mirror of
https://github.com/github/codeql-action.git
synced 2026-10-03 09:14:58 +00:00
Merge pull request #4084 from github/navntoft/bump-undici
Bump undici from ^6.24.0 to ^6.28.0
This commit is contained in:
94
lib/entry-points.js
generated
94
lib/entry-points.js
generated
@@ -2218,7 +2218,11 @@ var require_request = __commonJS({
|
||||
} else if (typeof val[i] === "object") {
|
||||
throw new InvalidArgumentError(`invalid ${key} header`);
|
||||
} else {
|
||||
arr.push(`${val[i]}`);
|
||||
const str = `${val[i]}`;
|
||||
if (!isValidHeaderValue(str)) {
|
||||
throw new InvalidArgumentError(`invalid ${key} header`);
|
||||
}
|
||||
arr.push(str);
|
||||
}
|
||||
}
|
||||
val = arr;
|
||||
@@ -2230,6 +2234,9 @@ var require_request = __commonJS({
|
||||
val = "";
|
||||
} else {
|
||||
val = `${val}`;
|
||||
if (!isValidHeaderValue(val)) {
|
||||
throw new InvalidArgumentError(`invalid ${key} header`);
|
||||
}
|
||||
}
|
||||
if (headerName === "host") {
|
||||
if (request3.host !== null) {
|
||||
@@ -5960,6 +5967,7 @@ var require_client_h1 = __commonJS({
|
||||
RequestContentLengthMismatchError,
|
||||
ResponseContentLengthMismatchError,
|
||||
RequestAbortedError,
|
||||
InvalidArgumentError,
|
||||
HeadersTimeoutError,
|
||||
HeadersOverflowError,
|
||||
SocketError,
|
||||
@@ -6686,8 +6694,16 @@ var require_client_h1 = __commonJS({
|
||||
}
|
||||
body = bodyStream.stream;
|
||||
contentLength = bodyStream.length;
|
||||
} else if (util3.isBlobLike(body) && request3.contentType == null && body.type) {
|
||||
headers.push("content-type", body.type);
|
||||
} else if (util3.isBlobLike(body) && request3.contentType == null) {
|
||||
const contentType = body.type;
|
||||
if (contentType) {
|
||||
const contentTypeValue = `${contentType}`;
|
||||
if (!util3.isValidHeaderValue(contentTypeValue)) {
|
||||
util3.errorRequest(client, request3, new InvalidArgumentError("invalid content-type header"));
|
||||
return false;
|
||||
}
|
||||
headers.push("content-type", contentTypeValue);
|
||||
}
|
||||
}
|
||||
if (body && typeof body.read === "function") {
|
||||
body.read(0);
|
||||
@@ -9239,6 +9255,24 @@ var require_retry_handler = __commonJS({
|
||||
const current = Date.now();
|
||||
return new Date(retryAfter).getTime() - current;
|
||||
}
|
||||
function validatePartialResponseContentLength(headers, range2, statusCode, retryCount) {
|
||||
const contentLength = headers["content-length"];
|
||||
if (contentLength == null) {
|
||||
return null;
|
||||
}
|
||||
if (!Number.isFinite(range2.start) || !Number.isFinite(range2.end)) {
|
||||
return null;
|
||||
}
|
||||
const length = Number(contentLength);
|
||||
const expectedLength = range2.end - range2.start + 1;
|
||||
if (!Number.isFinite(length) || length !== expectedLength) {
|
||||
return new RequestRetryError("Content-Length mismatch", statusCode, {
|
||||
headers,
|
||||
data: { count: retryCount }
|
||||
});
|
||||
}
|
||||
return null;
|
||||
}
|
||||
var RetryHandler = class _RetryHandler {
|
||||
constructor(opts, handlers) {
|
||||
const { retryOptions, ...dispatchOpts } = opts;
|
||||
@@ -9411,6 +9445,11 @@ var require_retry_handler = __commonJS({
|
||||
);
|
||||
return false;
|
||||
}
|
||||
const contentLengthError = validatePartialResponseContentLength(headers, contentRange, statusCode, this.retryCount);
|
||||
if (contentLengthError != null) {
|
||||
this.abort(contentLengthError);
|
||||
return false;
|
||||
}
|
||||
const { start, size, end = size - 1 } = contentRange;
|
||||
assert(this.start === start, "content-range mismatch");
|
||||
assert(this.end == null || this.end === end, "content-range mismatch");
|
||||
@@ -9428,6 +9467,11 @@ var require_retry_handler = __commonJS({
|
||||
statusMessage
|
||||
);
|
||||
}
|
||||
const contentLengthError = validatePartialResponseContentLength(headers, range2, statusCode, this.retryCount);
|
||||
if (contentLengthError != null) {
|
||||
this.abort(contentLengthError);
|
||||
return false;
|
||||
}
|
||||
const { start, size, end = size - 1 } = range2;
|
||||
assert(
|
||||
start != null && Number.isFinite(start),
|
||||
@@ -16273,14 +16317,48 @@ var require_util6 = __commonJS({
|
||||
for (let i = 0; i < path29.length; ++i) {
|
||||
const code = path29.charCodeAt(i);
|
||||
if (code < 32 || // exclude CTLs (0-31)
|
||||
code === 127 || // DEL
|
||||
code > 126 || // exclude DEL and non-ascii
|
||||
code === 59) {
|
||||
throw new Error("Invalid cookie path");
|
||||
}
|
||||
}
|
||||
}
|
||||
function isLetterOrDigit(code) {
|
||||
return code >= 48 && code <= 57 || // 0-9
|
||||
code >= 65 && code <= 90 || // A-Z
|
||||
code >= 97 && code <= 122;
|
||||
}
|
||||
function validateCookieDomain(domain) {
|
||||
if (domain.startsWith("-") || domain.endsWith(".") || domain.endsWith("-")) {
|
||||
if (domain === " ") {
|
||||
return;
|
||||
}
|
||||
if (domain.length > 255) {
|
||||
throw new Error("Invalid cookie domain");
|
||||
}
|
||||
let labelLength = 0;
|
||||
for (let i = 0; i < domain.length; ++i) {
|
||||
const code = domain.charCodeAt(i);
|
||||
if (code === 46) {
|
||||
if (labelLength === 0) {
|
||||
throw new Error("Invalid cookie domain");
|
||||
}
|
||||
if (domain.charCodeAt(i - 1) === 45) {
|
||||
throw new Error("Invalid cookie domain");
|
||||
}
|
||||
labelLength = 0;
|
||||
continue;
|
||||
}
|
||||
if (labelLength === 0 && !isLetterOrDigit(code)) {
|
||||
throw new Error("Invalid cookie domain");
|
||||
}
|
||||
if (!isLetterOrDigit(code) && code !== 45) {
|
||||
throw new Error("Invalid cookie domain");
|
||||
}
|
||||
if (++labelLength > 63) {
|
||||
throw new Error("Invalid cookie domain");
|
||||
}
|
||||
}
|
||||
if (labelLength === 0 || domain.charCodeAt(domain.length - 1) === 45) {
|
||||
throw new Error("Invalid cookie domain");
|
||||
}
|
||||
}
|
||||
@@ -16363,7 +16441,11 @@ var require_util6 = __commonJS({
|
||||
throw new Error("Invalid unparsed");
|
||||
}
|
||||
const [key, ...value] = part.split("=");
|
||||
out.push(`${key.trim()}=${value.join("=")}`);
|
||||
const trimmedKey = key.trim();
|
||||
const joinedValue = value.join("=");
|
||||
validateCookieName(trimmedKey);
|
||||
validateCookieValue(joinedValue);
|
||||
out.push(`${trimmedKey}=${joinedValue}`);
|
||||
}
|
||||
return out.join("; ");
|
||||
}
|
||||
|
||||
9
package-lock.json
generated
9
package-lock.json
generated
@@ -36,7 +36,7 @@
|
||||
"long": "^5.3.2",
|
||||
"node-forge": "^1.4.0",
|
||||
"semver": "^7.8.5",
|
||||
"undici": "^6.24.0",
|
||||
"undici": "^6.28.0",
|
||||
"uuid": "^14.0.1"
|
||||
},
|
||||
"devDependencies": {
|
||||
@@ -9363,9 +9363,10 @@
|
||||
}
|
||||
},
|
||||
"node_modules/undici": {
|
||||
"version": "6.27.0",
|
||||
"resolved": "https://registry.npmjs.org/undici/-/undici-6.27.0.tgz",
|
||||
"integrity": "sha512-YmfV3YnEDzXRC5lZ2jWtWWHKGUm1zIt8AhesR1tens+HTNv+YZlN/dp6G727LOvMJ8xjP9Be7Y2Sdr96LDm+pg==",
|
||||
"version": "6.28.0",
|
||||
"resolved": "https://registry.npmjs.org/undici/-/undici-6.28.0.tgz",
|
||||
"integrity": "sha512-LIY910g9TI13YS95lrMFrs8Rm/u/irgHeTWoKCoteeJ04CUJ92eEfj0rVn+7VKMPBpUPiUoBKfhNyLI23EE/KA==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">=18.17"
|
||||
}
|
||||
|
||||
@@ -45,7 +45,7 @@
|
||||
"node-forge": "^1.4.0",
|
||||
"semver": "^7.8.5",
|
||||
"uuid": "^14.0.1",
|
||||
"undici": "^6.24.0"
|
||||
"undici": "^6.28.0"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@ava/typescript": "6.0.0",
|
||||
@@ -95,6 +95,6 @@
|
||||
"semver": ">=6.3.1"
|
||||
},
|
||||
"glob": "^13.0.6",
|
||||
"undici": "^6.24.0"
|
||||
"undici": "^6.28.0"
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user