mirror of
https://github.com/actions/runner.git
synced 2026-08-03 09:52:46 +08:00
Compare commits
12 Commits
v2.336.0
...
dependabot
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b3fd3c1613 | ||
|
|
b8dd9a3e3c | ||
|
|
cc01a0d090 | ||
|
|
03a0707cbe | ||
|
|
e1d1844725 | ||
|
|
44b796f3c8 | ||
|
|
6bb3178b59 | ||
|
|
148a3bb616 | ||
|
|
e18d1a9845 | ||
|
|
14de40d73a | ||
|
|
8bd0a334d7 | ||
|
|
f898ef14a5 |
@@ -4,7 +4,7 @@
|
|||||||
"features": {
|
"features": {
|
||||||
"ghcr.io/devcontainers/features/docker-in-docker:2": {},
|
"ghcr.io/devcontainers/features/docker-in-docker:2": {},
|
||||||
"ghcr.io/devcontainers/features/dotnet": {
|
"ghcr.io/devcontainers/features/dotnet": {
|
||||||
"version": "8.0.422"
|
"version": "8.0.423"
|
||||||
},
|
},
|
||||||
"ghcr.io/devcontainers/features/node:1": {
|
"ghcr.io/devcontainers/features/node:1": {
|
||||||
"version": "20"
|
"version": "20"
|
||||||
|
|||||||
2
.github/workflows/close-bugs-bot.yml
vendored
2
.github/workflows/close-bugs-bot.yml
vendored
@@ -7,7 +7,7 @@ jobs:
|
|||||||
stale:
|
stale:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/stale@v10
|
- uses: actions/stale@v11
|
||||||
with:
|
with:
|
||||||
close-issue-message: "This issue does not seem to be a problem with the runner application, it concerns the GitHub actions platform more generally. Could you please post your feedback on the [GitHub Community Support Forum](https://github.com/orgs/community/discussions/categories/actions) which is actively monitored. Using the forum ensures that we route your problem to the correct team. 😃"
|
close-issue-message: "This issue does not seem to be a problem with the runner application, it concerns the GitHub actions platform more generally. Could you please post your feedback on the [GitHub Community Support Forum](https://github.com/orgs/community/discussions/categories/actions) which is actively monitored. Using the forum ensures that we route your problem to the correct team. 😃"
|
||||||
exempt-issue-labels: "keep"
|
exempt-issue-labels: "keep"
|
||||||
|
|||||||
2
.github/workflows/close-features-bot.yml
vendored
2
.github/workflows/close-features-bot.yml
vendored
@@ -7,7 +7,7 @@ jobs:
|
|||||||
stale:
|
stale:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/stale@v10
|
- uses: actions/stale@v11
|
||||||
with:
|
with:
|
||||||
close-issue-message: "Thank you for your interest in the runner application and taking the time to provide your valuable feedback. We kindly ask you to redirect this feedback to the [GitHub Community Support Forum](https://github.com/orgs/community/discussions/categories/actions) which our team actively monitors and would be a better place to start a discussion for new feature requests in GitHub Actions. For more information on this policy please [read our contribution guidelines](https://github.com/actions/runner#contribute). 😃"
|
close-issue-message: "Thank you for your interest in the runner application and taking the time to provide your valuable feedback. We kindly ask you to redirect this feedback to the [GitHub Community Support Forum](https://github.com/orgs/community/discussions/categories/actions) which our team actively monitors and would be a better place to start a discussion for new feature requests in GitHub Actions. For more information on this policy please [read our contribution guidelines](https://github.com/actions/runner#contribute). 😃"
|
||||||
exempt-issue-labels: "keep"
|
exempt-issue-labels: "keep"
|
||||||
|
|||||||
2
.github/workflows/dependency-check.yml
vendored
2
.github/workflows/dependency-check.yml
vendored
@@ -31,7 +31,7 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v7
|
- uses: actions/checkout@v7
|
||||||
- name: Setup Node.js
|
- name: Setup Node.js
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v7
|
||||||
with:
|
with:
|
||||||
node-version: "20"
|
node-version: "20"
|
||||||
|
|
||||||
|
|||||||
2
.github/workflows/npm-audit-typescript.yml
vendored
2
.github/workflows/npm-audit-typescript.yml
vendored
@@ -9,7 +9,7 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v7
|
- uses: actions/checkout@v7
|
||||||
- name: Setup Node.js
|
- name: Setup Node.js
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v7
|
||||||
with:
|
with:
|
||||||
node-version: "20"
|
node-version: "20"
|
||||||
- name: NPM install and audit fix with TypeScript auto-repair
|
- name: NPM install and audit fix with TypeScript auto-repair
|
||||||
|
|||||||
2
.github/workflows/npm-audit.yml
vendored
2
.github/workflows/npm-audit.yml
vendored
@@ -12,7 +12,7 @@ jobs:
|
|||||||
- uses: actions/checkout@v7
|
- uses: actions/checkout@v7
|
||||||
|
|
||||||
- name: Setup Node.js
|
- name: Setup Node.js
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v7
|
||||||
with:
|
with:
|
||||||
node-version: "20"
|
node-version: "20"
|
||||||
|
|
||||||
|
|||||||
2
.github/workflows/stale-bot.yml
vendored
2
.github/workflows/stale-bot.yml
vendored
@@ -7,7 +7,7 @@ jobs:
|
|||||||
stale:
|
stale:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/stale@v10
|
- uses: actions/stale@v11
|
||||||
with:
|
with:
|
||||||
stale-issue-message: "This issue is stale because it has been open 365 days with no activity. Remove stale label or comment or this will be closed in 15 days."
|
stale-issue-message: "This issue is stale because it has been open 365 days with no activity. Remove stale label or comment or this will be closed in 15 days."
|
||||||
close-issue-message: "This issue was closed because it has been stalled for 15 days with no activity."
|
close-issue-message: "This issue was closed because it has been stalled for 15 days with no activity."
|
||||||
|
|||||||
5463
src/Misc/expressionFunc/hashFiles/package-lock.json
generated
5463
src/Misc/expressionFunc/hashFiles/package-lock.json
generated
File diff suppressed because it is too large
Load Diff
@@ -38,10 +38,10 @@
|
|||||||
"@stylistic/eslint-plugin": "^5.10.0",
|
"@stylistic/eslint-plugin": "^5.10.0",
|
||||||
"@types/node": "^22.0.0",
|
"@types/node": "^22.0.0",
|
||||||
"@typescript-eslint/eslint-plugin": "^8.59.0",
|
"@typescript-eslint/eslint-plugin": "^8.59.0",
|
||||||
"@typescript-eslint/parser": "^8.59.0",
|
"@typescript-eslint/parser": "^8.65.0",
|
||||||
"@vercel/ncc": "^0.38.3",
|
"@vercel/ncc": "^0.38.3",
|
||||||
"eslint": "^8.47.0",
|
"eslint": "^8.47.0",
|
||||||
"eslint-plugin-github": "^4.10.2",
|
"eslint-plugin-github": "^6.1.0",
|
||||||
"eslint-plugin-prettier": "^5.0.0",
|
"eslint-plugin-prettier": "^5.0.0",
|
||||||
"husky": "^9.1.7",
|
"husky": "^9.1.7",
|
||||||
"lint-staged": "^16.4.0",
|
"lint-staged": "^16.4.0",
|
||||||
|
|||||||
@@ -15,7 +15,7 @@
|
|||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
|
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
<PackageReference Include="System.Text.Encoding.CodePages" Version="10.0.3" />
|
<PackageReference Include="System.Text.Encoding.CodePages" Version="10.0.10" />
|
||||||
<PackageReference Include="Microsoft.Win32.Registry" Version="5.0.0" />
|
<PackageReference Include="Microsoft.Win32.Registry" Version="5.0.0" />
|
||||||
<PackageReference Include="System.Threading.Channels" Version="10.0.3" />
|
<PackageReference Include="System.Threading.Channels" Version="10.0.3" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
|
|||||||
@@ -1026,7 +1026,9 @@ namespace GitHub.Runner.Worker.Dap
|
|||||||
{
|
{
|
||||||
if (!string.IsNullOrEmpty(debuggerConfig.WelcomeMessage))
|
if (!string.IsNullOrEmpty(debuggerConfig.WelcomeMessage))
|
||||||
{
|
{
|
||||||
SendOutput("console", debuggerConfig.WelcomeMessage);
|
// The welcome message is server-supplied and never rendered verbatim:
|
||||||
|
// mask secrets and strip control characters before it reaches the console.
|
||||||
|
SendOutput("console", SanitizeConsoleText(MaskUserVisibleText(debuggerConfig.WelcomeMessage)));
|
||||||
Trace.Info("Sent custom welcome message");
|
Trace.Info("Sent custom welcome message");
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
@@ -1772,6 +1774,30 @@ namespace GitHub.Runner.Worker.Dap
|
|||||||
return HostContext?.SecretMasker?.MaskSecrets(value) ?? value;
|
return HostContext?.SecretMasker?.MaskSecrets(value) ?? value;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// Removes C0/C1 control characters (except tab, carriage return and line feed) so
|
||||||
|
/// server-supplied text cannot inject ANSI escape sequences or terminal control codes
|
||||||
|
/// into the DAP console.
|
||||||
|
/// </summary>
|
||||||
|
internal static string SanitizeConsoleText(string value)
|
||||||
|
{
|
||||||
|
if (string.IsNullOrEmpty(value))
|
||||||
|
{
|
||||||
|
return value ?? string.Empty;
|
||||||
|
}
|
||||||
|
|
||||||
|
var builder = new StringBuilder(value.Length);
|
||||||
|
foreach (var character in value)
|
||||||
|
{
|
||||||
|
if (!char.IsControl(character) || character == '\t' || character == '\r' || character == '\n')
|
||||||
|
{
|
||||||
|
builder.Append(character);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return builder.ToString();
|
||||||
|
}
|
||||||
|
|
||||||
/// <summary>
|
/// <summary>
|
||||||
/// Creates a DAP response with common fields pre-populated.
|
/// Creates a DAP response with common fields pre-populated.
|
||||||
/// </summary>
|
/// </summary>
|
||||||
|
|||||||
@@ -36,6 +36,11 @@ namespace GitHub.Runner.Worker.Dap
|
|||||||
/// Optional welcome message content for the debugger console. Only used when
|
/// Optional welcome message content for the debugger console. Only used when
|
||||||
/// <see cref="OverrideWelcomeMessage"/> is true.
|
/// <see cref="OverrideWelcomeMessage"/> is true.
|
||||||
/// </summary>
|
/// </summary>
|
||||||
|
/// <remarks>
|
||||||
|
/// Server-supplied and treated as untrusted: it is masked with the runner's
|
||||||
|
/// secret masker and stripped of control characters before being written to
|
||||||
|
/// the debugger console.
|
||||||
|
/// </remarks>
|
||||||
public string WelcomeMessage { get; }
|
public string WelcomeMessage { get; }
|
||||||
|
|
||||||
/// <summary>Whether the tunnel configuration is complete and valid.</summary>
|
/// <summary>Whether the tunnel configuration is complete and valid.</summary>
|
||||||
|
|||||||
@@ -23,7 +23,7 @@
|
|||||||
<PackageReference Include="System.ServiceProcess.ServiceController" Version="10.0.3" />
|
<PackageReference Include="System.ServiceProcess.ServiceController" Version="10.0.3" />
|
||||||
<PackageReference Include="System.Threading.Channels" Version="10.0.3" />
|
<PackageReference Include="System.Threading.Channels" Version="10.0.3" />
|
||||||
<PackageReference Include="YamlDotNet.Signed" Version="5.3.0" />
|
<PackageReference Include="YamlDotNet.Signed" Version="5.3.0" />
|
||||||
<PackageReference Include="Microsoft.DevTunnels.Connections" Version="1.3.48" />
|
<PackageReference Include="Microsoft.DevTunnels.Connections" Version="1.3.50" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
|
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
|
|||||||
@@ -271,7 +271,7 @@ namespace GitHub.DistributedTask.Pipelines
|
|||||||
/// Optional welcome message shown in the debugger console when a client connects.
|
/// Optional welcome message shown in the debugger console when a client connects.
|
||||||
/// Only used when the <c>actions_runner_override_debugger_welcome_message</c>
|
/// Only used when the <c>actions_runner_override_debugger_welcome_message</c>
|
||||||
/// feature flag is set to <c>true</c> in the job variables. With the flag set,
|
/// feature flag is set to <c>true</c> in the job variables. With the flag set,
|
||||||
/// a non-empty value is shown as-is and a null or empty value suppresses the
|
/// a non-empty value is shown and a null or empty value suppresses the
|
||||||
/// default welcome message. When the flag is not set, the runner shows its
|
/// default welcome message. When the flag is not set, the runner shows its
|
||||||
/// built-in help text and this field is ignored.
|
/// built-in help text and this field is ignored.
|
||||||
/// </summary>
|
/// </summary>
|
||||||
|
|||||||
@@ -18,19 +18,19 @@
|
|||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
|
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
<PackageReference Include="Azure.Storage.Blobs" Version="12.27.0" />
|
<PackageReference Include="Azure.Storage.Blobs" Version="12.29.1" />
|
||||||
<PackageReference Include="Microsoft.Win32.Registry" Version="5.0.0" />
|
<PackageReference Include="Microsoft.Win32.Registry" Version="5.0.0" />
|
||||||
<PackageReference Include="Newtonsoft.Json" Version="13.0.3" />
|
<PackageReference Include="Newtonsoft.Json" Version="13.0.3" />
|
||||||
<PackageReference Include="Microsoft.AspNet.WebApi.Client" Version="6.0.0" />
|
<PackageReference Include="Microsoft.AspNet.WebApi.Client" Version="6.0.0" />
|
||||||
<PackageReference Include="System.Security.Cryptography.Cng" Version="5.0.0" />
|
<PackageReference Include="System.Security.Cryptography.Cng" Version="5.0.0" />
|
||||||
<PackageReference Include="System.Security.Cryptography.Pkcs" Version="10.0.7" />
|
<PackageReference Include="System.Security.Cryptography.Pkcs" Version="10.0.10" />
|
||||||
<PackageReference Include="System.Security.Cryptography.ProtectedData" Version="10.0.3" />
|
<PackageReference Include="System.Security.Cryptography.ProtectedData" Version="10.0.3" />
|
||||||
<PackageReference Include="Minimatch" Version="2.0.0" />
|
<PackageReference Include="Minimatch" Version="2.0.0" />
|
||||||
<PackageReference Include="YamlDotNet.Signed" Version="5.3.0" />
|
<PackageReference Include="YamlDotNet.Signed" Version="5.3.0" />
|
||||||
<PackageReference Include="System.Net.Http" Version="4.3.4" />
|
<PackageReference Include="System.Net.Http" Version="4.3.4" />
|
||||||
<PackageReference Include="System.Text.RegularExpressions" Version="4.3.1" />
|
<PackageReference Include="System.Text.RegularExpressions" Version="4.3.1" />
|
||||||
<PackageReference Include="System.Private.Uri" Version="4.3.2" />
|
<PackageReference Include="System.Private.Uri" Version="4.3.2" />
|
||||||
<PackageReference Include="System.Formats.Asn1" Version="10.0.7" />
|
<PackageReference Include="System.Formats.Asn1" Version="10.0.10" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
|
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
|
|||||||
@@ -1422,6 +1422,96 @@ namespace GitHub.Runner.Common.Tests.Worker
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
[Trait("Level", "L0")]
|
||||||
|
[Trait("Category", "Worker")]
|
||||||
|
public async Task WelcomeMessageMasksSecrets()
|
||||||
|
{
|
||||||
|
using (var hc = CreateTestContext())
|
||||||
|
{
|
||||||
|
hc.SecretMasker.AddValue("super-secret-token");
|
||||||
|
|
||||||
|
var port = GetFreePort();
|
||||||
|
using var cts = new CancellationTokenSource(TimeSpan.FromSeconds(10));
|
||||||
|
var jobContext = CreateJobContextWithTunnel(cts.Token, port,
|
||||||
|
overrideWelcomeMessage: true,
|
||||||
|
welcomeMessage: "Welcome! Token: super-secret-token");
|
||||||
|
await _debugger.StartAsync(jobContext.Object);
|
||||||
|
|
||||||
|
using var client = await ConnectClientAsync(port);
|
||||||
|
var stream = client.GetStream();
|
||||||
|
|
||||||
|
await SendRequestAsync(stream, new Request
|
||||||
|
{
|
||||||
|
Seq = 1,
|
||||||
|
Type = "request",
|
||||||
|
Command = "configurationDone"
|
||||||
|
});
|
||||||
|
|
||||||
|
var configDoneResponse = await ReadDapMessageAsync(stream, TimeSpan.FromSeconds(5));
|
||||||
|
Assert.Contains("\"command\":\"configurationDone\"", configDoneResponse);
|
||||||
|
|
||||||
|
var welcomeMsg = await ReadDapMessageAsync(stream, TimeSpan.FromSeconds(5));
|
||||||
|
Assert.Contains("\"event\":\"output\"", welcomeMsg);
|
||||||
|
Assert.DoesNotContain("super-secret-token", welcomeMsg);
|
||||||
|
Assert.Contains("***", welcomeMsg);
|
||||||
|
|
||||||
|
await _debugger.StopAsync();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
[Trait("Level", "L0")]
|
||||||
|
[Trait("Category", "Worker")]
|
||||||
|
public async Task WelcomeMessageStripsControlCharacters()
|
||||||
|
{
|
||||||
|
using (CreateTestContext())
|
||||||
|
{
|
||||||
|
var port = GetFreePort();
|
||||||
|
using var cts = new CancellationTokenSource(TimeSpan.FromSeconds(10));
|
||||||
|
var jobContext = CreateJobContextWithTunnel(cts.Token, port,
|
||||||
|
overrideWelcomeMessage: true,
|
||||||
|
welcomeMessage: "Wel\u001b[31mcome\u0007\u0000\u009bhere\nnext\tline");
|
||||||
|
await _debugger.StartAsync(jobContext.Object);
|
||||||
|
|
||||||
|
using var client = await ConnectClientAsync(port);
|
||||||
|
var stream = client.GetStream();
|
||||||
|
|
||||||
|
await SendRequestAsync(stream, new Request
|
||||||
|
{
|
||||||
|
Seq = 1,
|
||||||
|
Type = "request",
|
||||||
|
Command = "configurationDone"
|
||||||
|
});
|
||||||
|
|
||||||
|
var configDoneResponse = await ReadDapMessageAsync(stream, TimeSpan.FromSeconds(5));
|
||||||
|
Assert.Contains("\"command\":\"configurationDone\"", configDoneResponse);
|
||||||
|
|
||||||
|
var welcomeMsg = await ReadDapMessageAsync(stream, TimeSpan.FromSeconds(5));
|
||||||
|
Assert.Contains("\"event\":\"output\"", welcomeMsg);
|
||||||
|
|
||||||
|
var output = JObject.Parse(welcomeMsg)["body"]["output"].ToString();
|
||||||
|
Assert.Equal("Wel[31mcomehere\nnext\tline", output);
|
||||||
|
|
||||||
|
await _debugger.StopAsync();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
[Theory]
|
||||||
|
[Trait("Level", "L0")]
|
||||||
|
[Trait("Category", "Worker")]
|
||||||
|
[InlineData(null, "")]
|
||||||
|
[InlineData("", "")]
|
||||||
|
[InlineData("plain text", "plain text")]
|
||||||
|
[InlineData("keep\r\nnewlines\tand tabs", "keep\r\nnewlines\tand tabs")]
|
||||||
|
[InlineData("esc\u001bape", "escape")]
|
||||||
|
[InlineData("bell\u0007null\u0000del\u007f", "bellnulldel")]
|
||||||
|
[InlineData("c1\u0080\u009fchars", "c1chars")]
|
||||||
|
public void SanitizeConsoleTextRemovesControlCharacters(string input, string expected)
|
||||||
|
{
|
||||||
|
Assert.Equal(expected, DapDebugger.SanitizeConsoleText(input));
|
||||||
|
}
|
||||||
|
|
||||||
[Fact]
|
[Fact]
|
||||||
[Trait("Level", "L0")]
|
[Trait("Level", "L0")]
|
||||||
[Trait("Category", "Worker")]
|
[Trait("Category", "Worker")]
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ LAYOUT_DIR="$SCRIPT_DIR/../_layout"
|
|||||||
DOWNLOAD_DIR="$SCRIPT_DIR/../_downloads/netcore2x"
|
DOWNLOAD_DIR="$SCRIPT_DIR/../_downloads/netcore2x"
|
||||||
PACKAGE_DIR="$SCRIPT_DIR/../_package"
|
PACKAGE_DIR="$SCRIPT_DIR/../_package"
|
||||||
DOTNETSDK_ROOT="$SCRIPT_DIR/../_dotnetsdk"
|
DOTNETSDK_ROOT="$SCRIPT_DIR/../_dotnetsdk"
|
||||||
DOTNETSDK_VERSION="8.0.422"
|
DOTNETSDK_VERSION="8.0.423"
|
||||||
DOTNETSDK_INSTALLDIR="$DOTNETSDK_ROOT/$DOTNETSDK_VERSION"
|
DOTNETSDK_INSTALLDIR="$DOTNETSDK_ROOT/$DOTNETSDK_VERSION"
|
||||||
RUNNER_VERSION=$(cat runnerversion)
|
RUNNER_VERSION=$(cat runnerversion)
|
||||||
|
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
{
|
{
|
||||||
"sdk": {
|
"sdk": {
|
||||||
"version": "8.0.422"
|
"version": "8.0.423"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user