Skip to content

[pull] main from actions:main - #7

Open
pull[bot] wants to merge 741 commits into
Graybar-codespace:mainfrom
actions:main
Open

pull[bot] wants to merge 741 commits into
Graybar-codespace:mainfrom
actions:main

Conversation

@pull

@pull pull Bot commented Oct 15, 2024 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot]

Can you help keep this open source service alive? 💖 Please sponsor : )

@sourcery-ai

sourcery-ai Bot commented Oct 15, 2024 •

Copy link
Copy Markdown

Reviewer's Guide by Sourcery

This pull request includes several significant changes across multiple packages in the actions/toolkit repository. The changes primarily focus on updating dependencies, improving error handling, enhancing security, and refactoring code for better performance and maintainability. Key updates include modifications to the artifact upload process, changes to OIDC token handling, improvements to the HTTP client, and updates to the glob and attest packages.

Class diagram for OIDC Token Handling

classDiagram
    class OIDCConfig {
        string issuer
        string jwks_uri
    }

    class ClaimSet {
        string iss
        string ref
        string sha
        string repository
        string event_name
        string job_workflow_ref
        string workflow_ref
        string repository_id
        string repository_owner_id
    }

    class OIDC {
        +getIDTokenClaims(issuer: string): Promise<ClaimSet>
        +decodeOIDCToken(token: string, issuer: string): Promise<JWTPayload>
        +getJWKS(issuer: string): Promise<JSONWebKeySet>
        +getIssuer(): string
    }

    OIDC --> OIDCConfig
    OIDC --> ClaimSet
Loading

Class diagram for HTTP Client Proxy Handling

classDiagram
    class DecodedURL {
        string username
        string password
        string href
    }

    class HttpClient {
        +getProxyUrl(reqUrl: URL): URL | undefined
        +getAgent(url: string): any
    }

    HttpClient --> DecodedURL
Loading

File-Level Changes

Change Details Files
Refactored artifact upload process
  • Updated chunk timeout logic
  • Implemented lazy stream to prevent issues with open file limits
  • Fixed a regression with symlinks not being automatically resolved
  • Improved error handling for upload progress stalling
packages/artifact/__tests__/upload-artifact.test.ts
packages/artifact/src/internal/upload/blob-upload.ts
packages/artifact/src/internal/upload/upload-zip-specification.ts
packages/artifact/src/internal/upload/zip.ts
Enhanced OIDC token handling and attestation process
  • Updated OIDC token claim validation
  • Improved handling of enterprise-specific OIDC issuers
  • Added support for custom HTTP headers in attestation requests
  • Updated SLSA provenance predicate generation
packages/attest/src/oidc.ts
packages/attest/src/provenance.ts
packages/attest/src/attest.ts
packages/attest/src/store.ts
Improved HTTP client functionality
  • Fixed handling of proxy usernames and passwords
  • Updated URL decoding for proxy authentication
  • Improved error handling for network requests
packages/http-client/src/index.ts
packages/http-client/src/proxy.ts
Updated glob package with new features
  • Added option to exclude hidden files in glob searches
  • Improved handling of symlinks in glob results
packages/glob/src/internal-glob-options.ts
packages/glob/src/internal-globber.ts
General dependency updates and security improvements
  • Updated various dependencies across packages
  • Replaced uuid package with native crypto.randomUUID()
  • Improved error messages and debugging information
packages/artifact/RELEASES.md
packages/attest/RELEASES.md
packages/core/RELEASES.md
packages/glob/RELEASES.md
packages/http-client/RELEASES.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time. You can also use
    this command to specify where the summary should be inserted.

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have skipped reviewing this pull request. It seems to have been created by a bot (hey, pull[bot]!). We assume it knows what it's doing!

@pull pull Bot added the ⤵️ pull label Oct 15, 2024
salmanmkc and others added 27 commits December 11, 2025 20:23
chore(artifact): bump dependencies for Node.js 24 support
docs(artifact): add v5.0.0 release notes
… deprecation

- Removed direct @azure/core-http dependency
- Updated @azure/storage-blob from ^12.15.0 to ^12.29.1
- Newer storage-blob uses @azure/core-rest-pipeline instead of deprecated @azure/core-http
- Fixes Node.js 24 deprecation warning for punycode module
…precation

- Updated @azure/storage-blob from ^12.13.0 to ^12.29.1
- Newer storage-blob uses @azure/core-rest-pipeline instead of deprecated @azure/core-http
- Fixes Node.js 24 deprecation warning for punycode module
fix(cache): update @azure/storage-blob to fix Node.js 24 punycode deprecation
fix(artifact): update @azure/storage-blob to fix Node.js 24 punycode deprecation
docs(cache): release @actions/cache v5.0.1
docs(artifact): release @actions/artifact v5.0.1
Co-authored-by: TingluoHuang <1750815+TingluoHuang@users.noreply.github.com>
Co-authored-by: TingluoHuang <1750815+TingluoHuang@users.noreply.github.com>
Co-authored-by: TingluoHuang <1750815+TingluoHuang@users.noreply.github.com>
Co-authored-by: TingluoHuang <1750815+TingluoHuang@users.noreply.github.com>
Co-authored-by: TingluoHuang <1750815+TingluoHuang@users.noreply.github.com>
Co-authored-by: TingluoHuang <1750815+TingluoHuang@users.noreply.github.com>
Co-authored-by: TingluoHuang <1750815+TingluoHuang@users.noreply.github.com>
dependabot Bot and others added 30 commits September 30, 2026 10:00
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.28.1.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.28.1)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.28.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.24.0 to 6.29.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.0...v6.29.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.29.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.25.0 to 6.29.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.25.0...v6.29.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.29.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…ith 7 updates

Bumps the artifact-minor-patch group with 7 updates in the /packages/artifact directory:

| Package | From | To |
| --- | --- | --- |
| [@azure/storage-blob](https://github.com/Azure/azure-sdk-for-js/tree/HEAD/sdk/storage/storage-blob) | `12.31.0` | `12.34.0` |
| [@octokit/core](https://github.com/octokit/core.js) | `7.0.6` | `7.0.8` |
| [@octokit/plugin-retry](https://github.com/octokit/plugin-retry.js) | `8.1.0` | `8.1.1` |
| [@octokit/request](https://github.com/octokit/request.js) | `10.0.8` | `10.0.16` |
| [@octokit/request-error](https://github.com/octokit/request-error.js) | `7.1.0` | `7.1.2` |
| [typedoc](https://github.com/TypeStrong/TypeDoc) | `0.28.19` | `0.28.20` |
| [typedoc-plugin-markdown](https://github.com/typedoc2md/typedoc-plugin-markdown/tree/HEAD/packages/typedoc-plugin-markdown) | `4.11.0` | `4.13.1` |



Updates `@azure/storage-blob` from 12.31.0 to 12.34.0
- [Release notes](https://github.com/Azure/azure-sdk-for-js/releases)
- [Changelog](https://github.com/Azure/azure-sdk-for-js/blob/main/sdk/storage/storage-blob/CHANGELOG.md)
- [Commits](https://github.com/Azure/azure-sdk-for-js/commits/@azure/storage-blob_12.34.0/sdk/storage/storage-blob)

Updates `@octokit/core` from 7.0.6 to 7.0.8
- [Release notes](https://github.com/octokit/core.js/releases)
- [Commits](octokit/core.js@v7.0.6...v7.0.8)

Updates `@octokit/plugin-retry` from 8.1.0 to 8.1.1
- [Release notes](https://github.com/octokit/plugin-retry.js/releases)
- [Commits](octokit/plugin-retry.js@v8.1.0...v8.1.1)

Updates `@octokit/request` from 10.0.8 to 10.0.16
- [Release notes](https://github.com/octokit/request.js/releases)
- [Commits](octokit/request.js@v10.0.8...v10.0.16)

Updates `@octokit/request-error` from 7.1.0 to 7.1.2
- [Release notes](https://github.com/octokit/request-error.js/releases)
- [Commits](octokit/request-error.js@v7.1.0...v7.1.2)

Updates `typedoc` from 0.28.19 to 0.28.20
- [Release notes](https://github.com/TypeStrong/TypeDoc/releases)
- [Changelog](https://github.com/TypeStrong/typedoc/blob/master/CHANGELOG.md)
- [Commits](TypeStrong/typedoc@v0.28.19...v0.28.20)

Updates `typedoc-plugin-markdown` from 4.11.0 to 4.13.1
- [Release notes](https://github.com/typedoc2md/typedoc-plugin-markdown/releases)
- [Changelog](https://github.com/typedoc2md/typedoc-plugin-markdown/blob/main/packages/typedoc-plugin-markdown/CHANGELOG.md)
- [Commits](https://github.com/typedoc2md/typedoc-plugin-markdown/commits/typedoc-plugin-markdown@4.13.1/packages/typedoc-plugin-markdown)

---
updated-dependencies:
- dependency-name: "@azure/storage-blob"
  dependency-version: 12.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: artifact-minor-patch
- dependency-name: "@octokit/core"
  dependency-version: 7.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: artifact-minor-patch
- dependency-name: "@octokit/plugin-retry"
  dependency-version: 8.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: artifact-minor-patch
- dependency-name: "@octokit/request"
  dependency-version: 10.0.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: artifact-minor-patch
- dependency-name: "@octokit/request-error"
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: artifact-minor-patch
- dependency-name: typedoc
  dependency-version: 0.28.20
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: artifact-minor-patch
- dependency-name: typedoc-plugin-markdown
  dependency-version: 4.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: artifact-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
… 2 updates

Bumps the cache-minor-patch group with 2 updates in the /packages/cache directory: [@azure/core-rest-pipeline](https://github.com/Azure/azure-sdk-for-js/tree/HEAD/sdk/core/core-rest-pipeline) and [@azure/storage-blob](https://github.com/Azure/azure-sdk-for-js/tree/HEAD/sdk/storage/storage-blob).


Updates `@azure/core-rest-pipeline` from 1.23.0 to 1.25.0
- [Release notes](https://github.com/Azure/azure-sdk-for-js/releases)
- [Changelog](https://github.com/Azure/azure-sdk-for-js/blob/main/sdk/core/core-rest-pipeline/CHANGELOG.md)
- [Commits](https://github.com/Azure/azure-sdk-for-js/commits/@azure/core-rest-pipeline_1.25.0/sdk/core/core-rest-pipeline)

Updates `@azure/storage-blob` from 12.31.0 to 12.34.0
- [Release notes](https://github.com/Azure/azure-sdk-for-js/releases)
- [Changelog](https://github.com/Azure/azure-sdk-for-js/blob/main/sdk/storage/storage-blob/CHANGELOG.md)
- [Commits](https://github.com/Azure/azure-sdk-for-js/commits/@azure/storage-blob_12.34.0/sdk/storage/storage-blob)

---
updated-dependencies:
- dependency-name: "@azure/core-rest-pipeline"
  dependency-version: 1.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cache-minor-patch
- dependency-name: "@azure/storage-blob"
  dependency-version: 12.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cache-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
…s/artifact/undici-6.29.0

chore(deps): bump undici from 6.28.0 to 6.29.0 in /packages/artifact
Bumps [axios](https://github.com/axios/axios) from 1.17.0 to 1.20.0.
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.17.0...v1.20.0)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 1.20.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…s/glob/undici-6.29.0

chore(deps): bump undici from 6.24.0 to 6.29.0 in /packages/glob
…s/http-client/undici-6.28.1

chore(deps): bump undici from 6.24.0 to 6.28.1 in /packages/http-client
…s/tool-cache/undici-6.29.0

chore(deps): bump undici from 6.25.0 to 6.29.0 in /packages/tool-cache
…s/core/undici-6.28.0

chore(deps): bump undici from 6.24.1 to 6.28.0 in /packages/core
….20.0

chore(deps-dev): bump axios from 1.17.0 to 1.20.0
…s/glob/brace-expansion-5.0.12

chore(deps): bump brace-expansion from 5.0.7 to 5.0.12 in /packages/glob
Bumps [undici](https://github.com/nodejs/undici) from 6.28.0 to 6.29.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.28.0...v6.29.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.29.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.2.0 to 10.7.2.
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v10.2.0...v10.7.2)

---
updated-dependencies:
- dependency-name: ip-address
  dependency-version: 10.7.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 2.1.4 to 2.1.7.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v2.1.4...v2.1.7)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 2.1.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…slist-4.28.8

chore(deps-dev): bump browserslist from 4.26.2 to 4.28.8
…-selector-parser-6.1.4

chore(deps-dev): bump postcss-selector-parser from 6.1.2 to 6.1.4
…s/artifact/artifact-minor-patch-e133483122

chore(deps): bump the artifact-minor-patch group across 1 directory with 7 updates
…s/core/undici-6.29.0

chore(deps): bump undici from 6.28.0 to 6.29.0 in /packages/core
…s/attest/ip-address-10.7.2

chore(deps): bump ip-address from 10.2.0 to 10.7.2 in /packages/attest
…s/attest/brace-expansion-2.1.7

chore(deps): bump brace-expansion from 2.1.4 to 2.1.7 in /packages/attest
Bumps  and [brace-expansion](https://github.com/juliangruber/brace-expansion). These dependencies needed to be updated together.

Updates `brace-expansion` from 2.1.0 to 2.1.7
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v2.1.0...v2.1.7)

Updates `brace-expansion` from 5.0.6 to 5.0.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v2.1.0...v2.1.7)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 2.1.7
  dependency-type: indirect
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 2.1.1 to 2.1.7.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v2.1.1...v2.1.7)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 2.1.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…xpansion-2.1.7

chore(deps-dev): bump brace-expansion from 2.1.1 to 2.1.7
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.2.0 to 10.7.2.
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v10.2.0...v10.7.2)

---
updated-dependencies:
- dependency-name: ip-address
  dependency-version: 10.7.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…ess-10.7.2

chore(deps-dev): bump ip-address from 10.2.0 to 10.7.2
…s/artifact/multi-581aeff57e

chore(deps): bump brace-expansion in /packages/artifact
…s/cache/cache-minor-patch-b3a9b739e6

chore(deps): bump the cache-minor-patch group across 1 directory with 2 updates
…ars-4.7.9

chore(deps): bump handlebars from 4.7.8 to 4.7.9
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.