From 83c236af2b01f1aaa4139eaedf7b363e7c9fa0e2 Mon Sep 17 00:00:00 2001 From: "Michael B. Gale" Date: Tue, 24 Feb 2026 11:25:57 +0000 Subject: [PATCH 1/6] Remove FF gate for improved CA generation --- lib/analyze-action-post.js | 5 ----- lib/analyze-action.js | 5 ----- lib/autobuild-action.js | 5 ----- lib/init-action-post.js | 5 ----- lib/init-action.js | 5 ----- lib/resolve-environment-action.js | 5 ----- lib/setup-codeql-action.js | 5 ----- lib/start-proxy-action-post.js | 5 ----- lib/start-proxy-action.js | 26 ++++++-------------------- lib/upload-lib.js | 5 ----- lib/upload-sarif-action-post.js | 5 ----- lib/upload-sarif-action.js | 5 ----- src/feature-flags.ts | 6 ------ src/start-proxy-action.ts | 4 +--- src/start-proxy/ca.test.ts | 28 +--------------------------- src/start-proxy/ca.ts | 26 +++++++------------------- 16 files changed, 15 insertions(+), 130 deletions(-) diff --git a/lib/analyze-action-post.js b/lib/analyze-action-post.js index d1068dc55..b82d8b580 100644 --- a/lib/analyze-action-post.js +++ b/lib/analyze-action-post.js @@ -161595,11 +161595,6 @@ var featureConfig = { envVar: "CODEQL_ACTION_IGNORE_GENERATED_FILES", minimumVersion: void 0 }, - ["improved_proxy_certificates" /* ImprovedProxyCertificates */]: { - defaultValue: false, - envVar: "CODEQL_ACTION_IMPROVED_PROXY_CERTIFICATES", - minimumVersion: void 0 - }, ["java_network_debugging" /* JavaNetworkDebugging */]: { defaultValue: false, envVar: "CODEQL_ACTION_JAVA_NETWORK_DEBUGGING", diff --git a/lib/analyze-action.js b/lib/analyze-action.js index d97d19c51..6ad384010 100644 --- a/lib/analyze-action.js +++ b/lib/analyze-action.js @@ -107706,11 +107706,6 @@ var featureConfig = { envVar: "CODEQL_ACTION_IGNORE_GENERATED_FILES", minimumVersion: void 0 }, - ["improved_proxy_certificates" /* ImprovedProxyCertificates */]: { - defaultValue: false, - envVar: "CODEQL_ACTION_IMPROVED_PROXY_CERTIFICATES", - minimumVersion: void 0 - }, ["java_network_debugging" /* JavaNetworkDebugging */]: { defaultValue: false, envVar: "CODEQL_ACTION_JAVA_NETWORK_DEBUGGING", diff --git a/lib/autobuild-action.js b/lib/autobuild-action.js index d39e63400..8650b0c53 100644 --- a/lib/autobuild-action.js +++ b/lib/autobuild-action.js @@ -103996,11 +103996,6 @@ var featureConfig = { envVar: "CODEQL_ACTION_IGNORE_GENERATED_FILES", minimumVersion: void 0 }, - ["improved_proxy_certificates" /* ImprovedProxyCertificates */]: { - defaultValue: false, - envVar: "CODEQL_ACTION_IMPROVED_PROXY_CERTIFICATES", - minimumVersion: void 0 - }, ["java_network_debugging" /* JavaNetworkDebugging */]: { defaultValue: false, envVar: "CODEQL_ACTION_JAVA_NETWORK_DEBUGGING", diff --git a/lib/init-action-post.js b/lib/init-action-post.js index f4bc19ecf..8b01a91a2 100644 --- a/lib/init-action-post.js +++ b/lib/init-action-post.js @@ -165073,11 +165073,6 @@ var featureConfig = { envVar: "CODEQL_ACTION_IGNORE_GENERATED_FILES", minimumVersion: void 0 }, - ["improved_proxy_certificates" /* ImprovedProxyCertificates */]: { - defaultValue: false, - envVar: "CODEQL_ACTION_IMPROVED_PROXY_CERTIFICATES", - minimumVersion: void 0 - }, ["java_network_debugging" /* JavaNetworkDebugging */]: { defaultValue: false, envVar: "CODEQL_ACTION_JAVA_NETWORK_DEBUGGING", diff --git a/lib/init-action.js b/lib/init-action.js index ca0b47a85..349d97b2e 100644 --- a/lib/init-action.js +++ b/lib/init-action.js @@ -105223,11 +105223,6 @@ var featureConfig = { envVar: "CODEQL_ACTION_IGNORE_GENERATED_FILES", minimumVersion: void 0 }, - ["improved_proxy_certificates" /* ImprovedProxyCertificates */]: { - defaultValue: false, - envVar: "CODEQL_ACTION_IMPROVED_PROXY_CERTIFICATES", - minimumVersion: void 0 - }, ["java_network_debugging" /* JavaNetworkDebugging */]: { defaultValue: false, envVar: "CODEQL_ACTION_JAVA_NETWORK_DEBUGGING", diff --git a/lib/resolve-environment-action.js b/lib/resolve-environment-action.js index 93eee7f4c..b140d4faf 100644 --- a/lib/resolve-environment-action.js +++ b/lib/resolve-environment-action.js @@ -103987,11 +103987,6 @@ var featureConfig = { envVar: "CODEQL_ACTION_IGNORE_GENERATED_FILES", minimumVersion: void 0 }, - ["improved_proxy_certificates" /* ImprovedProxyCertificates */]: { - defaultValue: false, - envVar: "CODEQL_ACTION_IMPROVED_PROXY_CERTIFICATES", - minimumVersion: void 0 - }, ["java_network_debugging" /* JavaNetworkDebugging */]: { defaultValue: false, envVar: "CODEQL_ACTION_JAVA_NETWORK_DEBUGGING", diff --git a/lib/setup-codeql-action.js b/lib/setup-codeql-action.js index 95a380ab4..fa3cdc503 100644 --- a/lib/setup-codeql-action.js +++ b/lib/setup-codeql-action.js @@ -103896,11 +103896,6 @@ var featureConfig = { envVar: "CODEQL_ACTION_IGNORE_GENERATED_FILES", minimumVersion: void 0 }, - ["improved_proxy_certificates" /* ImprovedProxyCertificates */]: { - defaultValue: false, - envVar: "CODEQL_ACTION_IMPROVED_PROXY_CERTIFICATES", - minimumVersion: void 0 - }, ["java_network_debugging" /* JavaNetworkDebugging */]: { defaultValue: false, envVar: "CODEQL_ACTION_JAVA_NETWORK_DEBUGGING", diff --git a/lib/start-proxy-action-post.js b/lib/start-proxy-action-post.js index 76abe6d2f..aed843fc9 100644 --- a/lib/start-proxy-action-post.js +++ b/lib/start-proxy-action-post.js @@ -161001,11 +161001,6 @@ var featureConfig = { envVar: "CODEQL_ACTION_IGNORE_GENERATED_FILES", minimumVersion: void 0 }, - ["improved_proxy_certificates" /* ImprovedProxyCertificates */]: { - defaultValue: false, - envVar: "CODEQL_ACTION_IMPROVED_PROXY_CERTIFICATES", - minimumVersion: void 0 - }, ["java_network_debugging" /* JavaNetworkDebugging */]: { defaultValue: false, envVar: "CODEQL_ACTION_JAVA_NETWORK_DEBUGGING", diff --git a/lib/start-proxy-action.js b/lib/start-proxy-action.js index e7d387120..709fddfc3 100644 --- a/lib/start-proxy-action.js +++ b/lib/start-proxy-action.js @@ -120688,11 +120688,6 @@ var featureConfig = { envVar: "CODEQL_ACTION_IGNORE_GENERATED_FILES", minimumVersion: void 0 }, - ["improved_proxy_certificates" /* ImprovedProxyCertificates */]: { - defaultValue: false, - envVar: "CODEQL_ACTION_IMPROVED_PROXY_CERTIFICATES", - minimumVersion: void 0 - }, ["java_network_debugging" /* JavaNetworkDebugging */]: { defaultValue: false, envVar: "CODEQL_ACTION_JAVA_NETWORK_DEBUGGING", @@ -121829,7 +121824,8 @@ var CERT_SUBJECT = [ value: "San Francisco" } ]; -var extraExtensions = [ +var allExtensions = [ + { name: "basicConstraints", cA: true }, { name: "keyUsage", critical: true, @@ -121840,7 +121836,7 @@ var extraExtensions = [ { name: "subjectKeyIdentifier" }, { name: "authorityKeyIdentifier", keyIdentifier: true } ]; -function generateCertificateAuthority(newCertGenFF) { +function generateCertificateAuthority() { const keys = import_node_forge.pki.rsa.generateKeyPair(KEY_SIZE); const cert = import_node_forge.pki.createCertificate(); cert.publicKey = keys.publicKey; @@ -121852,16 +121848,8 @@ function generateCertificateAuthority(newCertGenFF) { ); cert.setSubject(CERT_SUBJECT); cert.setIssuer(CERT_SUBJECT); - const extensions = [{ name: "basicConstraints", cA: true }]; - if (newCertGenFF) { - extensions.push(...extraExtensions); - } - cert.setExtensions(extensions); - if (newCertGenFF) { - cert.sign(keys.privateKey, import_node_forge.md.sha256.create()); - } else { - cert.sign(keys.privateKey); - } + cert.setExtensions(allExtensions); + cert.sign(keys.privateKey, import_node_forge.md.sha256.create()); const pem = import_node_forge.pki.certificateToPem(cert); const key = import_node_forge.pki.privateKeyToPem(keys.privateKey); return { cert: pem, key }; @@ -122138,9 +122126,7 @@ async function run(startedAt) { ); } } - const ca = generateCertificateAuthority( - await features.getValue("improved_proxy_certificates" /* ImprovedProxyCertificates */) - ); + const ca = generateCertificateAuthority(); const proxyConfig = { all_credentials: credentials, ca diff --git a/lib/upload-lib.js b/lib/upload-lib.js index fcec315ba..b16047dff 100644 --- a/lib/upload-lib.js +++ b/lib/upload-lib.js @@ -107155,11 +107155,6 @@ var featureConfig = { envVar: "CODEQL_ACTION_IGNORE_GENERATED_FILES", minimumVersion: void 0 }, - ["improved_proxy_certificates" /* ImprovedProxyCertificates */]: { - defaultValue: false, - envVar: "CODEQL_ACTION_IMPROVED_PROXY_CERTIFICATES", - minimumVersion: void 0 - }, ["java_network_debugging" /* JavaNetworkDebugging */]: { defaultValue: false, envVar: "CODEQL_ACTION_JAVA_NETWORK_DEBUGGING", diff --git a/lib/upload-sarif-action-post.js b/lib/upload-sarif-action-post.js index 707ab2835..7aa9b2f5f 100644 --- a/lib/upload-sarif-action-post.js +++ b/lib/upload-sarif-action-post.js @@ -161163,11 +161163,6 @@ var featureConfig = { envVar: "CODEQL_ACTION_IGNORE_GENERATED_FILES", minimumVersion: void 0 }, - ["improved_proxy_certificates" /* ImprovedProxyCertificates */]: { - defaultValue: false, - envVar: "CODEQL_ACTION_IMPROVED_PROXY_CERTIFICATES", - minimumVersion: void 0 - }, ["java_network_debugging" /* JavaNetworkDebugging */]: { defaultValue: false, envVar: "CODEQL_ACTION_JAVA_NETWORK_DEBUGGING", diff --git a/lib/upload-sarif-action.js b/lib/upload-sarif-action.js index 071fe3b0c..81a17fc4d 100644 --- a/lib/upload-sarif-action.js +++ b/lib/upload-sarif-action.js @@ -106880,11 +106880,6 @@ var featureConfig = { envVar: "CODEQL_ACTION_IGNORE_GENERATED_FILES", minimumVersion: void 0 }, - ["improved_proxy_certificates" /* ImprovedProxyCertificates */]: { - defaultValue: false, - envVar: "CODEQL_ACTION_IMPROVED_PROXY_CERTIFICATES", - minimumVersion: void 0 - }, ["java_network_debugging" /* JavaNetworkDebugging */]: { defaultValue: false, envVar: "CODEQL_ACTION_JAVA_NETWORK_DEBUGGING", diff --git a/src/feature-flags.ts b/src/feature-flags.ts index f2a6c90a2..77557743c 100644 --- a/src/feature-flags.ts +++ b/src/feature-flags.ts @@ -47,7 +47,6 @@ export enum Feature { ExportDiagnosticsEnabled = "export_diagnostics_enabled", ForceNightly = "force_nightly", IgnoreGeneratedFiles = "ignore_generated_files", - ImprovedProxyCertificates = "improved_proxy_certificates", JavaNetworkDebugging = "java_network_debugging", OverlayAnalysis = "overlay_analysis", OverlayAnalysisActions = "overlay_analysis_actions", @@ -175,11 +174,6 @@ export const featureConfig = { envVar: "CODEQL_ACTION_IGNORE_GENERATED_FILES", minimumVersion: undefined, }, - [Feature.ImprovedProxyCertificates]: { - defaultValue: false, - envVar: "CODEQL_ACTION_IMPROVED_PROXY_CERTIFICATES", - minimumVersion: undefined, - }, [Feature.JavaNetworkDebugging]: { defaultValue: false, envVar: "CODEQL_ACTION_JAVA_NETWORK_DEBUGGING", diff --git a/src/start-proxy-action.ts b/src/start-proxy-action.ts index df6c9a332..39d2bc2d4 100644 --- a/src/start-proxy-action.ts +++ b/src/start-proxy-action.ts @@ -90,9 +90,7 @@ async function run(startedAt: Date) { } } - const ca = generateCertificateAuthority( - await features.getValue(Feature.ImprovedProxyCertificates), - ); + const ca = generateCertificateAuthority(); const proxyConfig: ProxyConfig = { all_credentials: credentials, diff --git a/src/start-proxy/ca.test.ts b/src/start-proxy/ca.test.ts index ae4e22e9a..7b88fc54b 100644 --- a/src/start-proxy/ca.test.ts +++ b/src/start-proxy/ca.test.ts @@ -32,33 +32,7 @@ function checkCertAttributes( } test("generateCertificateAuthority - generates certificates", (t) => { - const result = ca.generateCertificateAuthority(false); - const cert = pki.certificateFromPem(result.cert); - const key = pki.privateKeyFromPem(result.key); - - t.truthy(cert); - t.truthy(key); - - checkCertAttributes(t, cert); - - // Check the validity. - t.true( - cert.validity.notBefore <= new Date(), - "notBefore date is in the future", - ); - t.true(cert.validity.notAfter > new Date(), "notAfter date is in the past"); - - // Check that the extensions are set as we'd expect. - const exts = cert.extensions as ca.Extension[]; - t.is(exts.length, 1); - t.is(exts[0].name, "basicConstraints"); - t.is(exts[0].cA, true); - - t.truthy(cert.siginfo); -}); - -test("generateCertificateAuthority - generates certificates with FF", (t) => { - const result = ca.generateCertificateAuthority(true); + const result = ca.generateCertificateAuthority(); const cert = pki.certificateFromPem(result.cert); const key = pki.privateKeyFromPem(result.key); diff --git a/src/start-proxy/ca.ts b/src/start-proxy/ca.ts index 80d976f7b..8f9b8de13 100644 --- a/src/start-proxy/ca.ts +++ b/src/start-proxy/ca.ts @@ -37,7 +37,8 @@ export type Extension = { [key: string]: unknown; }; -const extraExtensions: Extension[] = [ +const allExtensions: Extension[] = [ + { name: "basicConstraints", cA: true }, { name: "keyUsage", critical: true, @@ -52,12 +53,9 @@ const extraExtensions: Extension[] = [ /** * Generates a CA certificate for the proxy. * - * @param newCertGenFF Whether to use the updated certificate generation. * @returns The private and public keys. */ -export function generateCertificateAuthority( - newCertGenFF: boolean, -): CertificateAuthority { +export function generateCertificateAuthority(): CertificateAuthority { const keys = pki.rsa.generateKeyPair(KEY_SIZE); const cert = pki.createCertificate(); cert.publicKey = keys.publicKey; @@ -71,21 +69,11 @@ export function generateCertificateAuthority( cert.setSubject(CERT_SUBJECT); cert.setIssuer(CERT_SUBJECT); - const extensions: Extension[] = [{ name: "basicConstraints", cA: true }]; + // Set the CA extensions for the certificate. + cert.setExtensions(allExtensions); - // Add the extra CA extensions if the FF is enabled. - if (newCertGenFF) { - extensions.push(...extraExtensions); - } - - cert.setExtensions(extensions); - - // Specifically use SHA256 when the FF is enabled. - if (newCertGenFF) { - cert.sign(keys.privateKey, md.sha256.create()); - } else { - cert.sign(keys.privateKey); - } + // Specifically use SHA256 to ensure consistency and compatibility. + cert.sign(keys.privateKey, md.sha256.create()); const pem = pki.certificateToPem(cert); const key = pki.privateKeyToPem(keys.privateKey); From 160d27baf00e1b1f48bd189d637609258cad98c8 Mon Sep 17 00:00:00 2001 From: Henry Mercer Date: Tue, 24 Feb 2026 17:41:30 +0000 Subject: [PATCH 2/6] Improve type inference of `Result` --- lib/init-action.js | 44 ++++++++++++++------------- src/init-action.ts | 10 ++++--- src/util.test.ts | 8 ++--- src/util.ts | 75 ++++++++++++++++++++++++++-------------------- 4 files changed, 75 insertions(+), 62 deletions(-) diff --git a/lib/init-action.js b/lib/init-action.js index 27daa414a..c91c84ed2 100644 --- a/lib/init-action.js +++ b/lib/init-action.js @@ -103597,30 +103597,32 @@ function joinAtMost(array, separator, limit) { } return array.join(separator); } -var Result = class _Result { - constructor(_ok, value) { - this._ok = _ok; +var Success = class { + constructor(value) { this.value = value; } - /** Creates a success result. */ - static success(value) { - return new _Result(true, value); - } - /** Creates a failure result. */ - static failure(value) { - return new _Result(false, value); - } - /** Whether this result represents a success. */ isSuccess() { - return this._ok; + return true; } - /** Whether this result represents a failure. */ isFailure() { - return !this._ok; + return false; + } + orElse(_defaultValue) { + return this.value; + } +}; +var Failure = class { + constructor(value) { + this.value = value; + } + isSuccess() { + return false; + } + isFailure() { + return true; } - /** Get the value if this is a success, or return the default value if this is a failure. */ orElse(defaultValue) { - return this.isSuccess() ? this.value : defaultValue; + return defaultValue; } }; @@ -109739,23 +109741,23 @@ async function loadRepositoryProperties(repositoryNwo, gitHubVersion, features, logger.debug( "Skipping loading repository properties because the repository is owned by a user and therefore cannot have repository properties." ); - return Result.success({}); + return new Success({}); } if (!await features.getValue("use_repository_properties" /* UseRepositoryProperties */)) { logger.debug( "Skipping loading repository properties because the UseRepositoryProperties feature flag is disabled." ); - return Result.success({}); + return new Success({}); } try { - return Result.success( + return new Success( await loadPropertiesFromApi(gitHubVersion, logger, repositoryNwo) ); } catch (error3) { logger.warning( `Failed to load repository properties: ${getErrorMessage(error3)}` ); - return Result.failure(error3); + return new Failure(error3); } } function getTrapCachingEnabled() { diff --git a/src/init-action.ts b/src/init-action.ts index a09967ab5..2a8ed5a50 100644 --- a/src/init-action.ts +++ b/src/init-action.ts @@ -96,6 +96,8 @@ import { GitHubVersion, Result, getOptionalEnvVar, + Success, + Failure, } from "./util"; import { checkWorkflow } from "./workflow"; @@ -834,25 +836,25 @@ async function loadRepositoryProperties( "Skipping loading repository properties because the repository is owned by a user and " + "therefore cannot have repository properties.", ); - return Result.success({}); + return new Success({}); } if (!(await features.getValue(Feature.UseRepositoryProperties))) { logger.debug( "Skipping loading repository properties because the UseRepositoryProperties feature flag is disabled.", ); - return Result.success({}); + return new Success({}); } try { - return Result.success( + return new Success( await loadPropertiesFromApi(gitHubVersion, logger, repositoryNwo), ); } catch (error) { logger.warning( `Failed to load repository properties: ${getErrorMessage(error)}`, ); - return Result.failure(error); + return new Failure(error); } } diff --git a/src/util.test.ts b/src/util.test.ts index 4d3121cf1..b63a91c8b 100644 --- a/src/util.test.ts +++ b/src/util.test.ts @@ -565,7 +565,7 @@ test("joinAtMost - truncates list if array is > than limit", (t) => { }); test("Result.success creates a success result", (t) => { - const result = util.Result.success("test value"); + const result = new util.Success("test value"); t.true(result.isSuccess()); t.false(result.isFailure()); t.is(result.value, "test value"); @@ -573,18 +573,18 @@ test("Result.success creates a success result", (t) => { test("Result.failure creates a failure result", (t) => { const error = new Error("test error"); - const result = util.Result.failure(error); + const result = new util.Failure(error); t.false(result.isSuccess()); t.true(result.isFailure()); t.is(result.value, error); }); test("Result.orElse returns the value for a success result", (t) => { - const result = util.Result.success("success value"); + const result = new util.Success("success value"); t.is(result.orElse("default value"), "success value"); }); test("Result.orElse returns the default value for a failure result", (t) => { - const result = util.Result.failure(new Error("test error")); + const result = new util.Failure(new Error("test error")); t.is(result.orElse("default value"), "default value"); }); diff --git a/src/util.ts b/src/util.ts index 3bcbb350b..29a75606b 100644 --- a/src/util.ts +++ b/src/util.ts @@ -1295,42 +1295,51 @@ export function joinAtMost( return array.join(separator); } -/** A success result. */ -type Success = Result; -/** A failure result. */ -type Failure = Result; - -/** - * A simple result type representing either a success or a failure. - */ -export class Result { - private constructor( - private readonly _ok: boolean, - public readonly value: T | E, - ) {} - - /** Creates a success result. */ - static success(value: T): Success { - return new Result(true, value) as Success; - } - - /** Creates a failure result. */ - static failure(value: E): Failure { - return new Result(false, value) as Failure; - } - +/** A simple result type representing either a success or a failure. */ +interface ResultLike { + /** The value of the result, which can be either a success value or a failure value. */ + value: T | E; /** Whether this result represents a success. */ - isSuccess(): this is Success { - return this._ok; - } - + isSuccess(): this is Success; /** Whether this result represents a failure. */ - isFailure(): this is Failure { - return !this._ok; + isFailure(): this is Failure; + /** Get the value if this is a success, or return the default value if this is a failure. */ + orElse(defaultValue: U): T | U; +} + +/** A simple result type representing either a success or a failure. */ +export type Result = Success | Failure; + +/** A result representing a success. */ +export class Success implements ResultLike { + constructor(public readonly value: T) {} + + isSuccess(): this is Success { + return true; } - /** Get the value if this is a success, or return the default value if this is a failure. */ - orElse(defaultValue: U): T | U { - return this.isSuccess() ? this.value : defaultValue; + isFailure(): this is Failure { + return false; + } + + orElse(_defaultValue: U): T { + return this.value; + } +} + +/** A result representing a failure. */ +export class Failure implements ResultLike { + constructor(public readonly value: E) {} + + isSuccess(): this is Success { + return false; + } + + isFailure(): this is Failure { + return true; + } + + orElse(defaultValue: U): never | U { + return defaultValue; } } From e51b6a9a520cc75c12cc3a2eaef8363f6845b5be Mon Sep 17 00:00:00 2001 From: Henry Mercer Date: Tue, 24 Feb 2026 17:55:29 +0000 Subject: [PATCH 3/6] Update names in tests --- src/util.test.ts | 8 ++++---- src/util.ts | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/src/util.test.ts b/src/util.test.ts index b63a91c8b..7b6850018 100644 --- a/src/util.test.ts +++ b/src/util.test.ts @@ -564,14 +564,14 @@ test("joinAtMost - truncates list if array is > than limit", (t) => { t.false(result.includes("test6")); }); -test("Result.success creates a success result", (t) => { +test("Success creates a success result", (t) => { const result = new util.Success("test value"); t.true(result.isSuccess()); t.false(result.isFailure()); t.is(result.value, "test value"); }); -test("Result.failure creates a failure result", (t) => { +test("Failure creates a failure result", (t) => { const error = new Error("test error"); const result = new util.Failure(error); t.false(result.isSuccess()); @@ -579,12 +579,12 @@ test("Result.failure creates a failure result", (t) => { t.is(result.value, error); }); -test("Result.orElse returns the value for a success result", (t) => { +test("Success.orElse returns the value for a success result", (t) => { const result = new util.Success("success value"); t.is(result.orElse("default value"), "success value"); }); -test("Result.orElse returns the default value for a failure result", (t) => { +test("Failure.orElse returns the default value for a failure result", (t) => { const result = new util.Failure(new Error("test error")); t.is(result.orElse("default value"), "default value"); }); diff --git a/src/util.ts b/src/util.ts index 29a75606b..4862bc8e9 100644 --- a/src/util.ts +++ b/src/util.ts @@ -1339,7 +1339,7 @@ export class Failure implements ResultLike { return true; } - orElse(defaultValue: U): never | U { + orElse(defaultValue: U): U { return defaultValue; } } From 2a607fea25af475c1da15fbb12d33701cdf05d16 Mon Sep 17 00:00:00 2001 From: Henry Mercer Date: Tue, 24 Feb 2026 19:28:27 +0000 Subject: [PATCH 4/6] Update JSDoc Co-authored-by: Michael B. Gale --- src/util.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/util.ts b/src/util.ts index 4862bc8e9..607b19aa9 100644 --- a/src/util.ts +++ b/src/util.ts @@ -1295,7 +1295,7 @@ export function joinAtMost( return array.join(separator); } -/** A simple result type representing either a success or a failure. */ +/** An interface representing something that is either a success or a failure. */ interface ResultLike { /** The value of the result, which can be either a success value or a failure value. */ value: T | E; From 0aafb58a10b2dbc56c1d060e0e0a0219d52d0f9c Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 25 Feb 2026 00:17:44 +0000 Subject: [PATCH 5/6] Bump minimatch Bumps and [minimatch](https://github.com/isaacs/minimatch). These dependencies needed to be updated together. Updates `minimatch` from 10.1.1 to 10.2.2 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](https://github.com/isaacs/minimatch/compare/v10.1.1...v10.2.2) Updates `minimatch` from 5.1.6 to 5.1.7 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](https://github.com/isaacs/minimatch/compare/v10.1.1...v10.2.2) Updates `minimatch` from 3.1.2 to 3.1.3 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](https://github.com/isaacs/minimatch/compare/v10.1.1...v10.2.2) Updates `minimatch` from 9.0.5 to 9.0.6 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](https://github.com/isaacs/minimatch/compare/v10.1.1...v10.2.2) --- updated-dependencies: - dependency-name: minimatch dependency-version: 10.2.2 dependency-type: indirect - dependency-name: minimatch dependency-version: 5.1.7 dependency-type: indirect - dependency-name: minimatch dependency-version: 3.1.3 dependency-type: indirect - dependency-name: minimatch dependency-version: 9.0.6 dependency-type: indirect ... Signed-off-by: dependabot[bot] --- package-lock.json | 95 +++++++++++++++++++++++++++-------------------- 1 file changed, 55 insertions(+), 40 deletions(-) diff --git a/package-lock.json b/package-lock.json index 89e11fc2d..203901544 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1607,27 +1607,6 @@ "url": "https://github.com/sponsors/nzakas" } }, - "node_modules/@isaacs/balanced-match": { - "version": "4.0.1", - "resolved": "https://registry.npmjs.org/@isaacs/balanced-match/-/balanced-match-4.0.1.tgz", - "integrity": "sha512-yzMTt9lEb8Gv7zRioUilSglI0c0smZ9k5D65677DLWLtWJaXIS3CqcGyUFByYKlnUj6TkjLVs54fBl6+TiGQDQ==", - "license": "MIT", - "engines": { - "node": "20 || >=22" - } - }, - "node_modules/@isaacs/brace-expansion": { - "version": "5.0.1", - "resolved": "https://registry.npmjs.org/@isaacs/brace-expansion/-/brace-expansion-5.0.1.tgz", - "integrity": "sha512-WMz71T1JS624nWj2n2fnYAuPovhv7EUhk69R6i9dsVyzxt5eM3bjwvgk9L+APE1TRscGysAVMANkB0jh0LQZrQ==", - "license": "MIT", - "dependencies": { - "@isaacs/balanced-match": "^4.0.1" - }, - "engines": { - "node": "20 || >=22" - } - }, "node_modules/@isaacs/cliui": { "version": "8.0.2", "resolved": "https://registry.npmjs.org/@isaacs/cliui/-/cliui-8.0.2.tgz", @@ -2807,14 +2786,27 @@ "typescript": ">=4.8.4 <6.0.0" } }, + "node_modules/@typescript-eslint/typescript-estree/node_modules/balanced-match": { + "version": "4.0.4", + "resolved": "https://registry.npmjs.org/balanced-match/-/balanced-match-4.0.4.tgz", + "integrity": "sha512-BLrgEcRTwX2o6gGxGOCNyMvGSp35YofuYzw9h1IMTRmKqttAZZVU67bdb9Pr2vUHA8+j3i2tJfjO6C6+4myGTA==", + "dev": true, + "license": "MIT", + "engines": { + "node": "18 || 20 || >=22" + } + }, "node_modules/@typescript-eslint/typescript-estree/node_modules/brace-expansion": { - "version": "2.0.2", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.2.tgz", - "integrity": "sha512-Jt0vHyM+jmUBqojB7E1NIYadt0vI0Qxjxd2TErW94wDz+E2LAm5vKMXXwg6ZZBTHPuUlDgQHKXvjGBdfcF1ZDQ==", + "version": "5.0.3", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.3.tgz", + "integrity": "sha512-fy6KJm2RawA5RcHkLa1z/ScpBeA762UF9KmZQxwIbDtRJrgLzM10depAiEQ+CXYcoiqW1/m96OAAoke2nE9EeA==", "dev": true, "license": "MIT", "dependencies": { - "balanced-match": "^1.0.0" + "balanced-match": "^4.0.2" + }, + "engines": { + "node": "18 || 20 || >=22" } }, "node_modules/@typescript-eslint/typescript-estree/node_modules/debug": { @@ -2836,13 +2828,13 @@ } }, "node_modules/@typescript-eslint/typescript-estree/node_modules/minimatch": { - "version": "9.0.5", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-9.0.5.tgz", - "integrity": "sha512-G6T0ZX48xgozx7587koeX9Ys2NYy6Gmv//P89sEte9V9whIapMNF4idKxnW2QtCcLiTWlb/wfCabAtAFWhhBow==", + "version": "9.0.6", + "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-9.0.6.tgz", + "integrity": "sha512-kQAVowdR33euIqeA0+VZTDqU+qo1IeVY+hrKYtZMio3Pg0P0vuh/kwRylLUddJhB6pf3q/botcOvRtx4IN1wqQ==", "dev": true, "license": "ISC", "dependencies": { - "brace-expansion": "^2.0.1" + "brace-expansion": "^5.0.2" }, "engines": { "node": ">=16 || 14 >=14.17" @@ -6010,16 +6002,37 @@ "node": ">= 6" } }, - "node_modules/glob/node_modules/minimatch": { - "version": "10.1.1", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-10.1.1.tgz", - "integrity": "sha512-enIvLvRAFZYXJzkCYG5RKmPfrFArdLv+R+lbQ53BmIMLIry74bjKzX6iHAm8WYamJkhSSEabrWN5D97XnKObjQ==", - "license": "BlueOak-1.0.0", + "node_modules/glob/node_modules/balanced-match": { + "version": "4.0.4", + "resolved": "https://registry.npmjs.org/balanced-match/-/balanced-match-4.0.4.tgz", + "integrity": "sha512-BLrgEcRTwX2o6gGxGOCNyMvGSp35YofuYzw9h1IMTRmKqttAZZVU67bdb9Pr2vUHA8+j3i2tJfjO6C6+4myGTA==", + "license": "MIT", + "engines": { + "node": "18 || 20 || >=22" + } + }, + "node_modules/glob/node_modules/brace-expansion": { + "version": "5.0.3", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.3.tgz", + "integrity": "sha512-fy6KJm2RawA5RcHkLa1z/ScpBeA762UF9KmZQxwIbDtRJrgLzM10depAiEQ+CXYcoiqW1/m96OAAoke2nE9EeA==", + "license": "MIT", "dependencies": { - "@isaacs/brace-expansion": "^5.0.0" + "balanced-match": "^4.0.2" }, "engines": { - "node": "20 || >=22" + "node": "18 || 20 || >=22" + } + }, + "node_modules/glob/node_modules/minimatch": { + "version": "10.2.2", + "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-10.2.2.tgz", + "integrity": "sha512-+G4CpNBxa5MprY+04MbgOw1v7So6n5JY166pFi9KfYwT78fxScCeSNQSNzp6dpPSW2rONOps6Ocam1wFhCgoVw==", + "license": "BlueOak-1.0.0", + "dependencies": { + "brace-expansion": "^5.0.2" + }, + "engines": { + "node": "18 || 20 || >=22" }, "funding": { "url": "https://github.com/sponsors/isaacs" @@ -7227,7 +7240,9 @@ } }, "node_modules/minimatch": { - "version": "3.1.2", + "version": "3.1.3", + "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-3.1.3.tgz", + "integrity": "sha512-M2GCs7Vk83NxkUyQV1bkABc4yxgz9kILhHImZiBPAZ9ybuvCb0/H7lEl5XvIg3g+9d4eNotkZA5IWwYl0tibaA==", "license": "ISC", "dependencies": { "brace-expansion": "^1.1.7" @@ -7913,9 +7928,9 @@ } }, "node_modules/readdir-glob/node_modules/minimatch": { - "version": "5.1.6", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-5.1.6.tgz", - "integrity": "sha512-lKwV/1brpG6mBUFHtb7NUmtABCb2WZZmm2wNiOA5hAb8VdCS4B3dtMWyvcoViccwAW/COERjXLt0zP1zXUN26g==", + "version": "5.1.7", + "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-5.1.7.tgz", + "integrity": "sha512-FjiwU9HaHW6YB3H4a1sFudnv93lvydNjz2lmyUXR6IwKhGI+bgL3SOZrBGn6kvvX2pJvhEkGSGjyTHN47O4rqA==", "license": "ISC", "dependencies": { "brace-expansion": "^2.0.1" From 123b3011faa9ffce4bf411a5a954f1485254b50e Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Wed, 25 Feb 2026 00:19:51 +0000 Subject: [PATCH 6/6] Rebuild --- lib/analyze-action-post.js | 41 +++++++++++++++++++++---------- lib/analyze-action.js | 1 + lib/autobuild-action.js | 1 + lib/init-action-post.js | 41 +++++++++++++++++++++---------- lib/init-action.js | 1 + lib/resolve-environment-action.js | 1 + lib/setup-codeql-action.js | 1 + lib/start-proxy-action-post.js | 41 +++++++++++++++++++++---------- lib/start-proxy-action.js | 1 + lib/upload-lib.js | 1 + lib/upload-sarif-action-post.js | 41 +++++++++++++++++++++---------- lib/upload-sarif-action.js | 1 + 12 files changed, 120 insertions(+), 52 deletions(-) diff --git a/lib/analyze-action-post.js b/lib/analyze-action-post.js index 7c8823caa..8d5f7d001 100644 --- a/lib/analyze-action-post.js +++ b/lib/analyze-action-post.js @@ -49518,6 +49518,7 @@ var require_minimatch = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; self2.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c; @@ -103582,6 +103583,7 @@ var require_minimatch2 = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; this.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c; @@ -116408,9 +116410,9 @@ var require_isPlainObject = __commonJS({ } }); -// node_modules/@isaacs/balanced-match/dist/commonjs/index.js +// node_modules/glob/node_modules/balanced-match/dist/commonjs/index.js var require_commonjs18 = __commonJS({ - "node_modules/@isaacs/balanced-match/dist/commonjs/index.js"(exports2) { + "node_modules/glob/node_modules/balanced-match/dist/commonjs/index.js"(exports2) { "use strict"; Object.defineProperty(exports2, "__esModule", { value: true }); exports2.range = exports2.balanced = void 0; @@ -116470,9 +116472,9 @@ var require_commonjs18 = __commonJS({ } }); -// node_modules/@isaacs/brace-expansion/dist/commonjs/index.js +// node_modules/glob/node_modules/brace-expansion/dist/commonjs/index.js var require_commonjs19 = __commonJS({ - "node_modules/@isaacs/brace-expansion/dist/commonjs/index.js"(exports2) { + "node_modules/glob/node_modules/brace-expansion/dist/commonjs/index.js"(exports2) { "use strict"; Object.defineProperty(exports2, "__esModule", { value: true }); exports2.EXPANSION_MAX = void 0; @@ -117233,6 +117235,7 @@ var require_ast = __commonJS({ let escaping = false; let re = ""; let uflag = false; + let inStar = false; for (let i = 0; i < glob2.length; i++) { const c = glob2.charAt(i); if (escaping) { @@ -117240,6 +117243,16 @@ var require_ast = __commonJS({ re += (reSpecials.has(c) ? "\\" : "") + c; continue; } + if (c === "*") { + if (inStar) + continue; + inStar = true; + re += noEmpty && /^[*]+$/.test(glob2) ? starNoEmpty : star; + hasMagic = true; + continue; + } else { + inStar = false; + } if (c === "\\") { if (i === glob2.length - 1) { re += "\\\\"; @@ -117258,11 +117271,6 @@ var require_ast = __commonJS({ continue; } } - if (c === "*") { - re += noEmpty && glob2 === "*" ? starNoEmpty : star; - hasMagic = true; - continue; - } if (c === "?") { re += qmark; hasMagic = true; @@ -117422,7 +117430,7 @@ var require_commonjs20 = __commonJS({ if (options.nobrace || !/\{(?:(?!\{).)*\}/.test(pattern)) { return [pattern]; } - return (0, brace_expansion_1.expand)(pattern); + return (0, brace_expansion_1.expand)(pattern, { max: options.braceExpandMax }); }; exports2.braceExpand = braceExpand; exports2.minimatch.braceExpand = exports2.braceExpand; @@ -117466,7 +117474,8 @@ var require_commonjs20 = __commonJS({ this.pattern = pattern; this.platform = options.platform || defaultPlatform; this.isWindows = this.platform === "win32"; - this.windowsPathsNoEscape = !!options.windowsPathsNoEscape || options.allowWindowsEscape === false; + const awe = "allowWindowsEscape"; + this.windowsPathsNoEscape = !!options.windowsPathsNoEscape || options[awe] === false; if (this.windowsPathsNoEscape) { this.pattern = this.pattern.replace(/\\/g, "/"); } @@ -117523,7 +117532,10 @@ var require_commonjs20 = __commonJS({ const isUNC = s[0] === "" && s[1] === "" && (s[2] === "?" || !globMagic.test(s[2])) && !globMagic.test(s[3]); const isDrive = /^[a-z]:/i.test(s[0]); if (isUNC) { - return [...s.slice(0, 4), ...s.slice(4).map((ss) => this.parse(ss))]; + return [ + ...s.slice(0, 4), + ...s.slice(4).map((ss) => this.parse(ss)) + ]; } else if (isDrive) { return [s[0], ...s.slice(1).map((ss) => this.parse(ss))]; } @@ -117804,7 +117816,10 @@ var require_commonjs20 = __commonJS({ const fdi = fileUNC ? 3 : fileDrive ? 0 : void 0; const pdi = patternUNC ? 3 : patternDrive ? 0 : void 0; if (typeof fdi === "number" && typeof pdi === "number") { - const [fd, pd] = [file[fdi], pattern[pdi]]; + const [fd, pd] = [ + file[fdi], + pattern[pdi] + ]; if (fd.toLowerCase() === pd.toLowerCase()) { pattern[pdi] = fd; if (pdi > fdi) { diff --git a/lib/analyze-action.js b/lib/analyze-action.js index 806fd5c46..b5710b2a4 100644 --- a/lib/analyze-action.js +++ b/lib/analyze-action.js @@ -49518,6 +49518,7 @@ var require_minimatch = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; self2.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c; diff --git a/lib/autobuild-action.js b/lib/autobuild-action.js index 03b8b56cd..490fd7a3d 100644 --- a/lib/autobuild-action.js +++ b/lib/autobuild-action.js @@ -49518,6 +49518,7 @@ var require_minimatch = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; self2.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c; diff --git a/lib/init-action-post.js b/lib/init-action-post.js index bc1294485..50fcc0603 100644 --- a/lib/init-action-post.js +++ b/lib/init-action-post.js @@ -49518,6 +49518,7 @@ var require_minimatch = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; self2.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c; @@ -103582,6 +103583,7 @@ var require_minimatch2 = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; this.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c; @@ -116408,9 +116410,9 @@ var require_isPlainObject = __commonJS({ } }); -// node_modules/@isaacs/balanced-match/dist/commonjs/index.js +// node_modules/glob/node_modules/balanced-match/dist/commonjs/index.js var require_commonjs18 = __commonJS({ - "node_modules/@isaacs/balanced-match/dist/commonjs/index.js"(exports2) { + "node_modules/glob/node_modules/balanced-match/dist/commonjs/index.js"(exports2) { "use strict"; Object.defineProperty(exports2, "__esModule", { value: true }); exports2.range = exports2.balanced = void 0; @@ -116470,9 +116472,9 @@ var require_commonjs18 = __commonJS({ } }); -// node_modules/@isaacs/brace-expansion/dist/commonjs/index.js +// node_modules/glob/node_modules/brace-expansion/dist/commonjs/index.js var require_commonjs19 = __commonJS({ - "node_modules/@isaacs/brace-expansion/dist/commonjs/index.js"(exports2) { + "node_modules/glob/node_modules/brace-expansion/dist/commonjs/index.js"(exports2) { "use strict"; Object.defineProperty(exports2, "__esModule", { value: true }); exports2.EXPANSION_MAX = void 0; @@ -117233,6 +117235,7 @@ var require_ast = __commonJS({ let escaping = false; let re = ""; let uflag = false; + let inStar = false; for (let i = 0; i < glob2.length; i++) { const c = glob2.charAt(i); if (escaping) { @@ -117240,6 +117243,16 @@ var require_ast = __commonJS({ re += (reSpecials.has(c) ? "\\" : "") + c; continue; } + if (c === "*") { + if (inStar) + continue; + inStar = true; + re += noEmpty && /^[*]+$/.test(glob2) ? starNoEmpty : star; + hasMagic = true; + continue; + } else { + inStar = false; + } if (c === "\\") { if (i === glob2.length - 1) { re += "\\\\"; @@ -117258,11 +117271,6 @@ var require_ast = __commonJS({ continue; } } - if (c === "*") { - re += noEmpty && glob2 === "*" ? starNoEmpty : star; - hasMagic = true; - continue; - } if (c === "?") { re += qmark; hasMagic = true; @@ -117422,7 +117430,7 @@ var require_commonjs20 = __commonJS({ if (options.nobrace || !/\{(?:(?!\{).)*\}/.test(pattern)) { return [pattern]; } - return (0, brace_expansion_1.expand)(pattern); + return (0, brace_expansion_1.expand)(pattern, { max: options.braceExpandMax }); }; exports2.braceExpand = braceExpand; exports2.minimatch.braceExpand = exports2.braceExpand; @@ -117466,7 +117474,8 @@ var require_commonjs20 = __commonJS({ this.pattern = pattern; this.platform = options.platform || defaultPlatform; this.isWindows = this.platform === "win32"; - this.windowsPathsNoEscape = !!options.windowsPathsNoEscape || options.allowWindowsEscape === false; + const awe = "allowWindowsEscape"; + this.windowsPathsNoEscape = !!options.windowsPathsNoEscape || options[awe] === false; if (this.windowsPathsNoEscape) { this.pattern = this.pattern.replace(/\\/g, "/"); } @@ -117523,7 +117532,10 @@ var require_commonjs20 = __commonJS({ const isUNC = s[0] === "" && s[1] === "" && (s[2] === "?" || !globMagic.test(s[2])) && !globMagic.test(s[3]); const isDrive = /^[a-z]:/i.test(s[0]); if (isUNC) { - return [...s.slice(0, 4), ...s.slice(4).map((ss) => this.parse(ss))]; + return [ + ...s.slice(0, 4), + ...s.slice(4).map((ss) => this.parse(ss)) + ]; } else if (isDrive) { return [s[0], ...s.slice(1).map((ss) => this.parse(ss))]; } @@ -117804,7 +117816,10 @@ var require_commonjs20 = __commonJS({ const fdi = fileUNC ? 3 : fileDrive ? 0 : void 0; const pdi = patternUNC ? 3 : patternDrive ? 0 : void 0; if (typeof fdi === "number" && typeof pdi === "number") { - const [fd, pd] = [file[fdi], pattern[pdi]]; + const [fd, pd] = [ + file[fdi], + pattern[pdi] + ]; if (fd.toLowerCase() === pd.toLowerCase()) { pattern[pdi] = fd; if (pdi > fdi) { diff --git a/lib/init-action.js b/lib/init-action.js index 403b5cdc6..47202a0ba 100644 --- a/lib/init-action.js +++ b/lib/init-action.js @@ -49669,6 +49669,7 @@ var require_minimatch = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; self2.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c; diff --git a/lib/resolve-environment-action.js b/lib/resolve-environment-action.js index 8aac361a3..4fbb72281 100644 --- a/lib/resolve-environment-action.js +++ b/lib/resolve-environment-action.js @@ -49518,6 +49518,7 @@ var require_minimatch = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; self2.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c; diff --git a/lib/setup-codeql-action.js b/lib/setup-codeql-action.js index 6a521cc92..782051e06 100644 --- a/lib/setup-codeql-action.js +++ b/lib/setup-codeql-action.js @@ -48221,6 +48221,7 @@ var require_minimatch = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; self2.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c; diff --git a/lib/start-proxy-action-post.js b/lib/start-proxy-action-post.js index afed44174..3d85eec2d 100644 --- a/lib/start-proxy-action-post.js +++ b/lib/start-proxy-action-post.js @@ -49518,6 +49518,7 @@ var require_minimatch = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; self2.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c; @@ -102209,6 +102210,7 @@ var require_minimatch2 = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; this.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c; @@ -115035,9 +115037,9 @@ var require_isPlainObject = __commonJS({ } }); -// node_modules/@isaacs/balanced-match/dist/commonjs/index.js +// node_modules/glob/node_modules/balanced-match/dist/commonjs/index.js var require_commonjs18 = __commonJS({ - "node_modules/@isaacs/balanced-match/dist/commonjs/index.js"(exports2) { + "node_modules/glob/node_modules/balanced-match/dist/commonjs/index.js"(exports2) { "use strict"; Object.defineProperty(exports2, "__esModule", { value: true }); exports2.range = exports2.balanced = void 0; @@ -115097,9 +115099,9 @@ var require_commonjs18 = __commonJS({ } }); -// node_modules/@isaacs/brace-expansion/dist/commonjs/index.js +// node_modules/glob/node_modules/brace-expansion/dist/commonjs/index.js var require_commonjs19 = __commonJS({ - "node_modules/@isaacs/brace-expansion/dist/commonjs/index.js"(exports2) { + "node_modules/glob/node_modules/brace-expansion/dist/commonjs/index.js"(exports2) { "use strict"; Object.defineProperty(exports2, "__esModule", { value: true }); exports2.EXPANSION_MAX = void 0; @@ -115860,6 +115862,7 @@ var require_ast = __commonJS({ let escaping = false; let re = ""; let uflag = false; + let inStar = false; for (let i = 0; i < glob2.length; i++) { const c = glob2.charAt(i); if (escaping) { @@ -115867,6 +115870,16 @@ var require_ast = __commonJS({ re += (reSpecials.has(c) ? "\\" : "") + c; continue; } + if (c === "*") { + if (inStar) + continue; + inStar = true; + re += noEmpty && /^[*]+$/.test(glob2) ? starNoEmpty : star; + hasMagic = true; + continue; + } else { + inStar = false; + } if (c === "\\") { if (i === glob2.length - 1) { re += "\\\\"; @@ -115885,11 +115898,6 @@ var require_ast = __commonJS({ continue; } } - if (c === "*") { - re += noEmpty && glob2 === "*" ? starNoEmpty : star; - hasMagic = true; - continue; - } if (c === "?") { re += qmark; hasMagic = true; @@ -116049,7 +116057,7 @@ var require_commonjs20 = __commonJS({ if (options.nobrace || !/\{(?:(?!\{).)*\}/.test(pattern)) { return [pattern]; } - return (0, brace_expansion_1.expand)(pattern); + return (0, brace_expansion_1.expand)(pattern, { max: options.braceExpandMax }); }; exports2.braceExpand = braceExpand; exports2.minimatch.braceExpand = exports2.braceExpand; @@ -116093,7 +116101,8 @@ var require_commonjs20 = __commonJS({ this.pattern = pattern; this.platform = options.platform || defaultPlatform; this.isWindows = this.platform === "win32"; - this.windowsPathsNoEscape = !!options.windowsPathsNoEscape || options.allowWindowsEscape === false; + const awe = "allowWindowsEscape"; + this.windowsPathsNoEscape = !!options.windowsPathsNoEscape || options[awe] === false; if (this.windowsPathsNoEscape) { this.pattern = this.pattern.replace(/\\/g, "/"); } @@ -116150,7 +116159,10 @@ var require_commonjs20 = __commonJS({ const isUNC = s[0] === "" && s[1] === "" && (s[2] === "?" || !globMagic.test(s[2])) && !globMagic.test(s[3]); const isDrive = /^[a-z]:/i.test(s[0]); if (isUNC) { - return [...s.slice(0, 4), ...s.slice(4).map((ss) => this.parse(ss))]; + return [ + ...s.slice(0, 4), + ...s.slice(4).map((ss) => this.parse(ss)) + ]; } else if (isDrive) { return [s[0], ...s.slice(1).map((ss) => this.parse(ss))]; } @@ -116431,7 +116443,10 @@ var require_commonjs20 = __commonJS({ const fdi = fileUNC ? 3 : fileDrive ? 0 : void 0; const pdi = patternUNC ? 3 : patternDrive ? 0 : void 0; if (typeof fdi === "number" && typeof pdi === "number") { - const [fd, pd] = [file[fdi], pattern[pdi]]; + const [fd, pd] = [ + file[fdi], + pattern[pdi] + ]; if (fd.toLowerCase() === pd.toLowerCase()) { pattern[pdi] = fd; if (pdi > fdi) { diff --git a/lib/start-proxy-action.js b/lib/start-proxy-action.js index 1f83e0a9f..75ce37a31 100644 --- a/lib/start-proxy-action.js +++ b/lib/start-proxy-action.js @@ -48221,6 +48221,7 @@ var require_minimatch = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; self2.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c; diff --git a/lib/upload-lib.js b/lib/upload-lib.js index 01383883e..1f5ed3889 100644 --- a/lib/upload-lib.js +++ b/lib/upload-lib.js @@ -49518,6 +49518,7 @@ var require_minimatch = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; self2.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c; diff --git a/lib/upload-sarif-action-post.js b/lib/upload-sarif-action-post.js index 67c09a211..1753662dc 100644 --- a/lib/upload-sarif-action-post.js +++ b/lib/upload-sarif-action-post.js @@ -94492,6 +94492,7 @@ var require_minimatch = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; this.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c; @@ -107318,9 +107319,9 @@ var require_isPlainObject = __commonJS({ } }); -// node_modules/@isaacs/balanced-match/dist/commonjs/index.js +// node_modules/glob/node_modules/balanced-match/dist/commonjs/index.js var require_commonjs18 = __commonJS({ - "node_modules/@isaacs/balanced-match/dist/commonjs/index.js"(exports2) { + "node_modules/glob/node_modules/balanced-match/dist/commonjs/index.js"(exports2) { "use strict"; Object.defineProperty(exports2, "__esModule", { value: true }); exports2.range = exports2.balanced = void 0; @@ -107380,9 +107381,9 @@ var require_commonjs18 = __commonJS({ } }); -// node_modules/@isaacs/brace-expansion/dist/commonjs/index.js +// node_modules/glob/node_modules/brace-expansion/dist/commonjs/index.js var require_commonjs19 = __commonJS({ - "node_modules/@isaacs/brace-expansion/dist/commonjs/index.js"(exports2) { + "node_modules/glob/node_modules/brace-expansion/dist/commonjs/index.js"(exports2) { "use strict"; Object.defineProperty(exports2, "__esModule", { value: true }); exports2.EXPANSION_MAX = void 0; @@ -108143,6 +108144,7 @@ var require_ast = __commonJS({ let escaping = false; let re = ""; let uflag = false; + let inStar = false; for (let i = 0; i < glob2.length; i++) { const c = glob2.charAt(i); if (escaping) { @@ -108150,6 +108152,16 @@ var require_ast = __commonJS({ re += (reSpecials.has(c) ? "\\" : "") + c; continue; } + if (c === "*") { + if (inStar) + continue; + inStar = true; + re += noEmpty && /^[*]+$/.test(glob2) ? starNoEmpty : star; + hasMagic = true; + continue; + } else { + inStar = false; + } if (c === "\\") { if (i === glob2.length - 1) { re += "\\\\"; @@ -108168,11 +108180,6 @@ var require_ast = __commonJS({ continue; } } - if (c === "*") { - re += noEmpty && glob2 === "*" ? starNoEmpty : star; - hasMagic = true; - continue; - } if (c === "?") { re += qmark; hasMagic = true; @@ -108332,7 +108339,7 @@ var require_commonjs20 = __commonJS({ if (options.nobrace || !/\{(?:(?!\{).)*\}/.test(pattern)) { return [pattern]; } - return (0, brace_expansion_1.expand)(pattern); + return (0, brace_expansion_1.expand)(pattern, { max: options.braceExpandMax }); }; exports2.braceExpand = braceExpand; exports2.minimatch.braceExpand = exports2.braceExpand; @@ -108376,7 +108383,8 @@ var require_commonjs20 = __commonJS({ this.pattern = pattern; this.platform = options.platform || defaultPlatform; this.isWindows = this.platform === "win32"; - this.windowsPathsNoEscape = !!options.windowsPathsNoEscape || options.allowWindowsEscape === false; + const awe = "allowWindowsEscape"; + this.windowsPathsNoEscape = !!options.windowsPathsNoEscape || options[awe] === false; if (this.windowsPathsNoEscape) { this.pattern = this.pattern.replace(/\\/g, "/"); } @@ -108433,7 +108441,10 @@ var require_commonjs20 = __commonJS({ const isUNC = s[0] === "" && s[1] === "" && (s[2] === "?" || !globMagic.test(s[2])) && !globMagic.test(s[3]); const isDrive = /^[a-z]:/i.test(s[0]); if (isUNC) { - return [...s.slice(0, 4), ...s.slice(4).map((ss) => this.parse(ss))]; + return [ + ...s.slice(0, 4), + ...s.slice(4).map((ss) => this.parse(ss)) + ]; } else if (isDrive) { return [s[0], ...s.slice(1).map((ss) => this.parse(ss))]; } @@ -108714,7 +108725,10 @@ var require_commonjs20 = __commonJS({ const fdi = fileUNC ? 3 : fileDrive ? 0 : void 0; const pdi = patternUNC ? 3 : patternDrive ? 0 : void 0; if (typeof fdi === "number" && typeof pdi === "number") { - const [fd, pd] = [file[fdi], pattern[pdi]]; + const [fd, pd] = [ + file[fdi], + pattern[pdi] + ]; if (fd.toLowerCase() === pd.toLowerCase()) { pattern[pdi] = fd; if (pdi > fdi) { @@ -150931,6 +150945,7 @@ var require_minimatch2 = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; self2.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c; diff --git a/lib/upload-sarif-action.js b/lib/upload-sarif-action.js index 34114e3ea..651623824 100644 --- a/lib/upload-sarif-action.js +++ b/lib/upload-sarif-action.js @@ -48221,6 +48221,7 @@ var require_minimatch = __commonJS({ re += c; continue; } + if (c === "*" && stateChar === "*") continue; self2.debug("call clearStateChar %j", stateChar); clearStateChar(); stateChar = c;