mirror of
				https://gitea.com/actions/checkout.git
				synced 2025-10-26 07:16:33 +00:00 
			
		
		
		
	Compare commits
	
		
			22 Commits
		
	
	
		
			v2.4.1
			...
			fhammerl/b
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
|   | 6f6aa33e7a | ||
|   | ac59398561 | ||
|   | 3ba5ee6fac | ||
|   | 8856415920 | ||
|   | 755da8c3cf | ||
|   | 26d48e8ea1 | ||
|   | bf085276ce | ||
|   | 5c3ccc22eb | ||
|   | 1f9a0c22da | ||
|   | 8230315d06 | ||
|   | 93ea575cb5 | ||
|   | 6a84743051 | ||
|   | e6d535c99c | ||
|   | 2541b1294d | ||
|   | 0ffe6f9c55 | ||
|   | dcd71f6466 | ||
|   | add3486cc3 | ||
| ![dependabot[bot]](/assets/img/avatar_default.png)  | 5126516654 | ||
|   | d50f8ea767 | ||
|   | 2d1c1198e7 | ||
|   | a12a3943b4 | ||
|   | 8f9e05e482 | 
							
								
								
									
										6
									
								
								.github/workflows/check-dist.yml
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										6
									
								
								.github/workflows/check-dist.yml
									
									
									
									
										vendored
									
									
								
							| @@ -22,12 +22,12 @@ jobs: | ||||
|     runs-on: ubuntu-latest | ||||
|  | ||||
|     steps: | ||||
|       - uses: actions/checkout@v2 | ||||
|       - uses: actions/checkout@v3 | ||||
|  | ||||
|       - name: Set Node.js 12.x | ||||
|       - name: Set Node.js 16.x | ||||
|         uses: actions/setup-node@v1 | ||||
|         with: | ||||
|           node-version: 12.x | ||||
|           node-version: 16.x | ||||
|  | ||||
|       - name: Install dependencies | ||||
|         run: npm ci | ||||
|   | ||||
							
								
								
									
										2
									
								
								.github/workflows/codeql-analysis.yml
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										2
									
								
								.github/workflows/codeql-analysis.yml
									
									
									
									
										vendored
									
									
								
							| @@ -39,7 +39,7 @@ jobs: | ||||
|  | ||||
|     steps: | ||||
|     - name: Checkout repository | ||||
|       uses: actions/checkout@v2 | ||||
|       uses: actions/checkout@v3 | ||||
|  | ||||
|     - name: Initialize CodeQL | ||||
|       uses: github/codeql-action/init@v1 | ||||
|   | ||||
							
								
								
									
										2
									
								
								.github/workflows/licensed.yml
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										2
									
								
								.github/workflows/licensed.yml
									
									
									
									
										vendored
									
									
								
							| @@ -9,6 +9,6 @@ jobs: | ||||
|     runs-on: ubuntu-latest | ||||
|     name: Check licenses | ||||
|     steps: | ||||
|       - uses: actions/checkout@v2 | ||||
|       - uses: actions/checkout@v3 | ||||
|       - run: npm ci | ||||
|       - run: npm run licensed-check | ||||
							
								
								
									
										50
									
								
								.github/workflows/test.yml
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										50
									
								
								.github/workflows/test.yml
									
									
									
									
										vendored
									
									
								
							| @@ -13,8 +13,8 @@ jobs: | ||||
|     steps: | ||||
|       - uses: actions/setup-node@v1 | ||||
|         with: | ||||
|           node-version: 12.x | ||||
|       - uses: actions/checkout@v2 | ||||
|           node-version: 16.x | ||||
|       - uses: actions/checkout@v3 | ||||
|       - run: npm ci | ||||
|       - run: npm run build | ||||
|       - run: npm run format-check | ||||
| @@ -32,7 +32,7 @@ jobs: | ||||
|     steps: | ||||
|       # Clone this repo | ||||
|       - name: Checkout | ||||
|         uses: actions/checkout@v2 | ||||
|         uses: actions/checkout@v3 | ||||
|  | ||||
|       # Basic checkout | ||||
|       - name: Checkout basic | ||||
| @@ -142,7 +142,7 @@ jobs: | ||||
|       options: --dns 127.0.0.1 | ||||
|     services: | ||||
|       squid-proxy: | ||||
|         image: datadog/squid:latest | ||||
|         image: ubuntu/squid:latest | ||||
|         ports: | ||||
|           - 3128:3128 | ||||
|     env: | ||||
| @@ -150,7 +150,7 @@ jobs: | ||||
|     steps: | ||||
|       # Clone this repo | ||||
|       - name: Checkout | ||||
|         uses: actions/checkout@v2 | ||||
|         uses: actions/checkout@v3 | ||||
|  | ||||
|       # Basic checkout using git | ||||
|       - name: Checkout basic | ||||
| @@ -182,7 +182,7 @@ jobs: | ||||
|     steps: | ||||
|       # Clone this repo | ||||
|       - name: Checkout | ||||
|         uses: actions/checkout@v2 | ||||
|         uses: actions/checkout@v3 | ||||
|  | ||||
|       # Basic checkout using git | ||||
|       - name: Checkout basic | ||||
| @@ -205,3 +205,41 @@ jobs: | ||||
|           path: basic | ||||
|       - name: Verify basic | ||||
|         run: __test__/verify-basic.sh --archive | ||||
|      | ||||
|   test-git-container: | ||||
|     runs-on: ubuntu-latest | ||||
|     container: bitnami/git:latest | ||||
|     steps: | ||||
|       # Clone this repo | ||||
|       - name: Checkout | ||||
|         uses: actions/checkout@v3 | ||||
|         with: | ||||
|           path: v3 | ||||
|  | ||||
|       # Basic checkout using git | ||||
|       - name: Checkout basic | ||||
|         uses: ./v3 | ||||
|         with: | ||||
|           ref: test-data/v2/basic | ||||
|       - name: Verify basic | ||||
|         run: | | ||||
|           if [ ! -f "./basic-file.txt" ]; then | ||||
|               echo "Expected basic file does not exist" | ||||
|               exit 1 | ||||
|           fi | ||||
|  | ||||
|           # Verify .git folder | ||||
|           if [ ! -d "./.git" ]; then | ||||
|             echo "Expected ./.git folder to exist" | ||||
|             exit 1 | ||||
|           fi | ||||
|  | ||||
|           # Verify auth token | ||||
|           git config --global --add safe.directory "*" | ||||
|           git fetch --no-tags --depth=1 origin +refs/heads/main:refs/remotes/origin/main | ||||
|  | ||||
|       # needed to make checkout post cleanup succeed | ||||
|       - name: Fix Checkout v3 | ||||
|         uses: actions/checkout@v3 | ||||
|         with: | ||||
|           path: v3 | ||||
							
								
								
									
										30
									
								
								.github/workflows/update-main-version.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										30
									
								
								.github/workflows/update-main-version.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,30 @@ | ||||
| name: Update Main Version | ||||
| run-name: Move ${{ github.event.inputs.main_version }} to ${{ github.event.inputs.target }} | ||||
|  | ||||
| on: | ||||
|   workflow_dispatch: | ||||
|     inputs: | ||||
|       target: | ||||
|         description: The tag or reference to use | ||||
|         required: true | ||||
|       main_version: | ||||
|         type: choice | ||||
|         description: The main version to update | ||||
|         options: | ||||
|           - v3 | ||||
|  | ||||
| jobs: | ||||
|   tag: | ||||
|     runs-on: ubuntu-latest | ||||
|     steps: | ||||
|     - uses: actions/checkout@v3 | ||||
|       with: | ||||
|         fetch-depth: 0 | ||||
|     - name: Git config | ||||
|       run: | | ||||
|         git config user.name github-actions | ||||
|         git config user.email github-actions@github.com | ||||
|     - name: Tag new target | ||||
|       run: git tag -f ${{ github.event.inputs.main_version }} ${{ github.event.inputs.target }} | ||||
|     - name: Push new tag | ||||
|       run: git push origin ${{ github.event.inputs.main_version }} --force | ||||
							
								
								
									
										3
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										3
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							| @@ -1,4 +1,5 @@ | ||||
| __test__/_temp | ||||
| _temp/ | ||||
| lib/ | ||||
| node_modules/ | ||||
| node_modules/ | ||||
| .vscode/ | ||||
							
								
								
									
										6
									
								
								.licenses/npm/@actions/core.dep.yml
									
									
									
										generated
									
									
									
								
							
							
						
						
									
										6
									
								
								.licenses/npm/@actions/core.dep.yml
									
									
									
										generated
									
									
									
								
							| @@ -1,9 +1,9 @@ | ||||
| --- | ||||
| name: "@actions/core" | ||||
| version: 1.2.6 | ||||
| version: 1.10.0 | ||||
| type: npm | ||||
| summary:  | ||||
| homepage:  | ||||
| summary: Actions core lib | ||||
| homepage: https://github.com/actions/toolkit/tree/main/packages/core | ||||
| license: mit | ||||
| licenses: | ||||
| - sources: LICENSE.md | ||||
|   | ||||
							
								
								
									
										32
									
								
								.licenses/npm/@actions/http-client-2.0.1.dep.yml
									
									
									
										generated
									
									
									
										Normal file
									
								
							
							
						
						
									
										32
									
								
								.licenses/npm/@actions/http-client-2.0.1.dep.yml
									
									
									
										generated
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,32 @@ | ||||
| --- | ||||
| name: "@actions/http-client" | ||||
| version: 2.0.1 | ||||
| type: npm | ||||
| summary: Actions Http Client | ||||
| homepage: https://github.com/actions/toolkit/tree/main/packages/http-client | ||||
| license: mit | ||||
| licenses: | ||||
| - sources: LICENSE | ||||
|   text: | | ||||
|     Actions Http Client for Node.js | ||||
| 
 | ||||
|     Copyright (c) GitHub, Inc. | ||||
| 
 | ||||
|     All rights reserved. | ||||
| 
 | ||||
|     MIT License | ||||
| 
 | ||||
|     Permission is hereby granted, free of charge, to any person obtaining a copy of this software and | ||||
|     associated documentation files (the "Software"), to deal in the Software without restriction, | ||||
|     including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, | ||||
|     and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, | ||||
|     subject to the following conditions: | ||||
| 
 | ||||
|     The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. | ||||
| 
 | ||||
|     THE SOFTWARE IS PROVIDED *AS IS*, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT | ||||
|     LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN | ||||
|     NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, | ||||
|     WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE | ||||
|     SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. | ||||
| notices: [] | ||||
							
								
								
									
										6
									
								
								.licenses/npm/@actions/io.dep.yml
									
									
									
										generated
									
									
									
								
							
							
						
						
									
										6
									
								
								.licenses/npm/@actions/io.dep.yml
									
									
									
										generated
									
									
									
								
							| @@ -1,13 +1,15 @@ | ||||
| --- | ||||
| name: "@actions/io" | ||||
| version: 1.0.1 | ||||
| version: 1.1.2 | ||||
| type: npm | ||||
| summary: Actions io lib | ||||
| homepage: https://github.com/actions/toolkit/tree/master/packages/io | ||||
| homepage: https://github.com/actions/toolkit/tree/main/packages/io | ||||
| license: mit | ||||
| licenses: | ||||
| - sources: LICENSE.md | ||||
|   text: |- | ||||
|     The MIT License (MIT) | ||||
| 
 | ||||
|     Copyright 2019 GitHub | ||||
| 
 | ||||
|     Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: | ||||
|   | ||||
							
								
								
									
										2
									
								
								.licenses/npm/node-fetch.dep.yml
									
									
									
										generated
									
									
									
								
							
							
						
						
									
										2
									
								
								.licenses/npm/node-fetch.dep.yml
									
									
									
										generated
									
									
									
								
							| @@ -1,6 +1,6 @@ | ||||
| --- | ||||
| name: node-fetch | ||||
| version: 2.6.5 | ||||
| version: 2.6.7 | ||||
| type: npm | ||||
| summary: A light-weight module that brings window.fetch to node.js | ||||
| homepage: https://github.com/bitinn/node-fetch | ||||
|   | ||||
							
								
								
									
										2
									
								
								.licenses/npm/qs.dep.yml
									
									
									
										generated
									
									
									
								
							
							
						
						
									
										2
									
								
								.licenses/npm/qs.dep.yml
									
									
									
										generated
									
									
									
								
							| @@ -1,6 +1,6 @@ | ||||
| --- | ||||
| name: qs | ||||
| version: 6.10.1 | ||||
| version: 6.11.0 | ||||
| type: npm | ||||
| summary: A querystring parser that supports nesting and arrays, with a depth limit | ||||
| homepage: https://github.com/ljharb/qs | ||||
|   | ||||
							
								
								
									
										20
									
								
								.licenses/npm/uuid-8.3.2.dep.yml
									
									
									
										generated
									
									
									
										Normal file
									
								
							
							
						
						
									
										20
									
								
								.licenses/npm/uuid-8.3.2.dep.yml
									
									
									
										generated
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,20 @@ | ||||
| --- | ||||
| name: uuid | ||||
| version: 8.3.2 | ||||
| type: npm | ||||
| summary: RFC4122 (v1, v4, and v5) UUIDs | ||||
| homepage: https://github.com/uuidjs/uuid#readme | ||||
| license: mit | ||||
| licenses: | ||||
| - sources: LICENSE.md | ||||
|   text: | | ||||
|     The MIT License (MIT) | ||||
| 
 | ||||
|     Copyright (c) 2010-2020 Robert Kieffer and other contributors | ||||
| 
 | ||||
|     Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: | ||||
| 
 | ||||
|     The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. | ||||
| 
 | ||||
|     THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. | ||||
| notices: [] | ||||
							
								
								
									
										17
									
								
								CHANGELOG.md
									
									
									
									
									
								
							
							
						
						
									
										17
									
								
								CHANGELOG.md
									
									
									
									
									
								
							| @@ -1,13 +1,24 @@ | ||||
| # Changelog | ||||
|  | ||||
| ## v2.4.1 | ||||
| - [Set the safe directory option on git to prevent git commands failing when running in containers](https://github.com/actions/checkout/pull/762) | ||||
| ## v3.1.0 | ||||
| - [Use @actions/core `saveState` and `getState`](https://github.com/actions/checkout/pull/939) | ||||
| - [Add `github-server-url` input](https://github.com/actions/checkout/pull/922) | ||||
|  | ||||
| ## v3.0.2 | ||||
| - [Add input `set-safe-directory`](https://github.com/actions/checkout/pull/770) | ||||
|  | ||||
| ## v3.0.1 | ||||
| - [Fixed an issue where checkout failed to run in container jobs due to the new git setting `safe.directory`](https://github.com/actions/checkout/pull/762) | ||||
| - [Bumped various npm package versions](https://github.com/actions/checkout/pull/744) | ||||
|  | ||||
| ## v3.0.0 | ||||
|  | ||||
| - [Update to node 16](https://github.com/actions/checkout/pull/689) | ||||
|  | ||||
| ## v2.3.1 | ||||
|  | ||||
| - [Fix default branch resolution for .wiki and when using SSH](https://github.com/actions/checkout/pull/284) | ||||
|  | ||||
|  | ||||
| ## v2.3.0 | ||||
|  | ||||
| - [Fallback to the default branch](https://github.com/actions/checkout/pull/278) | ||||
|   | ||||
							
								
								
									
										28
									
								
								CONTRIBUTING.md
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										28
									
								
								CONTRIBUTING.md
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,28 @@ | ||||
| # Contributing | ||||
|  | ||||
| ## Submitting a pull request | ||||
|  | ||||
| 1. Fork and clone the repository | ||||
| 1. Configure and install the dependencies: `npm install` | ||||
| 1. Create a new branch: `git checkout -b my-branch-name` | ||||
| 1. Make your change, add tests, and make sure the tests still pass: `npm run test` | ||||
| 1. Make sure your code is correctly formatted: `npm run format` | ||||
| 1. Update `dist/index.js` using `npm run build`. This creates a single javascript file that is used as an entrypoint for the action | ||||
| 1. Push to your fork and submit a pull request | ||||
| 1. Pat yourself on the back and wait for your pull request to be reviewed and merged | ||||
|  | ||||
| Here are a few things you can do that will increase the likelihood of your pull request being accepted: | ||||
|  | ||||
| - Write tests. | ||||
| - Keep your change as focused as possible. If there are multiple changes you would like to make that are not dependent upon each other, consider submitting them as separate pull requests. | ||||
|  | ||||
| ## Resources | ||||
|  | ||||
| - [How to Contribute to Open Source](https://opensource.guide/how-to-contribute/) | ||||
| - [Using Pull Requests](https://help.github.com/articles/about-pull-requests/) | ||||
| - [GitHub Help](https://help.github.com) | ||||
| - [Writing good commit messages](http://tbaggery.com/2008/04/19/a-note-about-git-commit-messages.html) | ||||
|  | ||||
| Thanks! :heart: :heart: :heart: | ||||
|  | ||||
| GitHub Actions Team :octocat: | ||||
							
								
								
									
										62
									
								
								README.md
									
									
									
									
									
								
							
							
						
						
									
										62
									
								
								README.md
									
									
									
									
									
								
							| @@ -1,8 +1,6 @@ | ||||
| <p align="center"> | ||||
|   <a href="https://github.com/actions/checkout"><img alt="GitHub Actions status" src="https://github.com/actions/checkout/workflows/test-local/badge.svg"></a> | ||||
| </p> | ||||
| [](https://github.com/actions/checkout/actions/workflows/test.yml) | ||||
|  | ||||
| # Checkout V2 | ||||
| # Checkout V3 | ||||
|  | ||||
| This action checks-out your repository under `$GITHUB_WORKSPACE`, so your workflow can access it. | ||||
|  | ||||
| @@ -14,27 +12,14 @@ When Git 2.18 or higher is not in your PATH, falls back to the REST API to downl | ||||
|  | ||||
| # What's new | ||||
|  | ||||
| - Improved performance | ||||
|   - Fetches only a single commit by default | ||||
| - Script authenticated git commands | ||||
|   - Auth token persisted in the local git config | ||||
| - Supports SSH | ||||
| - Creates a local branch | ||||
|   - No longer detached HEAD when checking out a branch | ||||
| - Improved layout | ||||
|   - The input `path` is always relative to $GITHUB_WORKSPACE | ||||
|   - Aligns better with container actions, where $GITHUB_WORKSPACE gets mapped in | ||||
| - Fallback to REST API download | ||||
|   - When Git 2.18 or higher is not in the PATH, the REST API will be used to download the files | ||||
|   - When using a job container, the container's PATH is used | ||||
|  | ||||
| Refer [here](https://github.com/actions/checkout/blob/v1/README.md) for previous versions. | ||||
| - Updated to the node16 runtime by default | ||||
|   - This requires a minimum [Actions Runner](https://github.com/actions/runner/releases/tag/v2.285.0) version of v2.285.0 to run, which is by default available in GHES 3.4 or later. | ||||
|  | ||||
| # Usage | ||||
|  | ||||
| <!-- start usage --> | ||||
| ```yaml | ||||
| - uses: actions/checkout@v2 | ||||
| - uses: actions/checkout@v3 | ||||
|   with: | ||||
|     # Repository name with owner. For example, actions/checkout | ||||
|     # Default: ${{ github.repository }} | ||||
| @@ -105,6 +90,17 @@ Refer [here](https://github.com/actions/checkout/blob/v1/README.md) for previous | ||||
|     # | ||||
|     # Default: false | ||||
|     submodules: '' | ||||
|  | ||||
|     # Add repository path as safe.directory for Git global config by running `git | ||||
|     # config --global --add safe.directory <path>` | ||||
|     # Default: true | ||||
|     set-safe-directory: '' | ||||
|  | ||||
|     # The base URL for the GitHub instance that you are trying to clone from, will use | ||||
|     # environment defaults to fetch from the same instance that the workflow is | ||||
|     # running from unless specified. Example URLs are https://github.com or | ||||
|     # https://my-ghes-server.example.com | ||||
|     github-server-url: '' | ||||
| ``` | ||||
| <!-- end usage --> | ||||
|  | ||||
| @@ -123,7 +119,7 @@ Refer [here](https://github.com/actions/checkout/blob/v1/README.md) for previous | ||||
| ## Fetch all history for all tags and branches | ||||
|  | ||||
| ```yaml | ||||
| - uses: actions/checkout@v2 | ||||
| - uses: actions/checkout@v3 | ||||
|   with: | ||||
|     fetch-depth: 0 | ||||
| ``` | ||||
| @@ -131,7 +127,7 @@ Refer [here](https://github.com/actions/checkout/blob/v1/README.md) for previous | ||||
| ## Checkout a different branch | ||||
|  | ||||
| ```yaml | ||||
| - uses: actions/checkout@v2 | ||||
| - uses: actions/checkout@v3 | ||||
|   with: | ||||
|     ref: my-branch | ||||
| ``` | ||||
| @@ -139,7 +135,7 @@ Refer [here](https://github.com/actions/checkout/blob/v1/README.md) for previous | ||||
| ## Checkout HEAD^ | ||||
|  | ||||
| ```yaml | ||||
| - uses: actions/checkout@v2 | ||||
| - uses: actions/checkout@v3 | ||||
|   with: | ||||
|     fetch-depth: 2 | ||||
| - run: git checkout HEAD^ | ||||
| @@ -149,40 +145,42 @@ Refer [here](https://github.com/actions/checkout/blob/v1/README.md) for previous | ||||
|  | ||||
| ```yaml | ||||
| - name: Checkout | ||||
|   uses: actions/checkout@v2 | ||||
|   uses: actions/checkout@v3 | ||||
|   with: | ||||
|     path: main | ||||
|  | ||||
| - name: Checkout tools repo | ||||
|   uses: actions/checkout@v2 | ||||
|   uses: actions/checkout@v3 | ||||
|   with: | ||||
|     repository: my-org/my-tools | ||||
|     path: my-tools | ||||
| ``` | ||||
| > - If your secondary repository is private you will need to add the option noted in [Checkout multiple repos (private)](#Checkout-multiple-repos-private) | ||||
|  | ||||
| ## Checkout multiple repos (nested) | ||||
|  | ||||
| ```yaml | ||||
| - name: Checkout | ||||
|   uses: actions/checkout@v2 | ||||
|   uses: actions/checkout@v3 | ||||
|  | ||||
| - name: Checkout tools repo | ||||
|   uses: actions/checkout@v2 | ||||
|   uses: actions/checkout@v3 | ||||
|   with: | ||||
|     repository: my-org/my-tools | ||||
|     path: my-tools | ||||
| ``` | ||||
| > - If your secondary repository is private you will need to add the option noted in [Checkout multiple repos (private)](#Checkout-multiple-repos-private) | ||||
|  | ||||
| ## Checkout multiple repos (private) | ||||
|  | ||||
| ```yaml | ||||
| - name: Checkout | ||||
|   uses: actions/checkout@v2 | ||||
|   uses: actions/checkout@v3 | ||||
|   with: | ||||
|     path: main | ||||
|  | ||||
| - name: Checkout private tools | ||||
|   uses: actions/checkout@v2 | ||||
|   uses: actions/checkout@v3 | ||||
|   with: | ||||
|     repository: my-org/my-private-tools | ||||
|     token: ${{ secrets.GH_PAT }} # `GH_PAT` is a secret that contains your PAT | ||||
| @@ -195,7 +193,7 @@ Refer [here](https://github.com/actions/checkout/blob/v1/README.md) for previous | ||||
| ## Checkout pull request HEAD commit instead of merge commit | ||||
|  | ||||
| ```yaml | ||||
| - uses: actions/checkout@v2 | ||||
| - uses: actions/checkout@v3 | ||||
|   with: | ||||
|     ref: ${{ github.event.pull_request.head.sha }} | ||||
| ``` | ||||
| @@ -211,7 +209,7 @@ jobs: | ||||
|   build: | ||||
|     runs-on: ubuntu-latest | ||||
|     steps: | ||||
|       - uses: actions/checkout@v2 | ||||
|       - uses: actions/checkout@v3 | ||||
| ``` | ||||
|  | ||||
| ## Push a commit using the built-in token | ||||
| @@ -222,7 +220,7 @@ jobs: | ||||
|   build: | ||||
|     runs-on: ubuntu-latest | ||||
|     steps: | ||||
|       - uses: actions/checkout@v2 | ||||
|       - uses: actions/checkout@v3 | ||||
|       - run: | | ||||
|           date > generated.txt | ||||
|           git config user.name github-actions | ||||
|   | ||||
| @@ -20,6 +20,7 @@ let tempHomedir: string | ||||
| let git: IGitCommandManager & {env: {[key: string]: string}} | ||||
| let settings: IGitSourceSettings | ||||
| let sshPath: string | ||||
| let githubServerUrl: string | ||||
|  | ||||
| describe('git-auth-helper tests', () => { | ||||
|   beforeAll(async () => { | ||||
| @@ -67,11 +68,18 @@ describe('git-auth-helper tests', () => { | ||||
|     } | ||||
|   }) | ||||
|  | ||||
|   const configureAuth_configuresAuthHeader = | ||||
|     'configureAuth configures auth header' | ||||
|   it(configureAuth_configuresAuthHeader, async () => { | ||||
|   async function testAuthHeader( | ||||
|     testName: string, | ||||
|     serverUrl: string | undefined = undefined | ||||
|   ) { | ||||
|     // Arrange | ||||
|     await setup(configureAuth_configuresAuthHeader) | ||||
|     let expectedServerUrl = 'https://github.com' | ||||
|     if (serverUrl) { | ||||
|       githubServerUrl = serverUrl | ||||
|       expectedServerUrl = githubServerUrl | ||||
|     } | ||||
|  | ||||
|     await setup(testName) | ||||
|     expect(settings.authToken).toBeTruthy() // sanity check | ||||
|     const authHelper = gitAuthHelper.createAuthHelper(git, settings) | ||||
|  | ||||
| @@ -88,9 +96,33 @@ describe('git-auth-helper tests', () => { | ||||
|     ).toString('base64') | ||||
|     expect( | ||||
|       configContent.indexOf( | ||||
|         `http.https://github.com/.extraheader AUTHORIZATION: basic ${basicCredential}` | ||||
|         `http.${expectedServerUrl}/.extraheader AUTHORIZATION: basic ${basicCredential}` | ||||
|       ) | ||||
|     ).toBeGreaterThanOrEqual(0) | ||||
|   } | ||||
|  | ||||
|   const configureAuth_configuresAuthHeader = | ||||
|     'configureAuth configures auth header' | ||||
|   it(configureAuth_configuresAuthHeader, async () => { | ||||
|     await testAuthHeader(configureAuth_configuresAuthHeader) | ||||
|   }) | ||||
|  | ||||
|   const configureAuth_AcceptsGitHubServerUrl = | ||||
|     'inject https://my-ghes-server.com as github server url' | ||||
|   it(configureAuth_AcceptsGitHubServerUrl, async () => { | ||||
|     await testAuthHeader( | ||||
|       configureAuth_AcceptsGitHubServerUrl, | ||||
|       'https://my-ghes-server.com' | ||||
|     ) | ||||
|   }) | ||||
|  | ||||
|   const configureAuth_AcceptsGitHubServerUrlSetToGHEC = | ||||
|     'inject https://github.com as github server url' | ||||
|   it(configureAuth_AcceptsGitHubServerUrlSetToGHEC, async () => { | ||||
|     await testAuthHeader( | ||||
|       configureAuth_AcceptsGitHubServerUrl, | ||||
|       'https://github.com' | ||||
|     ) | ||||
|   }) | ||||
|  | ||||
|   const configureAuth_configuresAuthHeaderEvenWhenPersistCredentialsFalse = | ||||
| @@ -777,7 +809,9 @@ async function setup(testName: string): Promise<void> { | ||||
|     sshKey: sshPath ? 'some ssh private key' : '', | ||||
|     sshKnownHosts: '', | ||||
|     sshStrict: true, | ||||
|     workflowOrganizationId: 123456 | ||||
|     workflowOrganizationId: 123456, | ||||
|     setSafeDirectory: true, | ||||
|     githubServerUrl: githubServerUrl | ||||
|   } | ||||
| } | ||||
|  | ||||
|   | ||||
							
								
								
									
										80
									
								
								__test__/git-command-manager.test.ts
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										80
									
								
								__test__/git-command-manager.test.ts
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,80 @@ | ||||
| import * as exec from '@actions/exec' | ||||
| import * as fshelper from '../lib/fs-helper' | ||||
| import * as commandManager from '../lib/git-command-manager' | ||||
|  | ||||
| let git: commandManager.IGitCommandManager | ||||
| let mockExec = jest.fn() | ||||
|  | ||||
| describe('git-auth-helper tests', () => { | ||||
|   beforeAll(async () => {}) | ||||
|  | ||||
|   beforeEach(async () => { | ||||
|     jest.spyOn(fshelper, 'fileExistsSync').mockImplementation(jest.fn()) | ||||
|     jest.spyOn(fshelper, 'directoryExistsSync').mockImplementation(jest.fn()) | ||||
|   }) | ||||
|  | ||||
|   afterEach(() => { | ||||
|     jest.restoreAllMocks() | ||||
|   }) | ||||
|  | ||||
|   afterAll(() => {}) | ||||
|  | ||||
|   it('branch list matches', async () => { | ||||
|     mockExec.mockImplementation((path, args, options) => { | ||||
|       console.log(args, options.listeners.stdout) | ||||
|  | ||||
|       if (args.includes('version')) { | ||||
|         options.listeners.stdout(Buffer.from('2.18')) | ||||
|         return 0 | ||||
|       } | ||||
|  | ||||
|       if (args.includes('rev-parse')) { | ||||
|         options.listeners.stdline(Buffer.from('refs/heads/foo')) | ||||
|         options.listeners.stdline(Buffer.from('refs/heads/bar')) | ||||
|         return 0 | ||||
|       } | ||||
|  | ||||
|       return 1 | ||||
|     }) | ||||
|     jest.spyOn(exec, 'exec').mockImplementation(mockExec) | ||||
|     const workingDirectory = 'test' | ||||
|     const lfs = false | ||||
|     git = await commandManager.createCommandManager(workingDirectory, lfs) | ||||
|  | ||||
|     let branches = await git.branchList(false) | ||||
|  | ||||
|     expect(branches).toHaveLength(2) | ||||
|     expect(branches.sort()).toEqual(['foo', 'bar'].sort()) | ||||
|   }) | ||||
|  | ||||
|   it('ambiguous ref name output is captured', async () => { | ||||
|     mockExec.mockImplementation((path, args, options) => { | ||||
|       console.log(args, options.listeners.stdout) | ||||
|  | ||||
|       if (args.includes('version')) { | ||||
|         options.listeners.stdout(Buffer.from('2.18')) | ||||
|         return 0 | ||||
|       } | ||||
|  | ||||
|       if (args.includes('rev-parse')) { | ||||
|         options.listeners.stdline(Buffer.from('refs/heads/foo')) | ||||
|         // If refs/tags/v1 and refs/heads/tags/v1 existed on this repository | ||||
|         options.listeners.errline( | ||||
|           Buffer.from("error: refname 'tags/v1' is ambiguous") | ||||
|         ) | ||||
|         return 0 | ||||
|       } | ||||
|  | ||||
|       return 1 | ||||
|     }) | ||||
|     jest.spyOn(exec, 'exec').mockImplementation(mockExec) | ||||
|     const workingDirectory = 'test' | ||||
|     const lfs = false | ||||
|     git = await commandManager.createCommandManager(workingDirectory, lfs) | ||||
|  | ||||
|     let branches = await git.branchList(false) | ||||
|  | ||||
|     expect(branches).toHaveLength(1) | ||||
|     expect(branches.sort()).toEqual(['foo'].sort()) | ||||
|   }) | ||||
| }) | ||||
| @@ -85,6 +85,7 @@ describe('input-helper tests', () => { | ||||
|     expect(settings.repositoryName).toBe('some-repo') | ||||
|     expect(settings.repositoryOwner).toBe('some-owner') | ||||
|     expect(settings.repositoryPath).toBe(gitHubWorkspace) | ||||
|     expect(settings.setSafeDirectory).toBe(true) | ||||
|   }) | ||||
|  | ||||
|   it('qualifies ref', async () => { | ||||
|   | ||||
| @@ -68,7 +68,13 @@ inputs: | ||||
|       When the `ssh-key` input is not provided, SSH URLs beginning with `git@github.com:` are | ||||
|       converted to HTTPS. | ||||
|     default: false | ||||
|   set-safe-directory: | ||||
|     description: Add repository path as safe.directory for Git global config by running `git config --global --add safe.directory <path>` | ||||
|     default: true | ||||
|   github-server-url: | ||||
|     description: The base URL for the GitHub instance that you are trying to clone from, will use environment defaults to fetch from the same instance that the workflow is running from unless specified. Example URLs are https://github.com or https://my-ghes-server.example.com | ||||
|     required: false | ||||
| runs: | ||||
|   using: node12 | ||||
|   using: node16 | ||||
|   main: dist/index.js | ||||
|   post: dist/index.js | ||||
|   | ||||
							
								
								
									
										3457
									
								
								dist/index.js
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										3457
									
								
								dist/index.js
									
									
									
									
										vendored
									
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										22768
									
								
								package-lock.json
									
									
									
										generated
									
									
									
								
							
							
						
						
									
										22768
									
								
								package-lock.json
									
									
									
										generated
									
									
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										15
									
								
								package.json
									
									
									
									
									
								
							
							
						
						
									
										15
									
								
								package.json
									
									
									
									
									
								
							| @@ -1,6 +1,6 @@ | ||||
| { | ||||
|   "name": "checkout", | ||||
|   "version": "2.0.2", | ||||
|   "version": "3.2.0", | ||||
|   "description": "checkout action", | ||||
|   "main": "lib/main.js", | ||||
|   "scripts": { | ||||
| @@ -28,22 +28,23 @@ | ||||
|   }, | ||||
|   "homepage": "https://github.com/actions/checkout#readme", | ||||
|   "dependencies": { | ||||
|     "@actions/core": "^1.2.6", | ||||
|     "@actions/core": "^1.10.0", | ||||
|     "@actions/exec": "^1.0.1", | ||||
|     "@actions/github": "^2.2.0", | ||||
|     "@actions/io": "^1.0.1", | ||||
|     "@actions/tool-cache": "^1.1.2", | ||||
|     "@actions/github": "^5.0.0", | ||||
|     "@actions/io": "^1.1.2", | ||||
|     "@actions/tool-cache": "^2.0.0", | ||||
|     "uuid": "^3.3.3" | ||||
|   }, | ||||
|   "devDependencies": { | ||||
|     "@types/jest": "^27.0.2", | ||||
|     "@types/node": "^12.7.12", | ||||
|     "@types/uuid": "^3.4.6", | ||||
|     "@typescript-eslint/parser": "^5.1.0", | ||||
|     "@typescript-eslint/eslint-plugin": "^5.45.0", | ||||
|     "@typescript-eslint/parser": "^5.45.0", | ||||
|     "@zeit/ncc": "^0.20.5", | ||||
|     "eslint": "^7.32.0", | ||||
|     "eslint-plugin-github": "^4.3.2", | ||||
|     "eslint-plugin-jest": "^25.2.2", | ||||
|     "eslint-plugin-jest": "^25.7.0", | ||||
|     "jest": "^27.3.0", | ||||
|     "jest-circus": "^27.3.0", | ||||
|     "js-yaml": "^3.13.1", | ||||
|   | ||||
| @@ -19,7 +19,7 @@ export interface IGitAuthHelper { | ||||
|   configureAuth(): Promise<void> | ||||
|   configureGlobalAuth(): Promise<void> | ||||
|   configureSubmoduleAuth(): Promise<void> | ||||
|   configureTempGlobalConfig(repositoryPath?: string): Promise<string> | ||||
|   configureTempGlobalConfig(): Promise<string> | ||||
|   removeAuth(): Promise<void> | ||||
|   removeGlobalConfig(): Promise<void> | ||||
| } | ||||
| @@ -52,7 +52,7 @@ class GitAuthHelper { | ||||
|     this.settings = gitSourceSettings || (({} as unknown) as IGitSourceSettings) | ||||
|  | ||||
|     // Token auth header | ||||
|     const serverUrl = urlHelper.getServerUrl() | ||||
|     const serverUrl = urlHelper.getServerUrl(this.settings.githubServerUrl) | ||||
|     this.tokenConfigKey = `http.${serverUrl.origin}/.extraheader` // "origin" is SCHEME://HOSTNAME[:PORT] | ||||
|     const basicCredential = Buffer.from( | ||||
|       `x-access-token:${this.settings.authToken}`, | ||||
| @@ -81,7 +81,7 @@ class GitAuthHelper { | ||||
|     await this.configureToken() | ||||
|   } | ||||
|  | ||||
|   async configureTempGlobalConfig(repositoryPath?: string): Promise<string> { | ||||
|   async configureTempGlobalConfig(): Promise<string> { | ||||
|     // Already setup global config | ||||
|     if (this.temporaryHomePath?.length > 0) { | ||||
|       return path.join(this.temporaryHomePath, '.gitconfig') | ||||
| @@ -121,21 +121,6 @@ class GitAuthHelper { | ||||
|     ) | ||||
|     this.git.setEnvironmentVariable('HOME', this.temporaryHomePath) | ||||
|  | ||||
|     // Setup the workspace as a safe directory, so if we pass this into a container job with a different user it doesn't fail | ||||
|     // Otherwise all git commands we run in a container fail | ||||
|     core.info( | ||||
|       `Adding working directory to the temporary git global config as a safe directory` | ||||
|     ) | ||||
|     await this.git | ||||
|       .config( | ||||
|         'safe.directory', | ||||
|         repositoryPath ?? this.settings.repositoryPath, | ||||
|         true, | ||||
|         true | ||||
|       ) | ||||
|       .catch(error => { | ||||
|         core.info(`Failed to initialize safe directory with error: ${error}`) | ||||
|       }) | ||||
|     return newGitConfigPath | ||||
|   } | ||||
|  | ||||
| @@ -172,7 +157,8 @@ class GitAuthHelper { | ||||
|       // by process creation audit events, which are commonly logged. For more information, | ||||
|       // refer to https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/component-updates/command-line-process-auditing | ||||
|       const output = await this.git.submoduleForeach( | ||||
|         `git config --local '${this.tokenConfigKey}' '${this.tokenPlaceholderConfigValue}' && git config --local --show-origin --name-only --get-regexp remote.origin.url`, | ||||
|         // wrap the pipeline in quotes to make sure it's handled properly by submoduleForeach, rather than just the first part of the pipeline | ||||
|         `sh -c "git config --local '${this.tokenConfigKey}' '${this.tokenPlaceholderConfigValue}' && git config --local --show-origin --name-only --get-regexp remote.origin.url"`, | ||||
|         this.settings.nestedSubmodules | ||||
|       ) | ||||
|  | ||||
| @@ -380,7 +366,8 @@ class GitAuthHelper { | ||||
|  | ||||
|     const pattern = regexpHelper.escape(configKey) | ||||
|     await this.git.submoduleForeach( | ||||
|       `git config --local --name-only --get-regexp '${pattern}' && git config --local --unset-all '${configKey}' || :`, | ||||
|       // wrap the pipeline in quotes to make sure it's handled properly by submoduleForeach, rather than just the first part of the pipeline | ||||
|       `sh -c "git config --local --name-only --get-regexp '${pattern}' && git config --local --unset-all '${configKey}' || :"`, | ||||
|       true | ||||
|     ) | ||||
|   } | ||||
|   | ||||
| @@ -94,8 +94,11 @@ class GitCommandManager { | ||||
|  | ||||
|     // Note, this implementation uses "rev-parse --symbolic-full-name" because the output from | ||||
|     // "branch --list" is more difficult when in a detached HEAD state. | ||||
|     // Note, this implementation uses "rev-parse --symbolic-full-name" because there is a bug | ||||
|     // in Git 2.18 that causes "rev-parse --symbolic" to output symbolic full names. | ||||
|  | ||||
|     // TODO(https://github.com/actions/checkout/issues/786): this implementation uses | ||||
|     // "rev-parse --symbolic-full-name" because there is a bug | ||||
|     // in Git 2.18 that causes "rev-parse --symbolic" to output symbolic full names. When | ||||
|     // 2.18 is no longer supported, we can switch back to --symbolic. | ||||
|  | ||||
|     const args = ['rev-parse', '--symbolic-full-name'] | ||||
|     if (remote) { | ||||
| @@ -104,21 +107,49 @@ class GitCommandManager { | ||||
|       args.push('--branches') | ||||
|     } | ||||
|  | ||||
|     const output = await this.execGit(args) | ||||
|     const stderr: string[] = [] | ||||
|     const errline: string[] = [] | ||||
|     const stdout: string[] = [] | ||||
|     const stdline: string[] = [] | ||||
|  | ||||
|     for (let branch of output.stdout.trim().split('\n')) { | ||||
|       branch = branch.trim() | ||||
|       if (branch) { | ||||
|         if (branch.startsWith('refs/heads/')) { | ||||
|           branch = branch.substr('refs/heads/'.length) | ||||
|         } else if (branch.startsWith('refs/remotes/')) { | ||||
|           branch = branch.substr('refs/remotes/'.length) | ||||
|         } | ||||
|  | ||||
|         result.push(branch) | ||||
|     const listeners = { | ||||
|       stderr: (data: Buffer) => { | ||||
|         stderr.push(data.toString()) | ||||
|       }, | ||||
|       errline: (data: Buffer) => { | ||||
|         errline.push(data.toString()) | ||||
|       }, | ||||
|       stdout: (data: Buffer) => { | ||||
|         stdout.push(data.toString()) | ||||
|       }, | ||||
|       stdline: (data: Buffer) => { | ||||
|         stdline.push(data.toString()) | ||||
|       } | ||||
|     } | ||||
|  | ||||
|     // Suppress the output in order to avoid flooding annotations with innocuous errors. | ||||
|     await this.execGit(args, false, true, listeners) | ||||
|  | ||||
|     core.debug(`stderr callback is: ${stderr}`) | ||||
|     core.debug(`errline callback is: ${errline}`) | ||||
|     core.debug(`stdout callback is: ${stdout}`) | ||||
|     core.debug(`stdline callback is: ${stdline}`) | ||||
|  | ||||
|     for (let branch of stdline) { | ||||
|       branch = branch.trim() | ||||
|       if (!branch) { | ||||
|         continue | ||||
|       } | ||||
|  | ||||
|       if (branch.startsWith('refs/heads/')) { | ||||
|         branch = branch.substring('refs/heads/'.length) | ||||
|       } else if (branch.startsWith('refs/remotes/')) { | ||||
|         branch = branch.substring('refs/remotes/'.length) | ||||
|       } | ||||
|  | ||||
|       result.push(branch) | ||||
|     } | ||||
|  | ||||
|     return result | ||||
|   } | ||||
|  | ||||
| @@ -395,7 +426,8 @@ class GitCommandManager { | ||||
|   private async execGit( | ||||
|     args: string[], | ||||
|     allowAllExitCodes = false, | ||||
|     silent = false | ||||
|     silent = false, | ||||
|     customListeners = {} | ||||
|   ): Promise<GitOutput> { | ||||
|     fshelper.directoryExistsSync(this.workingDirectory, true) | ||||
|  | ||||
| @@ -409,22 +441,29 @@ class GitCommandManager { | ||||
|       env[key] = this.gitEnv[key] | ||||
|     } | ||||
|  | ||||
|     const stdout: string[] = [] | ||||
|     const defaultListener = { | ||||
|       stdout: (data: Buffer) => { | ||||
|         stdout.push(data.toString()) | ||||
|       } | ||||
|     } | ||||
|  | ||||
|     const mergedListeners = {...defaultListener, ...customListeners} | ||||
|  | ||||
|     const stdout: string[] = [] | ||||
|     const options = { | ||||
|       cwd: this.workingDirectory, | ||||
|       env, | ||||
|       silent, | ||||
|       ignoreReturnCode: allowAllExitCodes, | ||||
|       listeners: { | ||||
|         stdout: (data: Buffer) => { | ||||
|           stdout.push(data.toString()) | ||||
|         } | ||||
|       } | ||||
|       listeners: mergedListeners | ||||
|     } | ||||
|  | ||||
|     result.exitCode = await exec.exec(`"${this.gitPath}"`, args, options) | ||||
|     result.stdout = stdout.join('') | ||||
|  | ||||
|     core.debug(result.exitCode.toString()) | ||||
|     core.debug(result.stdout) | ||||
|  | ||||
|     return result | ||||
|   } | ||||
|  | ||||
|   | ||||
| @@ -40,7 +40,24 @@ export async function getSource(settings: IGitSourceSettings): Promise<void> { | ||||
|   try { | ||||
|     if (git) { | ||||
|       authHelper = gitAuthHelper.createAuthHelper(git, settings) | ||||
|       await authHelper.configureTempGlobalConfig() | ||||
|       if (settings.setSafeDirectory) { | ||||
|         // Setup the repository path as a safe directory, so if we pass this into a container job with a different user it doesn't fail | ||||
|         // Otherwise all git commands we run in a container fail | ||||
|         await authHelper.configureTempGlobalConfig() | ||||
|         core.info( | ||||
|           `Adding repository directory to the temporary git global config as a safe directory` | ||||
|         ) | ||||
|  | ||||
|         await git | ||||
|           .config('safe.directory', settings.repositoryPath, true, true) | ||||
|           .catch(error => { | ||||
|             core.info( | ||||
|               `Failed to initialize safe directory with error: ${error}` | ||||
|             ) | ||||
|           }) | ||||
|  | ||||
|         stateHelper.setSafeDirectory() | ||||
|       } | ||||
|     } | ||||
|  | ||||
|     // Prepare existing directory, otherwise recreate | ||||
| @@ -76,7 +93,8 @@ export async function getSource(settings: IGitSourceSettings): Promise<void> { | ||||
|         settings.repositoryName, | ||||
|         settings.ref, | ||||
|         settings.commit, | ||||
|         settings.repositoryPath | ||||
|         settings.repositoryPath, | ||||
|         settings.githubServerUrl | ||||
|       ) | ||||
|       return | ||||
|     } | ||||
| @@ -121,7 +139,8 @@ export async function getSource(settings: IGitSourceSettings): Promise<void> { | ||||
|         settings.ref = await githubApiHelper.getDefaultBranch( | ||||
|           settings.authToken, | ||||
|           settings.repositoryOwner, | ||||
|           settings.repositoryName | ||||
|           settings.repositoryName, | ||||
|           settings.githubServerUrl | ||||
|         ) | ||||
|       } | ||||
|       core.endGroup() | ||||
| @@ -215,7 +234,8 @@ export async function getSource(settings: IGitSourceSettings): Promise<void> { | ||||
|       settings.repositoryOwner, | ||||
|       settings.repositoryName, | ||||
|       settings.ref, | ||||
|       settings.commit | ||||
|       settings.commit, | ||||
|       settings.githubServerUrl | ||||
|     ) | ||||
|   } finally { | ||||
|     // Remove auth | ||||
| @@ -249,7 +269,21 @@ export async function cleanup(repositoryPath: string): Promise<void> { | ||||
|   // Remove auth | ||||
|   const authHelper = gitAuthHelper.createAuthHelper(git) | ||||
|   try { | ||||
|     await authHelper.configureTempGlobalConfig(repositoryPath) | ||||
|     if (stateHelper.PostSetSafeDirectory) { | ||||
|       // Setup the repository path as a safe directory, so if we pass this into a container job with a different user it doesn't fail | ||||
|       // Otherwise all git commands we run in a container fail | ||||
|       await authHelper.configureTempGlobalConfig() | ||||
|       core.info( | ||||
|         `Adding repository directory to the temporary git global config as a safe directory` | ||||
|       ) | ||||
|  | ||||
|       await git | ||||
|         .config('safe.directory', repositoryPath, true, true) | ||||
|         .catch(error => { | ||||
|           core.info(`Failed to initialize safe directory with error: ${error}`) | ||||
|         }) | ||||
|     } | ||||
|  | ||||
|     await authHelper.removeAuth() | ||||
|   } finally { | ||||
|     await authHelper.removeGlobalConfig() | ||||
|   | ||||
| @@ -78,4 +78,14 @@ export interface IGitSourceSettings { | ||||
|    * Organization ID for the currently running workflow (used for auth settings) | ||||
|    */ | ||||
|   workflowOrganizationId: number | undefined | ||||
|  | ||||
|   /** | ||||
|    * Indicates whether to add repositoryPath as safe.directory in git global config | ||||
|    */ | ||||
|   setSafeDirectory: boolean | ||||
|  | ||||
|   /** | ||||
|    * User override on the GitHub Server/Host URL that hosts the repository to be cloned | ||||
|    */ | ||||
|   githubServerUrl: string | undefined | ||||
| } | ||||
|   | ||||
| @@ -1,13 +1,12 @@ | ||||
| import * as assert from 'assert' | ||||
| import * as core from '@actions/core' | ||||
| import * as fs from 'fs' | ||||
| import * as github from '@actions/github' | ||||
| import * as io from '@actions/io' | ||||
| import * as path from 'path' | ||||
| import * as retryHelper from './retry-helper' | ||||
| import * as toolCache from '@actions/tool-cache' | ||||
| import {default as uuid} from 'uuid/v4' | ||||
| import {Octokit} from '@octokit/rest' | ||||
| import {getOctokit, Octokit} from './octokit-provider' | ||||
|  | ||||
| const IS_WINDOWS = process.platform === 'win32' | ||||
|  | ||||
| @@ -17,18 +16,19 @@ export async function downloadRepository( | ||||
|   repo: string, | ||||
|   ref: string, | ||||
|   commit: string, | ||||
|   repositoryPath: string | ||||
|   repositoryPath: string, | ||||
|   baseUrl?: string | ||||
| ): Promise<void> { | ||||
|   // Determine the default branch | ||||
|   if (!ref && !commit) { | ||||
|     core.info('Determining the default branch') | ||||
|     ref = await getDefaultBranch(authToken, owner, repo) | ||||
|     ref = await getDefaultBranch(authToken, owner, repo, baseUrl) | ||||
|   } | ||||
|  | ||||
|   // Download the archive | ||||
|   let archiveData = await retryHelper.execute(async () => { | ||||
|     core.info('Downloading the archive') | ||||
|     return await downloadArchive(authToken, owner, repo, ref, commit) | ||||
|     return await downloadArchive(authToken, owner, repo, ref, commit, baseUrl) | ||||
|   }) | ||||
|  | ||||
|   // Write archive to disk | ||||
| @@ -79,11 +79,12 @@ export async function downloadRepository( | ||||
| export async function getDefaultBranch( | ||||
|   authToken: string, | ||||
|   owner: string, | ||||
|   repo: string | ||||
|   repo: string, | ||||
|   baseUrl?: string | ||||
| ): Promise<string> { | ||||
|   return await retryHelper.execute(async () => { | ||||
|     core.info('Retrieving the default branch name') | ||||
|     const octokit = new github.GitHub(authToken) | ||||
|     const octokit = getOctokit(authToken, {baseUrl: baseUrl}) | ||||
|     let result: string | ||||
|     try { | ||||
|       // Get the default branch from the repo info | ||||
| @@ -121,9 +122,10 @@ async function downloadArchive( | ||||
|   owner: string, | ||||
|   repo: string, | ||||
|   ref: string, | ||||
|   commit: string | ||||
|   commit: string, | ||||
|   baseUrl?: string | ||||
| ): Promise<Buffer> { | ||||
|   const octokit = new github.GitHub(authToken) | ||||
|   const octokit = getOctokit(authToken, {baseUrl: baseUrl}) | ||||
|   const params: Octokit.ReposGetArchiveLinkParams = { | ||||
|     owner: owner, | ||||
|     repo: repo, | ||||
|   | ||||
| @@ -122,5 +122,13 @@ export async function getInputs(): Promise<IGitSourceSettings> { | ||||
|   // Workflow organization ID | ||||
|   result.workflowOrganizationId = await workflowContextHelper.getOrganizationId() | ||||
|  | ||||
|   // Set safe.directory in git global config. | ||||
|   result.setSafeDirectory = | ||||
|     (core.getInput('set-safe-directory') || 'true').toUpperCase() === 'TRUE' | ||||
|  | ||||
|   // Determine the GitHub URL that the repository is being hosted from | ||||
|   result.githubServerUrl = core.getInput('github-server-url') | ||||
|   core.debug(`GitHub Host URL = ${result.githubServerUrl}`) | ||||
|  | ||||
|   return result | ||||
| } | ||||
|   | ||||
| @@ -120,7 +120,7 @@ function updateUsage( | ||||
| } | ||||
|  | ||||
| updateUsage( | ||||
|   'actions/checkout@v2', | ||||
|   'actions/checkout@v3', | ||||
|   path.join(__dirname, '..', '..', 'action.yml'), | ||||
|   path.join(__dirname, '..', '..', 'README.md') | ||||
| ) | ||||
|   | ||||
| @@ -5,4 +5,4 @@ set -e | ||||
| src/misc/licensed-download.sh | ||||
|  | ||||
| echo 'Running: licensed cached' | ||||
| _temp/licensed-3.3.1/licensed status | ||||
| _temp/licensed-3.6.0/licensed status | ||||
| @@ -2,23 +2,23 @@ | ||||
|  | ||||
| set -e | ||||
|  | ||||
| if [ ! -f _temp/licensed-3.3.1.done ]; then | ||||
| if [ ! -f _temp/licensed-3.6.0.done ]; then | ||||
|   echo 'Clearing temp' | ||||
|   rm -rf _temp/licensed-3.3.1 || true | ||||
|   rm -rf _temp/licensed-3.6.0 || true | ||||
|  | ||||
|   echo 'Downloading licensed' | ||||
|   mkdir -p _temp/licensed-3.3.1 | ||||
|   pushd _temp/licensed-3.3.1 | ||||
|   mkdir -p _temp/licensed-3.6.0 | ||||
|   pushd _temp/licensed-3.6.0 | ||||
|   if [[ "$OSTYPE" == "darwin"* ]]; then | ||||
|     curl -Lfs -o licensed.tar.gz https://github.com/github/licensed/releases/download/3.3.1/licensed-3.3.1-darwin-x64.tar.gz | ||||
|     curl -Lfs -o licensed.tar.gz https://github.com/github/licensed/releases/download/3.6.0/licensed-3.6.0-darwin-x64.tar.gz | ||||
|   else | ||||
|     curl -Lfs -o licensed.tar.gz https://github.com/github/licensed/releases/download/3.3.1/licensed-3.3.1-linux-x64.tar.gz | ||||
|     curl -Lfs -o licensed.tar.gz https://github.com/github/licensed/releases/download/3.6.0/licensed-3.6.0-linux-x64.tar.gz | ||||
|   fi | ||||
|  | ||||
|   echo 'Extracting licenesed' | ||||
|   tar -xzf licensed.tar.gz | ||||
|   popd | ||||
|   touch _temp/licensed-3.3.1.done | ||||
|   touch _temp/licensed-3.6.0.done | ||||
| else | ||||
|   echo 'Licensed already downloaded' | ||||
| fi | ||||
|   | ||||
| @@ -5,4 +5,4 @@ set -e | ||||
| src/misc/licensed-download.sh | ||||
|  | ||||
| echo 'Running: licensed cached' | ||||
| _temp/licensed-3.3.1/licensed cache | ||||
| _temp/licensed-3.6.0/licensed cache | ||||
							
								
								
									
										23
									
								
								src/octokit-provider.ts
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										23
									
								
								src/octokit-provider.ts
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,23 @@ | ||||
| import * as github from '@actions/github' | ||||
| import {Octokit} from '@octokit/rest' | ||||
| import {getServerApiUrl} from './url-helper' | ||||
|  | ||||
| // Centralize all Octokit references by re-exporting | ||||
| export {Octokit} from '@octokit/rest' | ||||
|  | ||||
| export type OctokitOptions = { | ||||
|   baseUrl?: string | ||||
|   userAgent?: string | ||||
| } | ||||
|  | ||||
| export function getOctokit(authToken: string, opts: OctokitOptions) { | ||||
|   const options: Octokit.Options = { | ||||
|     baseUrl: getServerApiUrl(opts.baseUrl) | ||||
|   } | ||||
|  | ||||
|   if (opts.userAgent) { | ||||
|     options.userAgent = opts.userAgent | ||||
|   } | ||||
|  | ||||
|   return new github.GitHub(authToken, options) | ||||
| } | ||||
| @@ -1,7 +1,8 @@ | ||||
| import {URL} from 'url' | ||||
| import {IGitCommandManager} from './git-command-manager' | ||||
| import * as core from '@actions/core' | ||||
| import * as github from '@actions/github' | ||||
| import {getOctokit} from './octokit-provider' | ||||
| import {isGhes} from './url-helper' | ||||
|  | ||||
| export const tagsRefSpec = '+refs/tags/*:refs/tags/*' | ||||
|  | ||||
| @@ -183,11 +184,12 @@ export async function checkCommitInfo( | ||||
|   repositoryOwner: string, | ||||
|   repositoryName: string, | ||||
|   ref: string, | ||||
|   commit: string | ||||
|   commit: string, | ||||
|   baseUrl?: string | ||||
| ): Promise<void> { | ||||
|   try { | ||||
|     // GHES? | ||||
|     if (isGhes()) { | ||||
|     if (isGhes(baseUrl)) { | ||||
|       return | ||||
|     } | ||||
|  | ||||
| @@ -243,7 +245,8 @@ export async function checkCommitInfo( | ||||
|       core.debug( | ||||
|         `Expected head sha ${expectedHeadSha}; actual head sha ${actualHeadSha}` | ||||
|       ) | ||||
|       const octokit = new github.GitHub(token, { | ||||
|       const octokit = getOctokit(token, { | ||||
|         baseUrl: baseUrl, | ||||
|         userAgent: `actions-checkout-tracepoint/1.0 (code=STALE_MERGE;owner=${repositoryOwner};repo=${repositoryName};pr=${fromPayload( | ||||
|           'number' | ||||
|         )};run_id=${ | ||||
| @@ -276,10 +279,3 @@ function select(obj: any, path: string): any { | ||||
|   const key = path.substr(0, i) | ||||
|   return select(obj[key], path.substr(i + 1)) | ||||
| } | ||||
|  | ||||
| function isGhes(): boolean { | ||||
|   const ghUrl = new URL( | ||||
|     process.env['GITHUB_SERVER_URL'] || 'https://github.com' | ||||
|   ) | ||||
|   return ghUrl.hostname.toUpperCase() !== 'GITHUB.COM' | ||||
| } | ||||
|   | ||||
| @@ -1,58 +1,60 @@ | ||||
| import * as coreCommand from '@actions/core/lib/command' | ||||
| import * as core from '@actions/core' | ||||
|  | ||||
| /** | ||||
|  * Indicates whether the POST action is running | ||||
|  */ | ||||
| export const IsPost = !!process.env['STATE_isPost'] | ||||
| export const IsPost = !!core.getState('isPost') | ||||
|  | ||||
| /** | ||||
|  * The repository path for the POST action. The value is empty during the MAIN action. | ||||
|  */ | ||||
| export const RepositoryPath = | ||||
|   (process.env['STATE_repositoryPath'] as string) || '' | ||||
| export const RepositoryPath = core.getState('repositoryPath') | ||||
|  | ||||
| /** | ||||
|  * The set-safe-directory for the POST action. The value is set if input: 'safe-directory' is set during the MAIN action. | ||||
|  */ | ||||
| export const PostSetSafeDirectory = core.getState('setSafeDirectory') === 'true' | ||||
|  | ||||
| /** | ||||
|  * The SSH key path for the POST action. The value is empty during the MAIN action. | ||||
|  */ | ||||
| export const SshKeyPath = (process.env['STATE_sshKeyPath'] as string) || '' | ||||
| export const SshKeyPath = core.getState('sshKeyPath') | ||||
|  | ||||
| /** | ||||
|  * The SSH known hosts path for the POST action. The value is empty during the MAIN action. | ||||
|  */ | ||||
| export const SshKnownHostsPath = | ||||
|   (process.env['STATE_sshKnownHostsPath'] as string) || '' | ||||
| export const SshKnownHostsPath = core.getState('sshKnownHostsPath') | ||||
|  | ||||
| /** | ||||
|  * Save the repository path so the POST action can retrieve the value. | ||||
|  */ | ||||
| export function setRepositoryPath(repositoryPath: string) { | ||||
|   coreCommand.issueCommand( | ||||
|     'save-state', | ||||
|     {name: 'repositoryPath'}, | ||||
|     repositoryPath | ||||
|   ) | ||||
|   core.saveState('repositoryPath', repositoryPath) | ||||
| } | ||||
|  | ||||
| /** | ||||
|  * Save the SSH key path so the POST action can retrieve the value. | ||||
|  */ | ||||
| export function setSshKeyPath(sshKeyPath: string) { | ||||
|   coreCommand.issueCommand('save-state', {name: 'sshKeyPath'}, sshKeyPath) | ||||
|   core.saveState('sshKeyPath', sshKeyPath) | ||||
| } | ||||
|  | ||||
| /** | ||||
|  * Save the SSH known hosts path so the POST action can retrieve the value. | ||||
|  */ | ||||
| export function setSshKnownHostsPath(sshKnownHostsPath: string) { | ||||
|   coreCommand.issueCommand( | ||||
|     'save-state', | ||||
|     {name: 'sshKnownHostsPath'}, | ||||
|     sshKnownHostsPath | ||||
|   ) | ||||
|   core.saveState('sshKnownHostsPath', sshKnownHostsPath) | ||||
| } | ||||
|  | ||||
| /** | ||||
|  * Save the set-safe-directory input so the POST action can retrieve the value. | ||||
|  */ | ||||
| export function setSafeDirectory() { | ||||
|   core.saveState('setSafeDirectory', 'true') | ||||
| } | ||||
|  | ||||
| // Publish a variable so that when the POST action runs, it can determine it should run the cleanup logic. | ||||
| // This is necessary since we don't have a separate entry point. | ||||
| if (!IsPost) { | ||||
|   coreCommand.issueCommand('save-state', {name: 'isPost'}, 'true') | ||||
|   core.saveState('isPost', 'true') | ||||
| } | ||||
|   | ||||
| @@ -1,6 +1,6 @@ | ||||
| import * as assert from 'assert' | ||||
| import {IGitSourceSettings} from './git-source-settings' | ||||
| import {URL} from 'url' | ||||
| import {IGitSourceSettings} from './git-source-settings' | ||||
|  | ||||
| export function getFetchUrl(settings: IGitSourceSettings): string { | ||||
|   assert.ok( | ||||
| @@ -8,7 +8,7 @@ export function getFetchUrl(settings: IGitSourceSettings): string { | ||||
|     'settings.repositoryOwner must be defined' | ||||
|   ) | ||||
|   assert.ok(settings.repositoryName, 'settings.repositoryName must be defined') | ||||
|   const serviceUrl = getServerUrl() | ||||
|   const serviceUrl = getServerUrl(settings.githubServerUrl) | ||||
|   const encodedOwner = encodeURIComponent(settings.repositoryOwner) | ||||
|   const encodedName = encodeURIComponent(settings.repositoryName) | ||||
|   if (settings.sshKey) { | ||||
| @@ -19,11 +19,27 @@ export function getFetchUrl(settings: IGitSourceSettings): string { | ||||
|   return `${serviceUrl.origin}/${encodedOwner}/${encodedName}` | ||||
| } | ||||
|  | ||||
| export function getServerUrl(): URL { | ||||
|   // todo: remove GITHUB_URL after support for GHES Alpha is no longer needed | ||||
|   return new URL( | ||||
|     process.env['GITHUB_SERVER_URL'] || | ||||
|       process.env['GITHUB_URL'] || | ||||
|       'https://github.com' | ||||
|   ) | ||||
| export function getServerUrl(url?: string): URL { | ||||
|   let urlValue = | ||||
|     url && url.trim().length > 0 | ||||
|       ? url | ||||
|       : process.env['GITHUB_SERVER_URL'] || 'https://github.com' | ||||
|   return new URL(urlValue) | ||||
| } | ||||
|  | ||||
| export function getServerApiUrl(url?: string): string { | ||||
|   let apiUrl = 'https://api.github.com' | ||||
|  | ||||
|   if (isGhes(url)) { | ||||
|     const serverUrl = getServerUrl(url) | ||||
|     apiUrl = new URL(`${serverUrl.origin}/api/v3`).toString() | ||||
|   } | ||||
|  | ||||
|   return apiUrl | ||||
| } | ||||
|  | ||||
| export function isGhes(url?: string): boolean { | ||||
|   const ghUrl = getServerUrl(url) | ||||
|  | ||||
|   return ghUrl.hostname.toUpperCase() !== 'GITHUB.COM' | ||||
| } | ||||
|   | ||||
		Reference in New Issue
	
	Block a user