options: ExecOptions = {silent: true};
await exec.exec( await exec.exec(
'gpg', 'gpg',
@@ -138,7 +127,7 @@ export async function verifyPackageSignature(
toGpgPath(gpgHome), toGpgPath(gpgHome),
'--batch', '--batch',
'--import', '--import',
...publicKeyFiles toGpgPath(publicKeyFile)
], ],
options options
); );
+6 -19
View File
@@ -4,7 +4,6 @@ import path from 'path';
import * as cache from '@actions/cache'; import * as cache from '@actions/cache';
import * as core from '@actions/core'; import * as core from '@actions/core';
import {isCacheFeatureAvailable} from './cache-feature.js'; import {isCacheFeatureAvailable} from './cache-feature.js';
import type {SignatureVerificationKey} from './distributions/base-models.js';
const STATE_JDK_CACHES = 'jdk-caches'; const STATE_JDK_CACHES = 'jdk-caches';
const JDK_CACHE_KEY_VERSION = 1; const JDK_CACHE_KEY_VERSION = 1;
@@ -118,30 +117,18 @@ function getInstallationIdentity(
export function getJdkVerificationIdentity( export function getJdkVerificationIdentity(
verifySignature: boolean, verifySignature: boolean,
enforceSignatureVerification: boolean, publicKey?: string
publicKey?: SignatureVerificationKey
): string { ): string {
if (!verifySignature) { if (!verifySignature) {
return 'disabled'; return 'unverified';
} }
const verificationPolicy = enforceSignatureVerification
? 'enforced'
: 'check-and-warn';
if (!publicKey) { if (!publicKey) {
return `${verificationPolicy}:bundled`; return 'verified:bundled';
} }
const publicKeys = Array.isArray(publicKey) ? publicKey : [publicKey]; const normalizedKey = publicKey.replace(/\r\n?/g, '\n').trim();
const normalizedKeys = publicKeys.map(key => const fingerprint = createHash('sha256').update(normalizedKey).digest('hex');
key.replace(/\r\n?/g, '\n').trim() return `verified:custom:sha256:${fingerprint}`;
);
const fingerprintSource = Array.isArray(publicKey)
? normalizedKeys.map(key => `${Buffer.byteLength(key)}:${key}`).join('')
: normalizedKeys[0];
const fingerprint = createHash('sha256')
.update(fingerprintSource)
.digest('hex');
return `${verificationPolicy}:custom:sha256:${fingerprint}`;
} }
export async function saveJdkCaches(): Promise<void> { export async function saveJdkCaches(): Promise<void> {
+5 -11
View File
@@ -29,6 +29,10 @@ export async function run() {
const checkLatest = getBooleanInput(constants.INPUT_CHECK_LATEST, false); const checkLatest = getBooleanInput(constants.INPUT_CHECK_LATEST, false);
const forceDownload = getBooleanInput(constants.INPUT_FORCE_DOWNLOAD, false); const forceDownload = getBooleanInput(constants.INPUT_FORCE_DOWNLOAD, false);
const setDefault = getBooleanInput(constants.INPUT_SET_DEFAULT, true); const setDefault = getBooleanInput(constants.INPUT_SET_DEFAULT, true);
const verifySignature = getBooleanInput(
constants.INPUT_VERIFY_SIGNATURE,
false
);
const verifySignaturePublicKey = const verifySignaturePublicKey =
core.getInput(constants.INPUT_VERIFY_SIGNATURE_PUBLIC_KEY) || undefined; core.getInput(constants.INPUT_VERIFY_SIGNATURE_PUBLIC_KEY) || undefined;
const toolchainIds = core.getMultilineInput(constants.INPUT_MVN_TOOLCHAIN_ID); const toolchainIds = core.getMultilineInput(constants.INPUT_MVN_TOOLCHAIN_ID);
@@ -76,8 +80,6 @@ export async function run() {
); );
} }
const verifySignature = getVerifySignatureInput();
const installerInputsOptions: installerInputsOptions = { const installerInputsOptions: installerInputsOptions = {
architecture, architecture,
packageType, packageType,
@@ -105,8 +107,6 @@ export async function run() {
throw new Error('distribution input is required'); throw new Error('distribution input is required');
} }
const verifySignature = getVerifySignatureInput();
const installerInputsOptions: installerInputsOptions = { const installerInputsOptions: installerInputsOptions = {
architecture, architecture,
packageType, packageType,
@@ -192,12 +192,6 @@ function getJdkFileInput(): string {
return jdkFile || deprecatedJdkFile; return jdkFile || deprecatedJdkFile;
} }
function getVerifySignatureInput(): boolean | undefined {
return core.getInput(constants.INPUT_VERIFY_SIGNATURE).trim()
? getBooleanInput(constants.INPUT_VERIFY_SIGNATURE)
: undefined;
}
async function installVersion( async function installVersion(
version: string, version: string,
options: installerInputsOptions, options: installerInputsOptions,
@@ -269,7 +263,7 @@ interface installerInputsOptions {
forceDownload: boolean; forceDownload: boolean;
cacheJdk: boolean; cacheJdk: boolean;
setDefault: boolean; setDefault: boolean;
verifySignature: boolean | undefined; verifySignature: boolean;
verifySignaturePublicKey: string | undefined; verifySignaturePublicKey: string | undefined;
distributionName: string; distributionName: string;
jdkFile: string; jdkFile: string;