mirror of
https://github.com/aws-actions/configure-aws-credentials.git
synced 2026-08-30 05:25:06 +09:00
Compare commits
77 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 2748f18272 | |||
| e977f476bf | |||
| ab0d61f6a0 | |||
| ccf493e3b1 | |||
| 05ed620dc8 | |||
| 62f98f6930 | |||
| 5a780d06ff | |||
| d3cb30b08b | |||
| eb48debd38 | |||
| e69af16b6c | |||
| 7fb20f0656 | |||
| 4e7ae70130 | |||
| 9ae780b171 | |||
| 517a711dbc | |||
| d01d678e65 | |||
| 8efa52b284 | |||
| 8e1eed5c14 | |||
| 112421a93a | |||
| fbc01c6585 | |||
| b12ca875eb | |||
| d314f7f43d | |||
| a53b65b84a | |||
| 338d2c1839 | |||
| b94086889d | |||
| 9df7c63a2f | |||
| c35a5960bf | |||
| 187c14ee87 | |||
| c403f3cb69 | |||
| 08319dee24 | |||
| d2e2926774 | |||
| 90f23cf274 | |||
| 26d9fee367 | |||
| 6686d5a051 | |||
| 254c19bd24 | |||
| a20cf827fe | |||
| 4d281fbc56 | |||
| e004cdcd28 | |||
| 88aa3695d3 | |||
| 687331b272 | |||
| ea607be060 | |||
| 6d136066d8 | |||
| 71a32ae408 | |||
| b290f2ca79 | |||
| 0cd4b34a9b | |||
| e6e5af76de | |||
| 7089b3a41f | |||
| 1a6323c7ef | |||
| 8136aa1bcb | |||
| ffffc0fe9d | |||
| 93823cfbdc | |||
| 7397aaead8 | |||
| fc8f6a6abe | |||
| 3c7bb1cb09 | |||
| 024bb07a82 | |||
| 86c1acf81a | |||
| 50c2567845 | |||
| 270cb5b1d9 | |||
| 51e8115730 | |||
| 7f56bcdc8b | |||
| 357812ba85 | |||
| 6a57fcec9b | |||
| 11b91e35b6 | |||
| eeef317384 | |||
| 586cfded7b | |||
| ff89a791a6 | |||
| c2036624d0 | |||
| 68fa256f0b | |||
| 97363c92bb | |||
| 05c3e92d7e | |||
| 037dd16322 | |||
| 89a34d9b83 | |||
| d63f12fba5 | |||
| aefb6ea018 | |||
| bf27562715 | |||
| 4f3ef32554 | |||
| 26b365ff2f | |||
| 262ce4cfb5 |
@@ -48,12 +48,15 @@
|
|||||||
uses: actions/checkout@v5
|
uses: actions/checkout@v5
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
|
persist-credentials: false
|
||||||
|
|
||||||
- name: Tag Major Version
|
- name: Tag Major Version
|
||||||
if: ${{ steps.release.outputs.release_created }}
|
if: ${{ steps.release.outputs.release_created }}
|
||||||
run: |
|
run: |
|
||||||
git config user.name "GitHub Actions"
|
git config user.name "GitHub Actions"
|
||||||
git config user.email "github-aws-sdk-osds-automation@amazon.com"
|
git config user.email "github-aws-sdk-osds-automation@amazon.com"
|
||||||
|
echo "::add-mask::${{ env.OSDS_ACCESS_TOKEN }}"
|
||||||
|
git remote set-url origin https://${{ env.OSDS_ACCESS_TOKEN }}@github.com/aws-actions/configure-aws-credentials.git
|
||||||
if git rev-parse "v${{ steps.release.outputs.major }}" >/dev/null 2>&1; then
|
if git rev-parse "v${{ steps.release.outputs.major }}" >/dev/null 2>&1; then
|
||||||
git tag -d "v${{ steps.release.outputs.major }}"
|
git tag -d "v${{ steps.release.outputs.major }}"
|
||||||
git push origin ":v${{ steps.release.outputs.major }}"
|
git push origin ":v${{ steps.release.outputs.major }}"
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
{
|
{
|
||||||
".release-please-manifest.json": "4.0.2",
|
".release-please-manifest.json": "4.0.2",
|
||||||
"package.json": "6.0.0",
|
"package.json": "6.0.0",
|
||||||
".": "6.2.0"
|
".": "6.2.2"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,6 +2,20 @@
|
|||||||
|
|
||||||
All notable changes to this project will be documented in this file. See [standard-version](https://github.com/conventional-changelog/standard-version) for commit guidelines.
|
All notable changes to this project will be documented in this file. See [standard-version](https://github.com/conventional-changelog/standard-version) for commit guidelines.
|
||||||
|
|
||||||
|
## [6.2.2](https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.1...v6.2.2) (2026-07-07)
|
||||||
|
|
||||||
|
|
||||||
|
### Miscellaneous Chores
|
||||||
|
|
||||||
|
* release 6.2.2 ([d01d678](https://github.com/aws-actions/configure-aws-credentials/commit/d01d678e65d6d2bd9d5ca7a95d6f07b00e25f2c2))
|
||||||
|
|
||||||
|
## [6.2.1](https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.0...v6.2.1) (2026-06-26)
|
||||||
|
|
||||||
|
|
||||||
|
### Bug Fixes
|
||||||
|
|
||||||
|
* enforce allowed-account-ids on all auth paths ([#1847](https://github.com/aws-actions/configure-aws-credentials/issues/1847)) ([4d281fb](https://github.com/aws-actions/configure-aws-credentials/commit/4d281fbc56a82e63c3fc14f2cc22361f34c97493))
|
||||||
|
|
||||||
## [6.2.0](https://github.com/aws-actions/configure-aws-credentials/compare/v6.1.3...v6.2.0) (2026-06-01)
|
## [6.2.0](https://github.com/aws-actions/configure-aws-credentials/compare/v6.1.3...v6.2.0) (2026-06-01)
|
||||||
|
|
||||||
### Features
|
### Features
|
||||||
|
|||||||
@@ -26,7 +26,7 @@ Authenticate to AWS in GitHub Actions (and others)! Works especially well with
|
|||||||
"Condition": {
|
"Condition": {
|
||||||
"StringEquals": {
|
"StringEquals": {
|
||||||
"token.actions.githubusercontent.com:aud": "sts.amazonaws.com",
|
"token.actions.githubusercontent.com:aud": "sts.amazonaws.com",
|
||||||
"token.actions.githubusercontent.com:sub": "repo:<GITHUB_ORG>/<GITHUB_REPOSITORY>:ref:refs/heads/<GITHUB_BRANCH>"
|
"token.actions.githubusercontent.com:sub": "repo:<GITHUB_ORG>@<ORG_ID>/<GITHUB_REPOSITORY>@<REPO_ID>:ref:refs/heads/<GITHUB_BRANCH>"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -36,11 +36,16 @@ Authenticate to AWS in GitHub Actions (and others)! Works especially well with
|
|||||||
|
|
||||||
</details>
|
</details>
|
||||||
|
|
||||||
Note: if you are running in a GitHub environment based workflow, the value
|
Note: The value of the `sub` claim may be different depending on the workflow
|
||||||
for the Sub claim will be different, in the form of
|
and the environment in which it's running. Workflows in repositories created
|
||||||
`repo:<GITHUB_ORG>/<GITHUB_REPOSITORY>:environment:<ENVIRONMENT_NAME>`.
|
prior to [15 July 2026][immutable-sub] will omit the `@<ORG_ID>` and
|
||||||
Adjust the trust policy accordingly if you are using environment-based
|
`@<REPO_ID>` suffixes unless opted in. Workflows running in GitHub
|
||||||
workflows.
|
environments will include an`environment:<ENVIRONMENT_NAME>` stanza. See
|
||||||
|
[Claims and scoping permissions](#claims-and-scoping-permissions) for more
|
||||||
|
information.
|
||||||
|
|
||||||
|
[immutable-sub]:
|
||||||
|
https://github.blog/changelog/2026-04-23-immutable-subject-claims-for-github-actions-oidc-tokens/
|
||||||
|
|
||||||
3. Attach permissions to the IAM Role that allow it to access the AWS resources
|
3. Attach permissions to the IAM Role that allow it to access the AWS resources
|
||||||
you need.
|
you need.
|
||||||
@@ -593,6 +598,29 @@ claims ([1][gh-blog-oidc], [2][sub-claim-custom]).
|
|||||||
> unintended access. Instead, use `StringEquals` or `StringLike` operators to
|
> unintended access. Instead, use `StringEquals` or `StringLike` operators to
|
||||||
> check for specific claim values.
|
> check for specific claim values.
|
||||||
|
|
||||||
|
#### Immutable subject claims
|
||||||
|
|
||||||
|
Repositories created on github.com on or after 15 July 2026, and older
|
||||||
|
repositories that have opted in, emit an [immutable `sub` claim][immutable-sub].
|
||||||
|
This claim appends the permanent numeric ID of the organization and of the
|
||||||
|
repository after each name, separated by `@`, so that a recycled org or
|
||||||
|
repository name cannot be used to mint tokens matching a stale trust policy.
|
||||||
|
For example:
|
||||||
|
|
||||||
|
```text
|
||||||
|
# Legacy (mutable) sub claim
|
||||||
|
repo:octo-org/octo-repo:ref:refs/heads/main
|
||||||
|
|
||||||
|
# Immutable sub claim
|
||||||
|
repo:octo-org@123456/octo-repo@789012:ref:refs/heads/main
|
||||||
|
```
|
||||||
|
|
||||||
|
If your trust policy matches the legacy name-only form and your repository emits
|
||||||
|
the immutable claim, `AssumeRoleWithWebIdentity` fails with `Not authorized to
|
||||||
|
perform sts:AssumeRoleWithWebIdentity`. To fix this, update the `sub` condition
|
||||||
|
to the immutable form. You can find your repository's prefix in the Settings,
|
||||||
|
or by following the token inspection steps below.
|
||||||
|
|
||||||
[least-privilege]:
|
[least-privilege]:
|
||||||
https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#grant-least-privilege
|
https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#grant-least-privilege
|
||||||
[gh-blog-oidc]:
|
[gh-blog-oidc]:
|
||||||
@@ -605,7 +633,7 @@ claims ([1][gh-blog-oidc], [2][sub-claim-custom]).
|
|||||||
If you aren't sure what claim values your workflow is producing, the
|
If you aren't sure what claim values your workflow is producing, the
|
||||||
[`actions-oidc-debugger`](https://github.com/github/actions-oidc-debugger)
|
[`actions-oidc-debugger`](https://github.com/github/actions-oidc-debugger)
|
||||||
action will print the decoded JWT payload. Run it in a private repository
|
action will print the decoded JWT payload. Run it in a private repository
|
||||||
only — the token itself is short-lived but the claim values may be sensitive.
|
only; the token itself is short-lived but the claim values may be sensitive.
|
||||||
|
|
||||||
See the GitHub [security-hardening guide][gh-oidc-hardening] for further
|
See the GitHub [security-hardening guide][gh-oidc-hardening] for further
|
||||||
discussion of trust conditions and threat modeling.
|
discussion of trust conditions and threat modeling.
|
||||||
@@ -776,7 +804,10 @@ the environment (for example, on a self-hosted runner where you do not want the
|
|||||||
assumed-role credentials to shadow an existing EC2 instance profile), pair
|
assumed-role credentials to shadow an existing EC2 instance profile), pair
|
||||||
`output-credentials: true` with `output-env-credentials: false`. In that mode,
|
`output-credentials: true` with `output-env-credentials: false`. In that mode,
|
||||||
the action does not run its post-credential SDK-pickup validation step, since
|
the action does not run its post-credential SDK-pickup validation step, since
|
||||||
the credentials were never written to the environment.
|
the credentials were never written to the environment. The action still
|
||||||
|
validates the resolved credentials by calling `sts:GetCallerIdentity` with the
|
||||||
|
explicit credentials, so the `allowed-account-ids` check can be enforced if
|
||||||
|
provided.
|
||||||
|
|
||||||
### Configure multiple AWS profiles in a single workflow
|
### Configure multiple AWS profiles in a single workflow
|
||||||
|
|
||||||
|
|||||||
+30
-787
@@ -3,7 +3,7 @@ https://www.npmjs.com/package/generate-license-file
|
|||||||
|
|
||||||
The following npm package may be included in this product:
|
The following npm package may be included in this product:
|
||||||
|
|
||||||
- @aws/lambda-invoke-store@0.2.4
|
- @aws/lambda-invoke-store@0.3.0
|
||||||
|
|
||||||
This package contains the following license:
|
This package contains the following license:
|
||||||
|
|
||||||
@@ -184,217 +184,6 @@ Apache License
|
|||||||
|
|
||||||
-----------
|
-----------
|
||||||
|
|
||||||
The following npm packages may be included in this product:
|
|
||||||
|
|
||||||
- @aws-crypto/sha256-browser@5.2.0
|
|
||||||
- @aws-crypto/supports-web-crypto@5.2.0
|
|
||||||
|
|
||||||
These packages each contain the following license:
|
|
||||||
|
|
||||||
Apache License
|
|
||||||
Version 2.0, January 2004
|
|
||||||
http://www.apache.org/licenses/
|
|
||||||
|
|
||||||
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
|
|
||||||
|
|
||||||
1. Definitions.
|
|
||||||
|
|
||||||
"License" shall mean the terms and conditions for use, reproduction,
|
|
||||||
and distribution as defined by Sections 1 through 9 of this document.
|
|
||||||
|
|
||||||
"Licensor" shall mean the copyright owner or entity authorized by
|
|
||||||
the copyright owner that is granting the License.
|
|
||||||
|
|
||||||
"Legal Entity" shall mean the union of the acting entity and all
|
|
||||||
other entities that control, are controlled by, or are under common
|
|
||||||
control with that entity. For the purposes of this definition,
|
|
||||||
"control" means (i) the power, direct or indirect, to cause the
|
|
||||||
direction or management of such entity, whether by contract or
|
|
||||||
otherwise, or (ii) ownership of fifty percent (50%) or more of the
|
|
||||||
outstanding shares, or (iii) beneficial ownership of such entity.
|
|
||||||
|
|
||||||
"You" (or "Your") shall mean an individual or Legal Entity
|
|
||||||
exercising permissions granted by this License.
|
|
||||||
|
|
||||||
"Source" form shall mean the preferred form for making modifications,
|
|
||||||
including but not limited to software source code, documentation
|
|
||||||
source, and configuration files.
|
|
||||||
|
|
||||||
"Object" form shall mean any form resulting from mechanical
|
|
||||||
transformation or translation of a Source form, including but
|
|
||||||
not limited to compiled object code, generated documentation,
|
|
||||||
and conversions to other media types.
|
|
||||||
|
|
||||||
"Work" shall mean the work of authorship, whether in Source or
|
|
||||||
Object form, made available under the License, as indicated by a
|
|
||||||
copyright notice that is included in or attached to the work
|
|
||||||
(an example is provided in the Appendix below).
|
|
||||||
|
|
||||||
"Derivative Works" shall mean any work, whether in Source or Object
|
|
||||||
form, that is based on (or derived from) the Work and for which the
|
|
||||||
editorial revisions, annotations, elaborations, or other modifications
|
|
||||||
represent, as a whole, an original work of authorship. For the purposes
|
|
||||||
of this License, Derivative Works shall not include works that remain
|
|
||||||
separable from, or merely link (or bind by name) to the interfaces of,
|
|
||||||
the Work and Derivative Works thereof.
|
|
||||||
|
|
||||||
"Contribution" shall mean any work of authorship, including
|
|
||||||
the original version of the Work and any modifications or additions
|
|
||||||
to that Work or Derivative Works thereof, that is intentionally
|
|
||||||
submitted to Licensor for inclusion in the Work by the copyright owner
|
|
||||||
or by an individual or Legal Entity authorized to submit on behalf of
|
|
||||||
the copyright owner. For the purposes of this definition, "submitted"
|
|
||||||
means any form of electronic, verbal, or written communication sent
|
|
||||||
to the Licensor or its representatives, including but not limited to
|
|
||||||
communication on electronic mailing lists, source code control systems,
|
|
||||||
and issue tracking systems that are managed by, or on behalf of, the
|
|
||||||
Licensor for the purpose of discussing and improving the Work, but
|
|
||||||
excluding communication that is conspicuously marked or otherwise
|
|
||||||
designated in writing by the copyright owner as "Not a Contribution."
|
|
||||||
|
|
||||||
"Contributor" shall mean Licensor and any individual or Legal Entity
|
|
||||||
on behalf of whom a Contribution has been received by Licensor and
|
|
||||||
subsequently incorporated within the Work.
|
|
||||||
|
|
||||||
2. Grant of Copyright License. Subject to the terms and conditions of
|
|
||||||
this License, each Contributor hereby grants to You a perpetual,
|
|
||||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
|
||||||
copyright license to reproduce, prepare Derivative Works of,
|
|
||||||
publicly display, publicly perform, sublicense, and distribute the
|
|
||||||
Work and such Derivative Works in Source or Object form.
|
|
||||||
|
|
||||||
3. Grant of Patent License. Subject to the terms and conditions of
|
|
||||||
this License, each Contributor hereby grants to You a perpetual,
|
|
||||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
|
||||||
(except as stated in this section) patent license to make, have made,
|
|
||||||
use, offer to sell, sell, import, and otherwise transfer the Work,
|
|
||||||
where such license applies only to those patent claims licensable
|
|
||||||
by such Contributor that are necessarily infringed by their
|
|
||||||
Contribution(s) alone or by combination of their Contribution(s)
|
|
||||||
with the Work to which such Contribution(s) was submitted. If You
|
|
||||||
institute patent litigation against any entity (including a
|
|
||||||
cross-claim or counterclaim in a lawsuit) alleging that the Work
|
|
||||||
or a Contribution incorporated within the Work constitutes direct
|
|
||||||
or contributory patent infringement, then any patent licenses
|
|
||||||
granted to You under this License for that Work shall terminate
|
|
||||||
as of the date such litigation is filed.
|
|
||||||
|
|
||||||
4. Redistribution. You may reproduce and distribute copies of the
|
|
||||||
Work or Derivative Works thereof in any medium, with or without
|
|
||||||
modifications, and in Source or Object form, provided that You
|
|
||||||
meet the following conditions:
|
|
||||||
|
|
||||||
(a) You must give any other recipients of the Work or
|
|
||||||
Derivative Works a copy of this License; and
|
|
||||||
|
|
||||||
(b) You must cause any modified files to carry prominent notices
|
|
||||||
stating that You changed the files; and
|
|
||||||
|
|
||||||
(c) You must retain, in the Source form of any Derivative Works
|
|
||||||
that You distribute, all copyright, patent, trademark, and
|
|
||||||
attribution notices from the Source form of the Work,
|
|
||||||
excluding those notices that do not pertain to any part of
|
|
||||||
the Derivative Works; and
|
|
||||||
|
|
||||||
(d) If the Work includes a "NOTICE" text file as part of its
|
|
||||||
distribution, then any Derivative Works that You distribute must
|
|
||||||
include a readable copy of the attribution notices contained
|
|
||||||
within such NOTICE file, excluding those notices that do not
|
|
||||||
pertain to any part of the Derivative Works, in at least one
|
|
||||||
of the following places: within a NOTICE text file distributed
|
|
||||||
as part of the Derivative Works; within the Source form or
|
|
||||||
documentation, if provided along with the Derivative Works; or,
|
|
||||||
within a display generated by the Derivative Works, if and
|
|
||||||
wherever such third-party notices normally appear. The contents
|
|
||||||
of the NOTICE file are for informational purposes only and
|
|
||||||
do not modify the License. You may add Your own attribution
|
|
||||||
notices within Derivative Works that You distribute, alongside
|
|
||||||
or as an addendum to the NOTICE text from the Work, provided
|
|
||||||
that such additional attribution notices cannot be construed
|
|
||||||
as modifying the License.
|
|
||||||
|
|
||||||
You may add Your own copyright statement to Your modifications and
|
|
||||||
may provide additional or different license terms and conditions
|
|
||||||
for use, reproduction, or distribution of Your modifications, or
|
|
||||||
for any such Derivative Works as a whole, provided Your use,
|
|
||||||
reproduction, and distribution of the Work otherwise complies with
|
|
||||||
the conditions stated in this License.
|
|
||||||
|
|
||||||
5. Submission of Contributions. Unless You explicitly state otherwise,
|
|
||||||
any Contribution intentionally submitted for inclusion in the Work
|
|
||||||
by You to the Licensor shall be under the terms and conditions of
|
|
||||||
this License, without any additional terms or conditions.
|
|
||||||
Notwithstanding the above, nothing herein shall supersede or modify
|
|
||||||
the terms of any separate license agreement you may have executed
|
|
||||||
with Licensor regarding such Contributions.
|
|
||||||
|
|
||||||
6. Trademarks. This License does not grant permission to use the trade
|
|
||||||
names, trademarks, service marks, or product names of the Licensor,
|
|
||||||
except as required for reasonable and customary use in describing the
|
|
||||||
origin of the Work and reproducing the content of the NOTICE file.
|
|
||||||
|
|
||||||
7. Disclaimer of Warranty. Unless required by applicable law or
|
|
||||||
agreed to in writing, Licensor provides the Work (and each
|
|
||||||
Contributor provides its Contributions) on an "AS IS" BASIS,
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
|
||||||
implied, including, without limitation, any warranties or conditions
|
|
||||||
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
|
|
||||||
PARTICULAR PURPOSE. You are solely responsible for determining the
|
|
||||||
appropriateness of using or redistributing the Work and assume any
|
|
||||||
risks associated with Your exercise of permissions under this License.
|
|
||||||
|
|
||||||
8. Limitation of Liability. In no event and under no legal theory,
|
|
||||||
whether in tort (including negligence), contract, or otherwise,
|
|
||||||
unless required by applicable law (such as deliberate and grossly
|
|
||||||
negligent acts) or agreed to in writing, shall any Contributor be
|
|
||||||
liable to You for damages, including any direct, indirect, special,
|
|
||||||
incidental, or consequential damages of any character arising as a
|
|
||||||
result of this License or out of the use or inability to use the
|
|
||||||
Work (including but not limited to damages for loss of goodwill,
|
|
||||||
work stoppage, computer failure or malfunction, or any and all
|
|
||||||
other commercial damages or losses), even if such Contributor
|
|
||||||
has been advised of the possibility of such damages.
|
|
||||||
|
|
||||||
9. Accepting Warranty or Additional Liability. While redistributing
|
|
||||||
the Work or Derivative Works thereof, You may choose to offer,
|
|
||||||
and charge a fee for, acceptance of support, warranty, indemnity,
|
|
||||||
or other liability obligations and/or rights consistent with this
|
|
||||||
License. However, in accepting such obligations, You may act only
|
|
||||||
on Your own behalf and on Your sole responsibility, not on behalf
|
|
||||||
of any other Contributor, and only if You agree to indemnify,
|
|
||||||
defend, and hold each Contributor harmless for any liability
|
|
||||||
incurred by, or claims asserted against, such Contributor by reason
|
|
||||||
of your accepting any such warranty or additional liability.
|
|
||||||
|
|
||||||
END OF TERMS AND CONDITIONS
|
|
||||||
|
|
||||||
APPENDIX: How to apply the Apache License to your work.
|
|
||||||
|
|
||||||
To apply the Apache License to your work, attach the following
|
|
||||||
boilerplate notice, with the fields enclosed by brackets "[]"
|
|
||||||
replaced with your own identifying information. (Don't include
|
|
||||||
the brackets!) The text should be enclosed in the appropriate
|
|
||||||
comment syntax for the file format. We also recommend that a
|
|
||||||
file or class name and description of purpose be included on the
|
|
||||||
same "printed page" as the copyright notice for easier
|
|
||||||
identification within third-party archives.
|
|
||||||
|
|
||||||
Copyright [yyyy] [name of copyright owner]
|
|
||||||
|
|
||||||
Licensed under the Apache License, Version 2.0 (the "License");
|
|
||||||
you may not use this file except in compliance with the License.
|
|
||||||
You may obtain a copy of the License at
|
|
||||||
|
|
||||||
http://www.apache.org/licenses/LICENSE-2.0
|
|
||||||
|
|
||||||
Unless required by applicable law or agreed to in writing, software
|
|
||||||
distributed under the License is distributed on an "AS IS" BASIS,
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
||||||
See the License for the specific language governing permissions and
|
|
||||||
limitations under the License.
|
|
||||||
|
|
||||||
-----------
|
|
||||||
|
|
||||||
The following npm package may be included in this product:
|
The following npm package may be included in this product:
|
||||||
|
|
||||||
- source-map@0.6.1
|
- source-map@0.6.1
|
||||||
@@ -431,220 +220,9 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
|||||||
|
|
||||||
-----------
|
-----------
|
||||||
|
|
||||||
The following npm packages may be included in this product:
|
|
||||||
|
|
||||||
- @aws-crypto/crc32@5.2.0
|
|
||||||
- @aws-crypto/util@5.2.0
|
|
||||||
|
|
||||||
These packages each contain the following license:
|
|
||||||
|
|
||||||
Apache License
|
|
||||||
Version 2.0, January 2004
|
|
||||||
http://www.apache.org/licenses/
|
|
||||||
|
|
||||||
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
|
|
||||||
|
|
||||||
1. Definitions.
|
|
||||||
|
|
||||||
"License" shall mean the terms and conditions for use, reproduction,
|
|
||||||
and distribution as defined by Sections 1 through 9 of this document.
|
|
||||||
|
|
||||||
"Licensor" shall mean the copyright owner or entity authorized by
|
|
||||||
the copyright owner that is granting the License.
|
|
||||||
|
|
||||||
"Legal Entity" shall mean the union of the acting entity and all
|
|
||||||
other entities that control, are controlled by, or are under common
|
|
||||||
control with that entity. For the purposes of this definition,
|
|
||||||
"control" means (i) the power, direct or indirect, to cause the
|
|
||||||
direction or management of such entity, whether by contract or
|
|
||||||
otherwise, or (ii) ownership of fifty percent (50%) or more of the
|
|
||||||
outstanding shares, or (iii) beneficial ownership of such entity.
|
|
||||||
|
|
||||||
"You" (or "Your") shall mean an individual or Legal Entity
|
|
||||||
exercising permissions granted by this License.
|
|
||||||
|
|
||||||
"Source" form shall mean the preferred form for making modifications,
|
|
||||||
including but not limited to software source code, documentation
|
|
||||||
source, and configuration files.
|
|
||||||
|
|
||||||
"Object" form shall mean any form resulting from mechanical
|
|
||||||
transformation or translation of a Source form, including but
|
|
||||||
not limited to compiled object code, generated documentation,
|
|
||||||
and conversions to other media types.
|
|
||||||
|
|
||||||
"Work" shall mean the work of authorship, whether in Source or
|
|
||||||
Object form, made available under the License, as indicated by a
|
|
||||||
copyright notice that is included in or attached to the work
|
|
||||||
(an example is provided in the Appendix below).
|
|
||||||
|
|
||||||
"Derivative Works" shall mean any work, whether in Source or Object
|
|
||||||
form, that is based on (or derived from) the Work and for which the
|
|
||||||
editorial revisions, annotations, elaborations, or other modifications
|
|
||||||
represent, as a whole, an original work of authorship. For the purposes
|
|
||||||
of this License, Derivative Works shall not include works that remain
|
|
||||||
separable from, or merely link (or bind by name) to the interfaces of,
|
|
||||||
the Work and Derivative Works thereof.
|
|
||||||
|
|
||||||
"Contribution" shall mean any work of authorship, including
|
|
||||||
the original version of the Work and any modifications or additions
|
|
||||||
to that Work or Derivative Works thereof, that is intentionally
|
|
||||||
submitted to Licensor for inclusion in the Work by the copyright owner
|
|
||||||
or by an individual or Legal Entity authorized to submit on behalf of
|
|
||||||
the copyright owner. For the purposes of this definition, "submitted"
|
|
||||||
means any form of electronic, verbal, or written communication sent
|
|
||||||
to the Licensor or its representatives, including but not limited to
|
|
||||||
communication on electronic mailing lists, source code control systems,
|
|
||||||
and issue tracking systems that are managed by, or on behalf of, the
|
|
||||||
Licensor for the purpose of discussing and improving the Work, but
|
|
||||||
excluding communication that is conspicuously marked or otherwise
|
|
||||||
designated in writing by the copyright owner as "Not a Contribution."
|
|
||||||
|
|
||||||
"Contributor" shall mean Licensor and any individual or Legal Entity
|
|
||||||
on behalf of whom a Contribution has been received by Licensor and
|
|
||||||
subsequently incorporated within the Work.
|
|
||||||
|
|
||||||
2. Grant of Copyright License. Subject to the terms and conditions of
|
|
||||||
this License, each Contributor hereby grants to You a perpetual,
|
|
||||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
|
||||||
copyright license to reproduce, prepare Derivative Works of,
|
|
||||||
publicly display, publicly perform, sublicense, and distribute the
|
|
||||||
Work and such Derivative Works in Source or Object form.
|
|
||||||
|
|
||||||
3. Grant of Patent License. Subject to the terms and conditions of
|
|
||||||
this License, each Contributor hereby grants to You a perpetual,
|
|
||||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
|
||||||
(except as stated in this section) patent license to make, have made,
|
|
||||||
use, offer to sell, sell, import, and otherwise transfer the Work,
|
|
||||||
where such license applies only to those patent claims licensable
|
|
||||||
by such Contributor that are necessarily infringed by their
|
|
||||||
Contribution(s) alone or by combination of their Contribution(s)
|
|
||||||
with the Work to which such Contribution(s) was submitted. If You
|
|
||||||
institute patent litigation against any entity (including a
|
|
||||||
cross-claim or counterclaim in a lawsuit) alleging that the Work
|
|
||||||
or a Contribution incorporated within the Work constitutes direct
|
|
||||||
or contributory patent infringement, then any patent licenses
|
|
||||||
granted to You under this License for that Work shall terminate
|
|
||||||
as of the date such litigation is filed.
|
|
||||||
|
|
||||||
4. Redistribution. You may reproduce and distribute copies of the
|
|
||||||
Work or Derivative Works thereof in any medium, with or without
|
|
||||||
modifications, and in Source or Object form, provided that You
|
|
||||||
meet the following conditions:
|
|
||||||
|
|
||||||
(a) You must give any other recipients of the Work or
|
|
||||||
Derivative Works a copy of this License; and
|
|
||||||
|
|
||||||
(b) You must cause any modified files to carry prominent notices
|
|
||||||
stating that You changed the files; and
|
|
||||||
|
|
||||||
(c) You must retain, in the Source form of any Derivative Works
|
|
||||||
that You distribute, all copyright, patent, trademark, and
|
|
||||||
attribution notices from the Source form of the Work,
|
|
||||||
excluding those notices that do not pertain to any part of
|
|
||||||
the Derivative Works; and
|
|
||||||
|
|
||||||
(d) If the Work includes a "NOTICE" text file as part of its
|
|
||||||
distribution, then any Derivative Works that You distribute must
|
|
||||||
include a readable copy of the attribution notices contained
|
|
||||||
within such NOTICE file, excluding those notices that do not
|
|
||||||
pertain to any part of the Derivative Works, in at least one
|
|
||||||
of the following places: within a NOTICE text file distributed
|
|
||||||
as part of the Derivative Works; within the Source form or
|
|
||||||
documentation, if provided along with the Derivative Works; or,
|
|
||||||
within a display generated by the Derivative Works, if and
|
|
||||||
wherever such third-party notices normally appear. The contents
|
|
||||||
of the NOTICE file are for informational purposes only and
|
|
||||||
do not modify the License. You may add Your own attribution
|
|
||||||
notices within Derivative Works that You distribute, alongside
|
|
||||||
or as an addendum to the NOTICE text from the Work, provided
|
|
||||||
that such additional attribution notices cannot be construed
|
|
||||||
as modifying the License.
|
|
||||||
|
|
||||||
You may add Your own copyright statement to Your modifications and
|
|
||||||
may provide additional or different license terms and conditions
|
|
||||||
for use, reproduction, or distribution of Your modifications, or
|
|
||||||
for any such Derivative Works as a whole, provided Your use,
|
|
||||||
reproduction, and distribution of the Work otherwise complies with
|
|
||||||
the conditions stated in this License.
|
|
||||||
|
|
||||||
5. Submission of Contributions. Unless You explicitly state otherwise,
|
|
||||||
any Contribution intentionally submitted for inclusion in the Work
|
|
||||||
by You to the Licensor shall be under the terms and conditions of
|
|
||||||
this License, without any additional terms or conditions.
|
|
||||||
Notwithstanding the above, nothing herein shall supersede or modify
|
|
||||||
the terms of any separate license agreement you may have executed
|
|
||||||
with Licensor regarding such Contributions.
|
|
||||||
|
|
||||||
6. Trademarks. This License does not grant permission to use the trade
|
|
||||||
names, trademarks, service marks, or product names of the Licensor,
|
|
||||||
except as required for reasonable and customary use in describing the
|
|
||||||
origin of the Work and reproducing the content of the NOTICE file.
|
|
||||||
|
|
||||||
7. Disclaimer of Warranty. Unless required by applicable law or
|
|
||||||
agreed to in writing, Licensor provides the Work (and each
|
|
||||||
Contributor provides its Contributions) on an "AS IS" BASIS,
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
|
||||||
implied, including, without limitation, any warranties or conditions
|
|
||||||
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
|
|
||||||
PARTICULAR PURPOSE. You are solely responsible for determining the
|
|
||||||
appropriateness of using or redistributing the Work and assume any
|
|
||||||
risks associated with Your exercise of permissions under this License.
|
|
||||||
|
|
||||||
8. Limitation of Liability. In no event and under no legal theory,
|
|
||||||
whether in tort (including negligence), contract, or otherwise,
|
|
||||||
unless required by applicable law (such as deliberate and grossly
|
|
||||||
negligent acts) or agreed to in writing, shall any Contributor be
|
|
||||||
liable to You for damages, including any direct, indirect, special,
|
|
||||||
incidental, or consequential damages of any character arising as a
|
|
||||||
result of this License or out of the use or inability to use the
|
|
||||||
Work (including but not limited to damages for loss of goodwill,
|
|
||||||
work stoppage, computer failure or malfunction, or any and all
|
|
||||||
other commercial damages or losses), even if such Contributor
|
|
||||||
has been advised of the possibility of such damages.
|
|
||||||
|
|
||||||
9. Accepting Warranty or Additional Liability. While redistributing
|
|
||||||
the Work or Derivative Works thereof, You may choose to offer,
|
|
||||||
and charge a fee for, acceptance of support, warranty, indemnity,
|
|
||||||
or other liability obligations and/or rights consistent with this
|
|
||||||
License. However, in accepting such obligations, You may act only
|
|
||||||
on Your own behalf and on Your sole responsibility, not on behalf
|
|
||||||
of any other Contributor, and only if You agree to indemnify,
|
|
||||||
defend, and hold each Contributor harmless for any liability
|
|
||||||
incurred by, or claims asserted against, such Contributor by reason
|
|
||||||
of your accepting any such warranty or additional liability.
|
|
||||||
|
|
||||||
END OF TERMS AND CONDITIONS
|
|
||||||
|
|
||||||
APPENDIX: How to apply the Apache License to your work.
|
|
||||||
|
|
||||||
To apply the Apache License to your work, attach the following
|
|
||||||
boilerplate notice, with the fields enclosed by brackets "{}"
|
|
||||||
replaced with your own identifying information. (Don't include
|
|
||||||
the brackets!) The text should be enclosed in the appropriate
|
|
||||||
comment syntax for the file format. We also recommend that a
|
|
||||||
file or class name and description of purpose be included on the
|
|
||||||
same "printed page" as the copyright notice for easier
|
|
||||||
identification within third-party archives.
|
|
||||||
|
|
||||||
Copyright {yyyy} {name of copyright owner}
|
|
||||||
|
|
||||||
Licensed under the Apache License, Version 2.0 (the "License");
|
|
||||||
you may not use this file except in compliance with the License.
|
|
||||||
You may obtain a copy of the License at
|
|
||||||
|
|
||||||
http://www.apache.org/licenses/LICENSE-2.0
|
|
||||||
|
|
||||||
Unless required by applicable law or agreed to in writing, software
|
|
||||||
distributed under the License is distributed on an "AS IS" BASIS,
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
||||||
See the License for the specific language governing permissions and
|
|
||||||
limitations under the License.
|
|
||||||
|
|
||||||
-----------
|
|
||||||
|
|
||||||
The following npm package may be included in this product:
|
The following npm package may be included in this product:
|
||||||
|
|
||||||
- @aws-sdk/client-sts@3.1049.0
|
- @aws-sdk/client-sts@3.1086.0
|
||||||
|
|
||||||
This package contains the following license:
|
This package contains the following license:
|
||||||
|
|
||||||
@@ -854,9 +432,9 @@ Apache License
|
|||||||
|
|
||||||
The following npm packages may be included in this product:
|
The following npm packages may be included in this product:
|
||||||
|
|
||||||
- @aws-sdk/signature-v4-multi-region@3.996.27
|
- @aws-sdk/signature-v4-multi-region@3.996.39
|
||||||
- @smithy/core@3.24.5
|
- @smithy/core@3.29.3
|
||||||
- @smithy/types@4.14.2
|
- @smithy/types@4.16.1
|
||||||
|
|
||||||
These packages each contain the following license:
|
These packages each contain the following license:
|
||||||
|
|
||||||
@@ -1068,10 +646,10 @@ The following npm packages may be included in this product:
|
|||||||
|
|
||||||
- agent-base@9.0.0
|
- agent-base@9.0.0
|
||||||
- degenerator@7.0.1
|
- degenerator@7.0.1
|
||||||
- https-proxy-agent@9.0.0
|
- https-proxy-agent@9.1.0
|
||||||
- pac-resolver@9.0.1
|
- pac-resolver@9.0.1
|
||||||
- proxy-agent@8.0.1
|
- proxy-agent@8.0.2
|
||||||
- socks-proxy-agent@10.0.0
|
- socks-proxy-agent@10.1.0
|
||||||
|
|
||||||
These packages each contain the following license:
|
These packages each contain the following license:
|
||||||
|
|
||||||
@@ -1102,7 +680,7 @@ SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
|||||||
|
|
||||||
The following npm package may be included in this product:
|
The following npm package may be included in this product:
|
||||||
|
|
||||||
- http-proxy-agent@9.0.0
|
- http-proxy-agent@9.1.0
|
||||||
|
|
||||||
This package contains the following license:
|
This package contains the following license:
|
||||||
|
|
||||||
@@ -1134,7 +712,7 @@ SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
|||||||
The following npm packages may be included in this product:
|
The following npm packages may be included in this product:
|
||||||
|
|
||||||
- data-uri-to-buffer@8.0.0
|
- data-uri-to-buffer@8.0.0
|
||||||
- get-uri@8.0.0
|
- get-uri@8.0.1
|
||||||
|
|
||||||
These packages each contain the following license:
|
These packages each contain the following license:
|
||||||
|
|
||||||
@@ -1165,7 +743,7 @@ SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
|||||||
|
|
||||||
The following npm package may be included in this product:
|
The following npm package may be included in this product:
|
||||||
|
|
||||||
- pac-proxy-agent@9.0.1
|
- pac-proxy-agent@9.1.0
|
||||||
|
|
||||||
This package contains the following license:
|
This package contains the following license:
|
||||||
|
|
||||||
@@ -1254,7 +832,7 @@ SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
|||||||
|
|
||||||
The following npm package may be included in this product:
|
The following npm package may be included in this product:
|
||||||
|
|
||||||
- @aws-sdk/core@3.974.15
|
- @aws-sdk/core@3.975.1
|
||||||
|
|
||||||
This package contains the following license:
|
This package contains the following license:
|
||||||
|
|
||||||
@@ -1462,232 +1040,18 @@ Apache License
|
|||||||
|
|
||||||
-----------
|
-----------
|
||||||
|
|
||||||
The following npm package may be included in this product:
|
|
||||||
|
|
||||||
- @aws-crypto/sha256-js@5.2.0
|
|
||||||
|
|
||||||
This package contains the following license:
|
|
||||||
|
|
||||||
Apache License
|
|
||||||
Version 2.0, January 2004
|
|
||||||
http://www.apache.org/licenses/
|
|
||||||
|
|
||||||
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
|
|
||||||
|
|
||||||
1. Definitions.
|
|
||||||
|
|
||||||
"License" shall mean the terms and conditions for use, reproduction,
|
|
||||||
and distribution as defined by Sections 1 through 9 of this document.
|
|
||||||
|
|
||||||
"Licensor" shall mean the copyright owner or entity authorized by
|
|
||||||
the copyright owner that is granting the License.
|
|
||||||
|
|
||||||
"Legal Entity" shall mean the union of the acting entity and all
|
|
||||||
other entities that control, are controlled by, or are under common
|
|
||||||
control with that entity. For the purposes of this definition,
|
|
||||||
"control" means (i) the power, direct or indirect, to cause the
|
|
||||||
direction or management of such entity, whether by contract or
|
|
||||||
otherwise, or (ii) ownership of fifty percent (50%) or more of the
|
|
||||||
outstanding shares, or (iii) beneficial ownership of such entity.
|
|
||||||
|
|
||||||
"You" (or "Your") shall mean an individual or Legal Entity
|
|
||||||
exercising permissions granted by this License.
|
|
||||||
|
|
||||||
"Source" form shall mean the preferred form for making modifications,
|
|
||||||
including but not limited to software source code, documentation
|
|
||||||
source, and configuration files.
|
|
||||||
|
|
||||||
"Object" form shall mean any form resulting from mechanical
|
|
||||||
transformation or translation of a Source form, including but
|
|
||||||
not limited to compiled object code, generated documentation,
|
|
||||||
and conversions to other media types.
|
|
||||||
|
|
||||||
"Work" shall mean the work of authorship, whether in Source or
|
|
||||||
Object form, made available under the License, as indicated by a
|
|
||||||
copyright notice that is included in or attached to the work
|
|
||||||
(an example is provided in the Appendix below).
|
|
||||||
|
|
||||||
"Derivative Works" shall mean any work, whether in Source or Object
|
|
||||||
form, that is based on (or derived from) the Work and for which the
|
|
||||||
editorial revisions, annotations, elaborations, or other modifications
|
|
||||||
represent, as a whole, an original work of authorship. For the purposes
|
|
||||||
of this License, Derivative Works shall not include works that remain
|
|
||||||
separable from, or merely link (or bind by name) to the interfaces of,
|
|
||||||
the Work and Derivative Works thereof.
|
|
||||||
|
|
||||||
"Contribution" shall mean any work of authorship, including
|
|
||||||
the original version of the Work and any modifications or additions
|
|
||||||
to that Work or Derivative Works thereof, that is intentionally
|
|
||||||
submitted to Licensor for inclusion in the Work by the copyright owner
|
|
||||||
or by an individual or Legal Entity authorized to submit on behalf of
|
|
||||||
the copyright owner. For the purposes of this definition, "submitted"
|
|
||||||
means any form of electronic, verbal, or written communication sent
|
|
||||||
to the Licensor or its representatives, including but not limited to
|
|
||||||
communication on electronic mailing lists, source code control systems,
|
|
||||||
and issue tracking systems that are managed by, or on behalf of, the
|
|
||||||
Licensor for the purpose of discussing and improving the Work, but
|
|
||||||
excluding communication that is conspicuously marked or otherwise
|
|
||||||
designated in writing by the copyright owner as "Not a Contribution."
|
|
||||||
|
|
||||||
"Contributor" shall mean Licensor and any individual or Legal Entity
|
|
||||||
on behalf of whom a Contribution has been received by Licensor and
|
|
||||||
subsequently incorporated within the Work.
|
|
||||||
|
|
||||||
2. Grant of Copyright License. Subject to the terms and conditions of
|
|
||||||
this License, each Contributor hereby grants to You a perpetual,
|
|
||||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
|
||||||
copyright license to reproduce, prepare Derivative Works of,
|
|
||||||
publicly display, publicly perform, sublicense, and distribute the
|
|
||||||
Work and such Derivative Works in Source or Object form.
|
|
||||||
|
|
||||||
3. Grant of Patent License. Subject to the terms and conditions of
|
|
||||||
this License, each Contributor hereby grants to You a perpetual,
|
|
||||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
|
||||||
(except as stated in this section) patent license to make, have made,
|
|
||||||
use, offer to sell, sell, import, and otherwise transfer the Work,
|
|
||||||
where such license applies only to those patent claims licensable
|
|
||||||
by such Contributor that are necessarily infringed by their
|
|
||||||
Contribution(s) alone or by combination of their Contribution(s)
|
|
||||||
with the Work to which such Contribution(s) was submitted. If You
|
|
||||||
institute patent litigation against any entity (including a
|
|
||||||
cross-claim or counterclaim in a lawsuit) alleging that the Work
|
|
||||||
or a Contribution incorporated within the Work constitutes direct
|
|
||||||
or contributory patent infringement, then any patent licenses
|
|
||||||
granted to You under this License for that Work shall terminate
|
|
||||||
as of the date such litigation is filed.
|
|
||||||
|
|
||||||
4. Redistribution. You may reproduce and distribute copies of the
|
|
||||||
Work or Derivative Works thereof in any medium, with or without
|
|
||||||
modifications, and in Source or Object form, provided that You
|
|
||||||
meet the following conditions:
|
|
||||||
|
|
||||||
(a) You must give any other recipients of the Work or
|
|
||||||
Derivative Works a copy of this License; and
|
|
||||||
|
|
||||||
(b) You must cause any modified files to carry prominent notices
|
|
||||||
stating that You changed the files; and
|
|
||||||
|
|
||||||
(c) You must retain, in the Source form of any Derivative Works
|
|
||||||
that You distribute, all copyright, patent, trademark, and
|
|
||||||
attribution notices from the Source form of the Work,
|
|
||||||
excluding those notices that do not pertain to any part of
|
|
||||||
the Derivative Works; and
|
|
||||||
|
|
||||||
(d) If the Work includes a "NOTICE" text file as part of its
|
|
||||||
distribution, then any Derivative Works that You distribute must
|
|
||||||
include a readable copy of the attribution notices contained
|
|
||||||
within such NOTICE file, excluding those notices that do not
|
|
||||||
pertain to any part of the Derivative Works, in at least one
|
|
||||||
of the following places: within a NOTICE text file distributed
|
|
||||||
as part of the Derivative Works; within the Source form or
|
|
||||||
documentation, if provided along with the Derivative Works; or,
|
|
||||||
within a display generated by the Derivative Works, if and
|
|
||||||
wherever such third-party notices normally appear. The contents
|
|
||||||
of the NOTICE file are for informational purposes only and
|
|
||||||
do not modify the License. You may add Your own attribution
|
|
||||||
notices within Derivative Works that You distribute, alongside
|
|
||||||
or as an addendum to the NOTICE text from the Work, provided
|
|
||||||
that such additional attribution notices cannot be construed
|
|
||||||
as modifying the License.
|
|
||||||
|
|
||||||
You may add Your own copyright statement to Your modifications and
|
|
||||||
may provide additional or different license terms and conditions
|
|
||||||
for use, reproduction, or distribution of Your modifications, or
|
|
||||||
for any such Derivative Works as a whole, provided Your use,
|
|
||||||
reproduction, and distribution of the Work otherwise complies with
|
|
||||||
the conditions stated in this License.
|
|
||||||
|
|
||||||
5. Submission of Contributions. Unless You explicitly state otherwise,
|
|
||||||
any Contribution intentionally submitted for inclusion in the Work
|
|
||||||
by You to the Licensor shall be under the terms and conditions of
|
|
||||||
this License, without any additional terms or conditions.
|
|
||||||
Notwithstanding the above, nothing herein shall supersede or modify
|
|
||||||
the terms of any separate license agreement you may have executed
|
|
||||||
with Licensor regarding such Contributions.
|
|
||||||
|
|
||||||
6. Trademarks. This License does not grant permission to use the trade
|
|
||||||
names, trademarks, service marks, or product names of the Licensor,
|
|
||||||
except as required for reasonable and customary use in describing the
|
|
||||||
origin of the Work and reproducing the content of the NOTICE file.
|
|
||||||
|
|
||||||
7. Disclaimer of Warranty. Unless required by applicable law or
|
|
||||||
agreed to in writing, Licensor provides the Work (and each
|
|
||||||
Contributor provides its Contributions) on an "AS IS" BASIS,
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
|
||||||
implied, including, without limitation, any warranties or conditions
|
|
||||||
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
|
|
||||||
PARTICULAR PURPOSE. You are solely responsible for determining the
|
|
||||||
appropriateness of using or redistributing the Work and assume any
|
|
||||||
risks associated with Your exercise of permissions under this License.
|
|
||||||
|
|
||||||
8. Limitation of Liability. In no event and under no legal theory,
|
|
||||||
whether in tort (including negligence), contract, or otherwise,
|
|
||||||
unless required by applicable law (such as deliberate and grossly
|
|
||||||
negligent acts) or agreed to in writing, shall any Contributor be
|
|
||||||
liable to You for damages, including any direct, indirect, special,
|
|
||||||
incidental, or consequential damages of any character arising as a
|
|
||||||
result of this License or out of the use or inability to use the
|
|
||||||
Work (including but not limited to damages for loss of goodwill,
|
|
||||||
work stoppage, computer failure or malfunction, or any and all
|
|
||||||
other commercial damages or losses), even if such Contributor
|
|
||||||
has been advised of the possibility of such damages.
|
|
||||||
|
|
||||||
9. Accepting Warranty or Additional Liability. While redistributing
|
|
||||||
the Work or Derivative Works thereof, You may choose to offer,
|
|
||||||
and charge a fee for, acceptance of support, warranty, indemnity,
|
|
||||||
or other liability obligations and/or rights consistent with this
|
|
||||||
License. However, in accepting such obligations, You may act only
|
|
||||||
on Your own behalf and on Your sole responsibility, not on behalf
|
|
||||||
of any other Contributor, and only if You agree to indemnify,
|
|
||||||
defend, and hold each Contributor harmless for any liability
|
|
||||||
incurred by, or claims asserted against, such Contributor by reason
|
|
||||||
of your accepting any such warranty or additional liability.
|
|
||||||
|
|
||||||
END OF TERMS AND CONDITIONS
|
|
||||||
|
|
||||||
APPENDIX: How to apply the Apache License to your work.
|
|
||||||
|
|
||||||
To apply the Apache License to your work, attach the following
|
|
||||||
boilerplate notice, with the fields enclosed by brackets "{}"
|
|
||||||
replaced with your own identifying information. (Don't include
|
|
||||||
the brackets!) The text should be enclosed in the appropriate
|
|
||||||
comment syntax for the file format. We also recommend that a
|
|
||||||
file or class name and description of purpose be included on the
|
|
||||||
same "printed page" as the copyright notice for easier
|
|
||||||
identification within third-party archives.
|
|
||||||
|
|
||||||
Copyright {yyyy} {name of copyright owner}
|
|
||||||
|
|
||||||
Licensed under the Apache License, Version 2.0 (the "License");
|
|
||||||
you may not use this file except in compliance with the License.
|
|
||||||
You may obtain a copy of the License at
|
|
||||||
|
|
||||||
http://www.apache.org/licenses/LICENSE-2.0
|
|
||||||
|
|
||||||
Unless required by applicable law or agreed to in writing, software
|
|
||||||
distributed under the License is distributed on an "AS IS" BASIS,
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
||||||
See the License for the specific language governing permissions and
|
|
||||||
limitations under the License.
|
|
||||||
|
|
||||||
-----------
|
|
||||||
|
|
||||||
The following npm packages may be included in this product:
|
The following npm packages may be included in this product:
|
||||||
|
|
||||||
- @aws-sdk/credential-provider-env@3.972.41
|
- @aws-sdk/credential-provider-env@3.972.57
|
||||||
- @aws-sdk/credential-provider-ini@3.972.42
|
- @aws-sdk/credential-provider-ini@3.973.1
|
||||||
- @aws-sdk/credential-provider-node@3.972.43
|
- @aws-sdk/credential-provider-node@3.972.67
|
||||||
- @aws-sdk/token-providers@3.1049.0
|
- @aws-sdk/token-providers@3.1083.0
|
||||||
- @aws-sdk/types@3.973.9
|
- @aws-sdk/types@3.974.0
|
||||||
- @aws-sdk/util-locate-window@3.965.5
|
- @aws-sdk/xml-builder@3.972.34
|
||||||
- @aws-sdk/xml-builder@3.972.26
|
- @smithy/credential-provider-imds@4.4.8
|
||||||
- @smithy/credential-provider-imds@4.3.3
|
- @smithy/fetch-http-handler@5.6.5
|
||||||
- @smithy/fetch-http-handler@5.4.3
|
- @smithy/node-http-handler@4.9.5
|
||||||
- @smithy/is-array-buffer@2.2.0
|
- @smithy/signature-v4@5.6.4
|
||||||
- @smithy/node-http-handler@4.7.3
|
|
||||||
- @smithy/signature-v4@5.4.5
|
|
||||||
- @smithy/util-buffer-from@2.2.0
|
|
||||||
- @smithy/util-utf8@2.3.0
|
|
||||||
|
|
||||||
These packages each contain the following license:
|
These packages each contain the following license:
|
||||||
|
|
||||||
@@ -1897,9 +1261,9 @@ Apache License
|
|||||||
|
|
||||||
The following npm packages may be included in this product:
|
The following npm packages may be included in this product:
|
||||||
|
|
||||||
- @aws-sdk/credential-provider-process@3.972.38
|
- @aws-sdk/credential-provider-process@3.972.57
|
||||||
- @aws-sdk/credential-provider-sso@3.972.42
|
- @aws-sdk/credential-provider-sso@3.973.1
|
||||||
- @aws-sdk/credential-provider-web-identity@3.972.42
|
- @aws-sdk/credential-provider-web-identity@3.972.63
|
||||||
|
|
||||||
These packages each contain the following license:
|
These packages each contain the following license:
|
||||||
|
|
||||||
@@ -2109,9 +1473,9 @@ Apache License
|
|||||||
|
|
||||||
The following npm packages may be included in this product:
|
The following npm packages may be included in this product:
|
||||||
|
|
||||||
- @aws-sdk/credential-provider-http@3.972.40
|
- @aws-sdk/credential-provider-http@3.972.59
|
||||||
- @aws-sdk/credential-provider-login@3.972.42
|
- @aws-sdk/credential-provider-login@3.972.63
|
||||||
- @aws-sdk/nested-clients@3.997.10
|
- @aws-sdk/nested-clients@3.997.31
|
||||||
|
|
||||||
These packages each contain the following license:
|
These packages each contain the following license:
|
||||||
|
|
||||||
@@ -2335,9 +1699,8 @@ THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
|||||||
|
|
||||||
The following npm packages may be included in this product:
|
The following npm packages may be included in this product:
|
||||||
|
|
||||||
- @nodable/entities@2.1.1
|
- proxy-agent-negotiate@1.1.0
|
||||||
- quickjs-wasi@2.2.0
|
- quickjs-wasi@2.2.0
|
||||||
- xml-naming@0.1.0
|
|
||||||
|
|
||||||
These packages each contain the following license:
|
These packages each contain the following license:
|
||||||
|
|
||||||
@@ -2377,127 +1740,7 @@ SOFTWARE.
|
|||||||
|
|
||||||
The following npm package may be included in this product:
|
The following npm package may be included in this product:
|
||||||
|
|
||||||
- fast-xml-parser@5.7.3
|
- undici@6.27.0
|
||||||
|
|
||||||
This package contains the following license:
|
|
||||||
|
|
||||||
MIT License
|
|
||||||
|
|
||||||
Copyright (c) 2017 Amit Kumar Gupta
|
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
|
||||||
of this software and associated documentation files (the "Software"), to deal
|
|
||||||
in the Software without restriction, including without limitation the rights
|
|
||||||
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
|
||||||
copies of the Software, and to permit persons to whom the Software is
|
|
||||||
furnished to do so, subject to the following conditions:
|
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be included in all
|
|
||||||
copies or substantial portions of the Software.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
|
||||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
|
||||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
|
||||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
|
||||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
|
||||||
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
|
||||||
SOFTWARE.
|
|
||||||
|
|
||||||
-----------
|
|
||||||
|
|
||||||
The following npm package may be included in this product:
|
|
||||||
|
|
||||||
- strnum@2.3.0
|
|
||||||
|
|
||||||
This package contains the following license:
|
|
||||||
|
|
||||||
MIT License
|
|
||||||
|
|
||||||
Copyright (c) 2021 Natural Intelligence
|
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
|
||||||
of this software and associated documentation files (the "Software"), to deal
|
|
||||||
in the Software without restriction, including without limitation the rights
|
|
||||||
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
|
||||||
copies of the Software, and to permit persons to whom the Software is
|
|
||||||
furnished to do so, subject to the following conditions:
|
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be included in all
|
|
||||||
copies or substantial portions of the Software.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
|
||||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
|
||||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
|
||||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
|
||||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
|
||||||
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
|
||||||
SOFTWARE.
|
|
||||||
|
|
||||||
-----------
|
|
||||||
|
|
||||||
The following npm package may be included in this product:
|
|
||||||
|
|
||||||
- path-expression-matcher@1.5.0
|
|
||||||
|
|
||||||
This package contains the following license:
|
|
||||||
|
|
||||||
MIT License
|
|
||||||
|
|
||||||
Copyright (c) 2024
|
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
|
||||||
of this software and associated documentation files (the "Software"), to deal
|
|
||||||
in the Software without restriction, including without limitation the rights
|
|
||||||
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
|
||||||
copies of the Software, and to permit persons to whom the Software is
|
|
||||||
furnished to do so, subject to the following conditions:
|
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be included in all
|
|
||||||
copies or substantial portions of the Software.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
|
||||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
|
||||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
|
||||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
|
||||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
|
||||||
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
|
||||||
SOFTWARE.
|
|
||||||
|
|
||||||
-----------
|
|
||||||
|
|
||||||
The following npm package may be included in this product:
|
|
||||||
|
|
||||||
- fast-xml-builder@1.2.0
|
|
||||||
|
|
||||||
This package contains the following license:
|
|
||||||
|
|
||||||
MIT License
|
|
||||||
|
|
||||||
Copyright (c) 2026 Natural Intelligence
|
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
|
||||||
of this software and associated documentation files (the "Software"), to deal
|
|
||||||
in the Software without restriction, including without limitation the rights
|
|
||||||
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
|
||||||
copies of the Software, and to permit persons to whom the Software is
|
|
||||||
furnished to do so, subject to the following conditions:
|
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be included in all
|
|
||||||
copies or substantial portions of the Software.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
|
||||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
|
||||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
|
||||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
|
||||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
|
||||||
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
|
||||||
SOFTWARE.
|
|
||||||
|
|
||||||
-----------
|
|
||||||
|
|
||||||
The following npm package may be included in this product:
|
|
||||||
|
|
||||||
- undici@6.25.0
|
|
||||||
|
|
||||||
This package contains the following license:
|
This package contains the following license:
|
||||||
|
|
||||||
|
|||||||
+153
-36
@@ -6,7 +6,11 @@ var __getOwnPropNames = Object.getOwnPropertyNames;
|
|||||||
var __getProtoOf = Object.getPrototypeOf;
|
var __getProtoOf = Object.getPrototypeOf;
|
||||||
var __hasOwnProp = Object.prototype.hasOwnProperty;
|
var __hasOwnProp = Object.prototype.hasOwnProperty;
|
||||||
var __commonJS = (cb, mod) => function __require() {
|
var __commonJS = (cb, mod) => function __require() {
|
||||||
return mod || (0, cb[__getOwnPropNames(cb)[0]])((mod = { exports: {} }).exports, mod), mod.exports;
|
try {
|
||||||
|
return mod || (0, cb[__getOwnPropNames(cb)[0]])((mod = { exports: {} }).exports, mod), mod.exports;
|
||||||
|
} catch (e) {
|
||||||
|
throw mod = 0, e;
|
||||||
|
}
|
||||||
};
|
};
|
||||||
var __export = (target, all) => {
|
var __export = (target, all) => {
|
||||||
for (var name in all)
|
for (var name in all)
|
||||||
@@ -2058,6 +2062,7 @@ var require_dispatcher_base = __commonJS({
|
|||||||
}
|
}
|
||||||
get webSocketOptions() {
|
get webSocketOptions() {
|
||||||
return {
|
return {
|
||||||
|
maxFragments: this[kWebSocketOptions].maxFragments ?? 131072,
|
||||||
maxPayloadSize: this[kWebSocketOptions].maxPayloadSize ?? 128 * 1024 * 1024
|
maxPayloadSize: this[kWebSocketOptions].maxPayloadSize ?? 128 * 1024 * 1024
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -5712,6 +5717,9 @@ var require_client_h1 = __commonJS({
|
|||||||
var FastBuffer = Buffer[Symbol.species];
|
var FastBuffer = Buffer[Symbol.species];
|
||||||
var addListener = util.addListener;
|
var addListener = util.addListener;
|
||||||
var removeAllListeners = util.removeAllListeners;
|
var removeAllListeners = util.removeAllListeners;
|
||||||
|
var kIdleSocketValidation = /* @__PURE__ */ Symbol("kIdleSocketValidation");
|
||||||
|
var kIdleSocketValidationTimeout = /* @__PURE__ */ Symbol("kIdleSocketValidationTimeout");
|
||||||
|
var kSocketUsed = /* @__PURE__ */ Symbol("kSocketUsed");
|
||||||
var extractBody;
|
var extractBody;
|
||||||
async function lazyllhttp() {
|
async function lazyllhttp() {
|
||||||
const llhttpWasmData = process.env.JEST_WORKER_ID ? require_llhttp_wasm() : void 0;
|
const llhttpWasmData = process.env.JEST_WORKER_ID ? require_llhttp_wasm() : void 0;
|
||||||
@@ -5874,24 +5882,55 @@ var require_client_h1 = __commonJS({
|
|||||||
currentBufferRef = null;
|
currentBufferRef = null;
|
||||||
}
|
}
|
||||||
const offset = llhttp.llhttp_get_error_pos(this.ptr) - currentBufferPtr;
|
const offset = llhttp.llhttp_get_error_pos(this.ptr) - currentBufferPtr;
|
||||||
if (ret === constants4.ERROR.PAUSED_UPGRADE) {
|
if (ret !== constants4.ERROR.OK) {
|
||||||
this.onUpgrade(data.slice(offset));
|
const body = data.subarray(offset);
|
||||||
} else if (ret === constants4.ERROR.PAUSED) {
|
if (ret === constants4.ERROR.PAUSED_UPGRADE) {
|
||||||
this.paused = true;
|
this.onUpgrade(body);
|
||||||
socket.unshift(data.slice(offset));
|
} else if (ret === constants4.ERROR.PAUSED) {
|
||||||
} else if (ret !== constants4.ERROR.OK) {
|
this.paused = true;
|
||||||
const ptr = llhttp.llhttp_get_error_reason(this.ptr);
|
socket.unshift(body);
|
||||||
let message = "";
|
} else {
|
||||||
if (ptr) {
|
throw this.createError(ret, body);
|
||||||
const len = new Uint8Array(llhttp.memory.buffer, ptr).indexOf(0);
|
|
||||||
message = "Response does not match the HTTP/1.1 protocol (" + Buffer.from(llhttp.memory.buffer, ptr, len).toString() + ")";
|
|
||||||
}
|
}
|
||||||
throw new HTTPParserError(message, constants4.ERROR[ret], data.slice(offset));
|
|
||||||
}
|
}
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
util.destroy(socket, err);
|
util.destroy(socket, err);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
finish() {
|
||||||
|
assert(currentParser === null);
|
||||||
|
assert(this.ptr != null);
|
||||||
|
assert(!this.paused);
|
||||||
|
const { llhttp } = this;
|
||||||
|
let ret;
|
||||||
|
try {
|
||||||
|
currentParser = this;
|
||||||
|
ret = llhttp.llhttp_finish(this.ptr);
|
||||||
|
} finally {
|
||||||
|
currentParser = null;
|
||||||
|
}
|
||||||
|
if (ret === constants4.ERROR.OK) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
if (ret === constants4.ERROR.PAUSED || ret === constants4.ERROR.PAUSED_UPGRADE) {
|
||||||
|
this.paused = true;
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
return this.createError(ret, EMPTY_BUF);
|
||||||
|
}
|
||||||
|
createError(ret, data) {
|
||||||
|
const { llhttp, contentLength, bytesRead } = this;
|
||||||
|
if (contentLength && bytesRead !== parseInt(contentLength, 10)) {
|
||||||
|
return new ResponseContentLengthMismatchError();
|
||||||
|
}
|
||||||
|
const ptr = llhttp.llhttp_get_error_reason(this.ptr);
|
||||||
|
let message = "";
|
||||||
|
if (ptr) {
|
||||||
|
const len = new Uint8Array(llhttp.memory.buffer, ptr).indexOf(0);
|
||||||
|
message = "Response does not match the HTTP/1.1 protocol (" + Buffer.from(llhttp.memory.buffer, ptr, len).toString() + ")";
|
||||||
|
}
|
||||||
|
return new HTTPParserError(message, constants4.ERROR[ret], data);
|
||||||
|
}
|
||||||
destroy() {
|
destroy() {
|
||||||
assert(this.ptr != null);
|
assert(this.ptr != null);
|
||||||
assert(currentParser == null);
|
assert(currentParser == null);
|
||||||
@@ -5911,6 +5950,10 @@ var require_client_h1 = __commonJS({
|
|||||||
if (socket.destroyed) {
|
if (socket.destroyed) {
|
||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
|
if (client[kRunning] === 0) {
|
||||||
|
util.destroy(socket, new SocketError("bad response", util.getSocketInfo(socket)));
|
||||||
|
return -1;
|
||||||
|
}
|
||||||
const request = client[kQueue][client[kRunningIdx]];
|
const request = client[kQueue][client[kRunningIdx]];
|
||||||
if (!request) {
|
if (!request) {
|
||||||
return -1;
|
return -1;
|
||||||
@@ -5990,6 +6033,10 @@ var require_client_h1 = __commonJS({
|
|||||||
if (socket.destroyed) {
|
if (socket.destroyed) {
|
||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
|
if (client[kRunning] === 0) {
|
||||||
|
util.destroy(socket, new SocketError("bad response", util.getSocketInfo(socket)));
|
||||||
|
return -1;
|
||||||
|
}
|
||||||
const request = client[kQueue][client[kRunningIdx]];
|
const request = client[kQueue][client[kRunningIdx]];
|
||||||
if (!request) {
|
if (!request) {
|
||||||
return -1;
|
return -1;
|
||||||
@@ -6115,6 +6162,7 @@ var require_client_h1 = __commonJS({
|
|||||||
}
|
}
|
||||||
request.onComplete(headers);
|
request.onComplete(headers);
|
||||||
client[kQueue][client[kRunningIdx]++] = null;
|
client[kQueue][client[kRunningIdx]++] = null;
|
||||||
|
socket[kSocketUsed] = true;
|
||||||
if (socket[kWriting]) {
|
if (socket[kWriting]) {
|
||||||
assert(client[kRunning] === 0);
|
assert(client[kRunning] === 0);
|
||||||
util.destroy(socket, new InformationalError("reset"));
|
util.destroy(socket, new InformationalError("reset"));
|
||||||
@@ -6158,12 +6206,19 @@ var require_client_h1 = __commonJS({
|
|||||||
socket[kWriting] = false;
|
socket[kWriting] = false;
|
||||||
socket[kReset] = false;
|
socket[kReset] = false;
|
||||||
socket[kBlocking] = false;
|
socket[kBlocking] = false;
|
||||||
|
socket[kIdleSocketValidation] = 0;
|
||||||
|
socket[kIdleSocketValidationTimeout] = null;
|
||||||
|
socket[kSocketUsed] = false;
|
||||||
socket[kParser] = new Parser(client, socket, llhttpInstance);
|
socket[kParser] = new Parser(client, socket, llhttpInstance);
|
||||||
addListener(socket, "error", function(err) {
|
addListener(socket, "error", function(err) {
|
||||||
assert(err.code !== "ERR_TLS_CERT_ALTNAME_INVALID");
|
assert(err.code !== "ERR_TLS_CERT_ALTNAME_INVALID");
|
||||||
const parser = this[kParser];
|
const parser = this[kParser];
|
||||||
if (err.code === "ECONNRESET" && parser.statusCode && !parser.shouldKeepAlive) {
|
if (err.code === "ECONNRESET" && parser.statusCode && !parser.shouldKeepAlive) {
|
||||||
parser.onMessageComplete();
|
const parserErr = parser.finish();
|
||||||
|
if (parserErr) {
|
||||||
|
this[kError] = parserErr;
|
||||||
|
this[kClient][kOnError](parserErr);
|
||||||
|
}
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
this[kError] = err;
|
this[kError] = err;
|
||||||
@@ -6178,7 +6233,10 @@ var require_client_h1 = __commonJS({
|
|||||||
addListener(socket, "end", function() {
|
addListener(socket, "end", function() {
|
||||||
const parser = this[kParser];
|
const parser = this[kParser];
|
||||||
if (parser.statusCode && !parser.shouldKeepAlive) {
|
if (parser.statusCode && !parser.shouldKeepAlive) {
|
||||||
parser.onMessageComplete();
|
const parserErr = parser.finish();
|
||||||
|
if (parserErr) {
|
||||||
|
util.destroy(this, parserErr);
|
||||||
|
}
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
util.destroy(this, new SocketError("other side closed", util.getSocketInfo(this)));
|
util.destroy(this, new SocketError("other side closed", util.getSocketInfo(this)));
|
||||||
@@ -6186,9 +6244,10 @@ var require_client_h1 = __commonJS({
|
|||||||
addListener(socket, "close", function() {
|
addListener(socket, "close", function() {
|
||||||
const client2 = this[kClient];
|
const client2 = this[kClient];
|
||||||
const parser = this[kParser];
|
const parser = this[kParser];
|
||||||
|
clearIdleSocketValidation(this);
|
||||||
if (parser) {
|
if (parser) {
|
||||||
if (!this[kError] && parser.statusCode && !parser.shouldKeepAlive) {
|
if (!this[kError] && parser.statusCode && !parser.shouldKeepAlive) {
|
||||||
parser.onMessageComplete();
|
this[kError] = parser.finish() || this[kError];
|
||||||
}
|
}
|
||||||
this[kParser].destroy();
|
this[kParser].destroy();
|
||||||
this[kParser] = null;
|
this[kParser] = null;
|
||||||
@@ -6237,7 +6296,7 @@ var require_client_h1 = __commonJS({
|
|||||||
return socket.destroyed;
|
return socket.destroyed;
|
||||||
},
|
},
|
||||||
busy(request) {
|
busy(request) {
|
||||||
if (socket[kWriting] || socket[kReset] || socket[kBlocking]) {
|
if (socket[kWriting] || socket[kReset] || socket[kBlocking] || socket[kIdleSocketValidation] === 1) {
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
if (request) {
|
if (request) {
|
||||||
@@ -6255,6 +6314,24 @@ var require_client_h1 = __commonJS({
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
function clearIdleSocketValidation(socket) {
|
||||||
|
if (socket[kIdleSocketValidationTimeout]) {
|
||||||
|
clearTimeout(socket[kIdleSocketValidationTimeout]);
|
||||||
|
socket[kIdleSocketValidationTimeout] = null;
|
||||||
|
}
|
||||||
|
socket[kIdleSocketValidation] = 0;
|
||||||
|
}
|
||||||
|
function scheduleIdleSocketValidation(client, socket) {
|
||||||
|
socket[kIdleSocketValidation] = 1;
|
||||||
|
socket[kIdleSocketValidationTimeout] = setTimeout(() => {
|
||||||
|
socket[kIdleSocketValidationTimeout] = null;
|
||||||
|
socket[kIdleSocketValidation] = 2;
|
||||||
|
if (client[kSocket] === socket && !socket.destroyed) {
|
||||||
|
client[kResume]();
|
||||||
|
}
|
||||||
|
}, 0);
|
||||||
|
socket[kIdleSocketValidationTimeout].unref?.();
|
||||||
|
}
|
||||||
function resumeH1(client) {
|
function resumeH1(client) {
|
||||||
const socket = client[kSocket];
|
const socket = client[kSocket];
|
||||||
if (socket && !socket.destroyed) {
|
if (socket && !socket.destroyed) {
|
||||||
@@ -6267,6 +6344,29 @@ var require_client_h1 = __commonJS({
|
|||||||
socket.ref();
|
socket.ref();
|
||||||
socket[kNoRef] = false;
|
socket[kNoRef] = false;
|
||||||
}
|
}
|
||||||
|
if (client[kRunning] === 0 && client[kPending] > 0 && socket[kSocketUsed]) {
|
||||||
|
if (socket[kIdleSocketValidation] === 0) {
|
||||||
|
scheduleIdleSocketValidation(client, socket);
|
||||||
|
socket[kParser].readMore();
|
||||||
|
if (socket.destroyed) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
if (socket[kIdleSocketValidation] === 1) {
|
||||||
|
socket[kParser].readMore();
|
||||||
|
if (socket.destroyed) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (client[kRunning] === 0) {
|
||||||
|
socket[kParser].readMore();
|
||||||
|
if (socket.destroyed) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
}
|
||||||
if (client[kSize] === 0) {
|
if (client[kSize] === 0) {
|
||||||
if (socket[kParser].timeoutType !== TIMEOUT_KEEP_ALIVE) {
|
if (socket[kParser].timeoutType !== TIMEOUT_KEEP_ALIVE) {
|
||||||
socket[kParser].setTimeout(client[kKeepAliveTimeoutValue], TIMEOUT_KEEP_ALIVE);
|
socket[kParser].setTimeout(client[kKeepAliveTimeoutValue], TIMEOUT_KEEP_ALIVE);
|
||||||
@@ -6319,6 +6419,7 @@ var require_client_h1 = __commonJS({
|
|||||||
process.emitWarning(new RequestContentLengthMismatchError());
|
process.emitWarning(new RequestContentLengthMismatchError());
|
||||||
}
|
}
|
||||||
const socket = client[kSocket];
|
const socket = client[kSocket];
|
||||||
|
clearIdleSocketValidation(socket);
|
||||||
const abort = (err) => {
|
const abort = (err) => {
|
||||||
if (request.aborted || request.completed) {
|
if (request.aborted || request.completed) {
|
||||||
return;
|
return;
|
||||||
@@ -16103,18 +16204,14 @@ var require_parse = __commonJS({
|
|||||||
} else if (attributeNameLowercase === "httponly") {
|
} else if (attributeNameLowercase === "httponly") {
|
||||||
cookieAttributeList.httpOnly = true;
|
cookieAttributeList.httpOnly = true;
|
||||||
} else if (attributeNameLowercase === "samesite") {
|
} else if (attributeNameLowercase === "samesite") {
|
||||||
let enforcement = "Default";
|
|
||||||
const attributeValueLowercase = attributeValue.toLowerCase();
|
const attributeValueLowercase = attributeValue.toLowerCase();
|
||||||
if (attributeValueLowercase.includes("none")) {
|
if (attributeValueLowercase === "none") {
|
||||||
enforcement = "None";
|
cookieAttributeList.sameSite = "None";
|
||||||
|
} else if (attributeValueLowercase === "strict") {
|
||||||
|
cookieAttributeList.sameSite = "Strict";
|
||||||
|
} else if (attributeValueLowercase === "lax") {
|
||||||
|
cookieAttributeList.sameSite = "Lax";
|
||||||
}
|
}
|
||||||
if (attributeValueLowercase.includes("strict")) {
|
|
||||||
enforcement = "Strict";
|
|
||||||
}
|
|
||||||
if (attributeValueLowercase.includes("lax")) {
|
|
||||||
enforcement = "Lax";
|
|
||||||
}
|
|
||||||
cookieAttributeList.sameSite = enforcement;
|
|
||||||
} else {
|
} else {
|
||||||
cookieAttributeList.unparsed ??= [];
|
cookieAttributeList.unparsed ??= [];
|
||||||
cookieAttributeList.unparsed.push(`${attributeName}=${attributeValue}`);
|
cookieAttributeList.unparsed.push(`${attributeName}=${attributeValue}`);
|
||||||
@@ -17136,6 +17233,10 @@ var require_receiver = __commonJS({
|
|||||||
var { closeWebSocketConnection } = require_connection();
|
var { closeWebSocketConnection } = require_connection();
|
||||||
var { PerMessageDeflate } = require_permessage_deflate();
|
var { PerMessageDeflate } = require_permessage_deflate();
|
||||||
var { MessageSizeExceededError } = require_errors();
|
var { MessageSizeExceededError } = require_errors();
|
||||||
|
function failWebsocketConnectionWithCode(ws, code, reason) {
|
||||||
|
closeWebSocketConnection(ws, code, reason, Buffer.byteLength(reason));
|
||||||
|
failWebsocketConnection(ws, reason);
|
||||||
|
}
|
||||||
var ByteParser = class extends Writable {
|
var ByteParser = class extends Writable {
|
||||||
#buffers = [];
|
#buffers = [];
|
||||||
#fragmentsBytes = 0;
|
#fragmentsBytes = 0;
|
||||||
@@ -17147,16 +17248,19 @@ var require_receiver = __commonJS({
|
|||||||
/** @type {Map<string, PerMessageDeflate>} */
|
/** @type {Map<string, PerMessageDeflate>} */
|
||||||
#extensions;
|
#extensions;
|
||||||
/** @type {number} */
|
/** @type {number} */
|
||||||
|
#maxFragments;
|
||||||
|
/** @type {number} */
|
||||||
#maxPayloadSize;
|
#maxPayloadSize;
|
||||||
/**
|
/**
|
||||||
* @param {import('./websocket').WebSocket} ws
|
* @param {import('./websocket').WebSocket} ws
|
||||||
* @param {Map<string, string>|null} extensions
|
* @param {Map<string, string>|null} extensions
|
||||||
* @param {{ maxPayloadSize?: number }} [options]
|
* @param {{ maxFragments?: number, maxPayloadSize?: number }} [options]
|
||||||
*/
|
*/
|
||||||
constructor(ws, extensions, options = {}) {
|
constructor(ws, extensions, options = {}) {
|
||||||
super();
|
super();
|
||||||
this.ws = ws;
|
this.ws = ws;
|
||||||
this.#extensions = extensions == null ? /* @__PURE__ */ new Map() : extensions;
|
this.#extensions = extensions == null ? /* @__PURE__ */ new Map() : extensions;
|
||||||
|
this.#maxFragments = options.maxFragments ?? 0;
|
||||||
this.#maxPayloadSize = options.maxPayloadSize ?? 0;
|
this.#maxPayloadSize = options.maxPayloadSize ?? 0;
|
||||||
if (this.#extensions.has("permessage-deflate")) {
|
if (this.#extensions.has("permessage-deflate")) {
|
||||||
this.#extensions.set("permessage-deflate", new PerMessageDeflate(extensions, options));
|
this.#extensions.set("permessage-deflate", new PerMessageDeflate(extensions, options));
|
||||||
@@ -17173,8 +17277,8 @@ var require_receiver = __commonJS({
|
|||||||
this.run(callback);
|
this.run(callback);
|
||||||
}
|
}
|
||||||
#validatePayloadLength() {
|
#validatePayloadLength() {
|
||||||
if (this.#maxPayloadSize > 0 && !isControlFrame(this.#info.opcode) && this.#info.payloadLength > this.#maxPayloadSize) {
|
if (this.#maxPayloadSize > 0 && !isControlFrame(this.#info.opcode) && this.#info.payloadLength + this.#fragmentsBytes > this.#maxPayloadSize) {
|
||||||
failWebsocketConnection(this.ws, "Payload size exceeds maximum allowed size");
|
failWebsocketConnectionWithCode(this.ws, 1009, "Payload size exceeds maximum allowed size");
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
return true;
|
return true;
|
||||||
@@ -17290,9 +17394,11 @@ var require_receiver = __commonJS({
|
|||||||
this.#state = parserStates.INFO;
|
this.#state = parserStates.INFO;
|
||||||
} else {
|
} else {
|
||||||
if (!this.#info.compressed) {
|
if (!this.#info.compressed) {
|
||||||
this.writeFragments(body);
|
if (!this.writeFragments(body)) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
if (this.#maxPayloadSize > 0 && this.#fragmentsBytes > this.#maxPayloadSize) {
|
if (this.#maxPayloadSize > 0 && this.#fragmentsBytes > this.#maxPayloadSize) {
|
||||||
failWebsocketConnection(this.ws, new MessageSizeExceededError().message);
|
failWebsocketConnectionWithCode(this.ws, 1009, new MessageSizeExceededError().message);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
if (!this.#info.fragmented && this.#info.fin) {
|
if (!this.#info.fragmented && this.#info.fin) {
|
||||||
@@ -17305,12 +17411,15 @@ var require_receiver = __commonJS({
|
|||||||
this.#info.fin,
|
this.#info.fin,
|
||||||
(error2, data) => {
|
(error2, data) => {
|
||||||
if (error2) {
|
if (error2) {
|
||||||
failWebsocketConnection(this.ws, error2.message);
|
const code = error2 instanceof MessageSizeExceededError ? 1009 : 1007;
|
||||||
|
failWebsocketConnectionWithCode(this.ws, code, error2.message);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
if (!this.writeFragments(data)) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
this.writeFragments(data);
|
|
||||||
if (this.#maxPayloadSize > 0 && this.#fragmentsBytes > this.#maxPayloadSize) {
|
if (this.#maxPayloadSize > 0 && this.#fragmentsBytes > this.#maxPayloadSize) {
|
||||||
failWebsocketConnection(this.ws, new MessageSizeExceededError().message);
|
failWebsocketConnectionWithCode(this.ws, 1009, new MessageSizeExceededError().message);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
if (!this.#info.fin) {
|
if (!this.#info.fin) {
|
||||||
@@ -17368,8 +17477,13 @@ var require_receiver = __commonJS({
|
|||||||
return buffer;
|
return buffer;
|
||||||
}
|
}
|
||||||
writeFragments(fragment) {
|
writeFragments(fragment) {
|
||||||
|
if (this.#maxFragments > 0 && this.#fragments.length === this.#maxFragments) {
|
||||||
|
failWebsocketConnectionWithCode(this.ws, 1008, "Too many message fragments");
|
||||||
|
return false;
|
||||||
|
}
|
||||||
this.#fragmentsBytes += fragment.length;
|
this.#fragmentsBytes += fragment.length;
|
||||||
this.#fragments.push(fragment);
|
this.#fragments.push(fragment);
|
||||||
|
return true;
|
||||||
}
|
}
|
||||||
consumeFragments() {
|
consumeFragments() {
|
||||||
const fragments = this.#fragments;
|
const fragments = this.#fragments;
|
||||||
@@ -17819,8 +17933,11 @@ var require_websocket = __commonJS({
|
|||||||
*/
|
*/
|
||||||
#onConnectionEstablished(response, parsedExtensions) {
|
#onConnectionEstablished(response, parsedExtensions) {
|
||||||
this[kResponse] = response;
|
this[kResponse] = response;
|
||||||
const maxPayloadSize = this[kController]?.dispatcher?.webSocketOptions?.maxPayloadSize;
|
const webSocketOptions = this[kController]?.dispatcher?.webSocketOptions;
|
||||||
|
const maxFragments = webSocketOptions?.maxFragments;
|
||||||
|
const maxPayloadSize = webSocketOptions?.maxPayloadSize;
|
||||||
const parser = new ByteParser(this, parsedExtensions, {
|
const parser = new ByteParser(this, parsedExtensions, {
|
||||||
|
maxFragments,
|
||||||
maxPayloadSize
|
maxPayloadSize
|
||||||
});
|
});
|
||||||
parser.on("drain", onParserDrain);
|
parser.on("drain", onParserDrain);
|
||||||
|
|||||||
+6304
-7189
File diff suppressed because one or more lines are too long
Generated
+1100
-1055
File diff suppressed because it is too large
Load Diff
+15
-15
@@ -1,7 +1,7 @@
|
|||||||
{
|
{
|
||||||
"name": "configure-aws-credentials",
|
"name": "configure-aws-credentials",
|
||||||
"description": "A GitHub Action to configure AWS credentials",
|
"description": "A GitHub Action to configure AWS credentials",
|
||||||
"version": "6.2.0",
|
"version": "6.2.2",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
"build": "tsc",
|
"build": "tsc",
|
||||||
"lint": "biome check --error-on-warnings ./src ./test && markdownlint -i node_modules -i CHANGELOG.md '**/*.md'",
|
"lint": "biome check --error-on-warnings ./src ./test && markdownlint -i node_modules -i CHANGELOG.md '**/*.md'",
|
||||||
@@ -17,26 +17,26 @@
|
|||||||
"organization": true
|
"organization": true
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@aws-sdk/credential-provider-env": "^3.972.39",
|
"@aws-sdk/credential-provider-env": "^3.972.57",
|
||||||
"@biomejs/biome": "2.4.15",
|
"@biomejs/biome": "2.5.3",
|
||||||
"@smithy/property-provider": "^4.3.4",
|
"@smithy/property-provider": "^4.4.8",
|
||||||
"@types/node": "^25.9.1",
|
"@types/node": "^26.1.1",
|
||||||
"@vitest/coverage-v8": "4.1.5",
|
"@vitest/coverage-v8": "4.1.10",
|
||||||
"aws-sdk-client-mock": "^4.1.0",
|
"aws-sdk-client-mock": "^4.1.0",
|
||||||
"esbuild": "^0.28.0",
|
"esbuild": "^0.28.1",
|
||||||
"generate-license-file": "^4.1.1",
|
"generate-license-file": "^4.2.1",
|
||||||
"json-schema": "^0.4.0",
|
"json-schema": "^0.4.0",
|
||||||
"markdownlint-cli": "^0.48.0",
|
"markdownlint-cli": "^0.49.0",
|
||||||
"memfs": "^4.57.2",
|
"memfs": "^4.64.0",
|
||||||
"standard-version": "^9.5.0",
|
"standard-version": "^9.5.0",
|
||||||
"typescript": "^6.0.3",
|
"typescript": "^7.0.2",
|
||||||
"vitest": "4.1.5"
|
"vitest": "4.1.10"
|
||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/core": "^3.0.1",
|
"@actions/core": "^3.0.1",
|
||||||
"@aws-sdk/client-sts": "^3.1049.0",
|
"@aws-sdk/client-sts": "^3.1086.0",
|
||||||
"@smithy/node-http-handler": "^4.7.3",
|
"@smithy/node-http-handler": "^4.9.5",
|
||||||
"proxy-agent": "^8.0.1"
|
"proxy-agent": "^8.0.2"
|
||||||
},
|
},
|
||||||
"keywords": [
|
"keywords": [
|
||||||
"aws",
|
"aws",
|
||||||
|
|||||||
+34
-33
@@ -53,54 +53,55 @@ export class CredentialsClient {
|
|||||||
|
|
||||||
public get stsClient(): STSClient {
|
public get stsClient(): STSClient {
|
||||||
if (!this._stsClient || this.roleChaining) {
|
if (!this._stsClient || this.roleChaining) {
|
||||||
this._stsClient = new STSClient({
|
this._stsClient = this.createStsClient();
|
||||||
customUserAgent: buildCustomUserAgent(),
|
|
||||||
...(this.region !== undefined && { region: this.region }),
|
|
||||||
...(this.stsEndpoint !== undefined && { endpoint: this.stsEndpoint }),
|
|
||||||
...(this.requestHandler !== undefined && { requestHandler: this.requestHandler }),
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
return this._stsClient;
|
return this._stsClient;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Builds an STS client using the action's configured region/endpoint/proxy. When explicit credentials are provided,
|
||||||
|
// the client uses them directly instead of the SDK default credential provider chain.
|
||||||
|
// This matters for validateAccountId.
|
||||||
|
private createStsClient(credentials?: AwsCredentialIdentity): STSClient {
|
||||||
|
return new STSClient({
|
||||||
|
customUserAgent: buildCustomUserAgent(),
|
||||||
|
...(this.region !== undefined && { region: this.region }),
|
||||||
|
...(this.stsEndpoint !== undefined && { endpoint: this.stsEndpoint }),
|
||||||
|
...(this.requestHandler !== undefined && { requestHandler: this.requestHandler }),
|
||||||
|
...(credentials !== undefined && { credentials }),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
// Validates that the credentials the action will hand to subsequent steps actually work, and returns the resolved
|
||||||
|
// caller identity (account + ARN). "Work" is proven by a sts:GetCallerIdentity call, which both confirms the
|
||||||
|
// credentials are accepted by AWS and returns the identity for later checks and outputs to use.
|
||||||
public async validateCredentials(
|
public async validateCredentials(
|
||||||
|
credentials?: AwsCredentialIdentity,
|
||||||
expectedAccessKeyId?: string,
|
expectedAccessKeyId?: string,
|
||||||
roleChaining?: boolean,
|
roleChaining?: boolean,
|
||||||
expectedAccountIds?: string[],
|
): Promise<Awaited<ReturnType<typeof getCallerIdentity>>> {
|
||||||
) {
|
if (!credentials) {
|
||||||
let credentials: AwsCredentialIdentity;
|
let resolved: AwsCredentialIdentity;
|
||||||
try {
|
|
||||||
credentials = await this.loadCredentials();
|
|
||||||
if (!credentials.accessKeyId) {
|
|
||||||
throw new Error('Access key ID empty after loading credentials');
|
|
||||||
}
|
|
||||||
} catch (error) {
|
|
||||||
throw new Error(`Credentials could not be loaded, please check your action inputs: ${errorMessage(error)}`);
|
|
||||||
}
|
|
||||||
if (expectedAccountIds && expectedAccountIds.length > 0 && expectedAccountIds[0] !== '') {
|
|
||||||
let callerIdentity: Awaited<ReturnType<typeof getCallerIdentity>>;
|
|
||||||
try {
|
try {
|
||||||
callerIdentity = await getCallerIdentity(this.stsClient);
|
resolved = await this.loadCredentials();
|
||||||
|
if (!resolved.accessKeyId) {
|
||||||
|
throw new Error('Access key ID empty after loading credentials');
|
||||||
|
}
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
throw new Error(`Could not validate account ID of credentials: ${errorMessage(error)}`);
|
throw new Error(`Credentials could not be loaded, please check your action inputs: ${errorMessage(error)}`);
|
||||||
}
|
}
|
||||||
if (!callerIdentity.Account || !expectedAccountIds.includes(callerIdentity.Account)) {
|
if (!roleChaining && expectedAccessKeyId && expectedAccessKeyId !== resolved.accessKeyId) {
|
||||||
throw new Error(
|
|
||||||
`The account ID of the provided credentials (${
|
|
||||||
callerIdentity.Account ?? 'unknown'
|
|
||||||
}) does not match any of the expected account IDs: ${expectedAccountIds.join(', ')}`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!roleChaining) {
|
|
||||||
const actualAccessKeyId = credentials.accessKeyId;
|
|
||||||
if (expectedAccessKeyId && expectedAccessKeyId !== actualAccessKeyId) {
|
|
||||||
throw new Error(
|
throw new Error(
|
||||||
'Credentials loaded by the SDK do not match the expected access key ID configured by the action',
|
'Credentials loaded by the SDK do not match the expected access key ID configured by the action',
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const client = credentials ? this.createStsClient(credentials) : this.stsClient;
|
||||||
|
try {
|
||||||
|
return await getCallerIdentity(client);
|
||||||
|
} catch (error) {
|
||||||
|
throw new Error(`Credentials could not be loaded, please check your action inputs: ${errorMessage(error)}`);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
private async loadCredentials() {
|
private async loadCredentials() {
|
||||||
|
|||||||
+32
-3
@@ -3,6 +3,7 @@ import * as path from 'node:path';
|
|||||||
import * as core from '@actions/core';
|
import * as core from '@actions/core';
|
||||||
import type { Credentials, STSClient } from '@aws-sdk/client-sts';
|
import type { Credentials, STSClient } from '@aws-sdk/client-sts';
|
||||||
import { GetCallerIdentityCommand } from '@aws-sdk/client-sts';
|
import { GetCallerIdentityCommand } from '@aws-sdk/client-sts';
|
||||||
|
import type { AwsCredentialIdentity } from '@aws-sdk/types';
|
||||||
import type { UserAgent } from '@smithy/types';
|
import type { UserAgent } from '@smithy/types';
|
||||||
import type { CredentialsClient } from './CredentialsClient';
|
import type { CredentialsClient } from './CredentialsClient';
|
||||||
|
|
||||||
@@ -150,9 +151,8 @@ export async function getCallerIdentity(client: STSClient): Promise<{ Account: s
|
|||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Obtains account ID from STS Client and sets it as output
|
// Emits the account ID and ARN of an already-resolved caller identity as action outputs.
|
||||||
export async function exportAccountId(credentialsClient: CredentialsClient, maskAccountId?: boolean) {
|
export function exportAccountId(identity: { Account: string; Arn: string }, maskAccountId?: boolean) {
|
||||||
const identity = await getCallerIdentity(credentialsClient.stsClient);
|
|
||||||
const accountId = identity.Account;
|
const accountId = identity.Account;
|
||||||
const arn = identity.Arn;
|
const arn = identity.Arn;
|
||||||
if (maskAccountId) {
|
if (maskAccountId) {
|
||||||
@@ -164,6 +164,35 @@ export async function exportAccountId(credentialsClient: CredentialsClient, mask
|
|||||||
return accountId;
|
return accountId;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Validates that the account of the already-resolved caller identity is in the allow-list provided via the
|
||||||
|
// `allowed-account-ids` input.
|
||||||
|
export function validateAccountId(expectedAccountIds: string[] | undefined, account: string | undefined): void {
|
||||||
|
if (!expectedAccountIds || expectedAccountIds.length === 0 || expectedAccountIds[0] === '') {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
if (!account || !expectedAccountIds.includes(account)) {
|
||||||
|
throw new Error(
|
||||||
|
`The account ID of the provided credentials (${
|
||||||
|
account ?? 'unknown'
|
||||||
|
}) does not match any of the expected account IDs: ${expectedAccountIds.join(', ')}`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Converts the STS Credentials shape (returned by AssumeRole and provided as action inputs) into
|
||||||
|
// the AwsCredentialIdentity shape the SDK expects when credentials are supplied explicitly to a
|
||||||
|
// client. Returns undefined if the access key ID or secret access key is missing.
|
||||||
|
export function toCredentialIdentity(creds?: Partial<Credentials>): AwsCredentialIdentity | undefined {
|
||||||
|
if (!creds?.AccessKeyId || !creds.SecretAccessKey) {
|
||||||
|
return undefined;
|
||||||
|
}
|
||||||
|
return {
|
||||||
|
accessKeyId: creds.AccessKeyId,
|
||||||
|
secretAccessKey: creds.SecretAccessKey,
|
||||||
|
...(creds.SessionToken && { sessionToken: creds.SessionToken }),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
// Tags have a more restrictive set of acceptable characters than GitHub environment variables can.
|
// Tags have a more restrictive set of acceptable characters than GitHub environment variables can.
|
||||||
// This replaces anything not conforming to the tag restrictions by inverting the regular expression.
|
// This replaces anything not conforming to the tag restrictions by inverting the regular expression.
|
||||||
// See the AWS documentation for constraint specifics https://docs.aws.amazon.com/STS/latest/APIReference/API_Tag.html.
|
// See the AWS documentation for constraint specifics https://docs.aws.amazon.com/STS/latest/APIReference/API_Tag.html.
|
||||||
|
|||||||
+38
-44
@@ -10,8 +10,10 @@ import {
|
|||||||
exportRegion,
|
exportRegion,
|
||||||
getBooleanInput,
|
getBooleanInput,
|
||||||
retryAndBackoff,
|
retryAndBackoff,
|
||||||
|
toCredentialIdentity,
|
||||||
translateEnvVariables,
|
translateEnvVariables,
|
||||||
unsetCredentials,
|
unsetCredentials,
|
||||||
|
validateAccountId,
|
||||||
verifyKeys,
|
verifyKeys,
|
||||||
} from './helpers';
|
} from './helpers';
|
||||||
import { writeProfileFiles } from './profileManager';
|
import { writeProfileFiles } from './profileManager';
|
||||||
@@ -51,8 +53,8 @@ export async function run() {
|
|||||||
});
|
});
|
||||||
const roleChaining = getBooleanInput('role-chaining', { required: false });
|
const roleChaining = getBooleanInput('role-chaining', { required: false });
|
||||||
const outputCredentials = getBooleanInput('output-credentials', { required: false });
|
const outputCredentials = getBooleanInput('output-credentials', { required: false });
|
||||||
// Default to always outputting environment credentials unless profile is specified. If profile is specified, default to
|
// Default to always outputting environment credentials unless profile is specified. If profile is specified, default
|
||||||
// no environment credentials (but still output them if the user specifically requests it).
|
// to no environment credentials (but still output them if the user specifically requests it).
|
||||||
const outputEnvCredentials = getBooleanInput('output-env-credentials', { required: false, default: !awsProfile });
|
const outputEnvCredentials = getBooleanInput('output-env-credentials', { required: false, default: !awsProfile });
|
||||||
const unsetCurrentCredentials = getBooleanInput('unset-current-credentials', { required: false });
|
const unsetCurrentCredentials = getBooleanInput('unset-current-credentials', { required: false });
|
||||||
let disableRetry = getBooleanInput('disable-retry', { required: false });
|
let disableRetry = getBooleanInput('disable-retry', { required: false });
|
||||||
@@ -198,27 +200,38 @@ export async function run() {
|
|||||||
writeProfileFiles(awsProfile, { AccessKeyId, SecretAccessKey, SessionToken }, region, overwriteAwsProfile);
|
writeProfileFiles(awsProfile, { AccessKeyId, SecretAccessKey, SessionToken }, region, overwriteAwsProfile);
|
||||||
}
|
}
|
||||||
} else if (!webIdentityTokenFile && !roleChaining) {
|
} else if (!webIdentityTokenFile && !roleChaining) {
|
||||||
// Proceed only if credentials can be picked up
|
// Proceed only if credentials can be picked up. validateCredentials resolves the ambient
|
||||||
await withRetry(
|
// credentials via the SDK default chain, proves they work, and returns the caller identity.
|
||||||
() => credentialsClient.validateCredentials(undefined, roleChaining, expectedAccountIds),
|
const identity = await withRetry(
|
||||||
|
() => credentialsClient.validateCredentials(undefined, undefined, roleChaining),
|
||||||
'validateCredentials',
|
'validateCredentials',
|
||||||
);
|
);
|
||||||
sourceAccountId = await withRetry(() => exportAccountId(credentialsClient, maskAccountId), 'exportAccountId');
|
// Enforce the allowed-account-ids guardrail unless a role will be assumed, in which case the
|
||||||
|
// final account is validated after assumeRole (these ambient credentials are the source account).
|
||||||
|
if (!roleToAssume) {
|
||||||
|
validateAccountId(expectedAccountIds, identity.Account);
|
||||||
|
}
|
||||||
|
sourceAccountId = exportAccountId(identity, maskAccountId);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (AccessKeyId || roleChaining) {
|
if (AccessKeyId || roleChaining) {
|
||||||
// Validate that the SDK can actually pick up credentials.
|
// Validate that the credentials the action will use actually work, and resolve their identity.
|
||||||
// This validates cases where this action is using existing environment credentials,
|
const resolutionCredentials =
|
||||||
// and cases where the user intended to provide input credentials but the secrets inputs resolved to empty strings.
|
outputEnvCredentials || !AccessKeyId
|
||||||
// Skip when output-env-credentials is false: input IAM keys were not written to env, so
|
? undefined
|
||||||
// the default chain would resolve to ambient runner credentials and the access-key check
|
: toCredentialIdentity({ AccessKeyId, SecretAccessKey, SessionToken });
|
||||||
// would spuriously fail (see #1554).
|
const identity = await withRetry(
|
||||||
|
() => credentialsClient.validateCredentials(resolutionCredentials, AccessKeyId, roleChaining),
|
||||||
|
'validateCredentials',
|
||||||
|
);
|
||||||
|
// Enforce the allowed-account-ids guardrail unless a role will be assumed (the final account is
|
||||||
|
// validated after assumeRole; these are the source credentials).
|
||||||
|
if (!roleToAssume) {
|
||||||
|
validateAccountId(expectedAccountIds, identity.Account);
|
||||||
|
}
|
||||||
|
sourceAccountId = identity.Account;
|
||||||
if (outputEnvCredentials) {
|
if (outputEnvCredentials) {
|
||||||
await withRetry(
|
exportAccountId(identity, maskAccountId);
|
||||||
() => credentialsClient.validateCredentials(AccessKeyId, roleChaining, expectedAccountIds),
|
|
||||||
'validateCredentials',
|
|
||||||
);
|
|
||||||
sourceAccountId = await withRetry(() => exportAccountId(credentialsClient, maskAccountId), 'exportAccountId');
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if (customTags && (useGitHubOIDCProvider() || webIdentityTokenFile)) {
|
if (customTags && (useGitHubOIDCProvider() || webIdentityTokenFile)) {
|
||||||
@@ -252,24 +265,15 @@ export async function run() {
|
|||||||
} while (specialCharacterWorkaround && !verifyKeys(roleCredentials.Credentials));
|
} while (specialCharacterWorkaround && !verifyKeys(roleCredentials.Credentials));
|
||||||
core.info(`Authenticated as assumedRoleId ${roleCredentials.AssumedRoleUser?.AssumedRoleId}`);
|
core.info(`Authenticated as assumedRoleId ${roleCredentials.AssumedRoleUser?.AssumedRoleId}`);
|
||||||
exportCredentials(roleCredentials.Credentials, outputCredentials, outputEnvCredentials);
|
exportCredentials(roleCredentials.Credentials, outputCredentials, outputEnvCredentials);
|
||||||
// Validate that the SDK can pick up the assumed-role credentials from the environment.
|
// Validate the assumed-role credentials and resolve their identity.
|
||||||
// Skip when output-env-credentials is false: the credentials were never written to env,
|
const identity = await withRetry(
|
||||||
// so the default credential provider chain would resolve to ambient runner credentials
|
() => credentialsClient.validateCredentials(toCredentialIdentity(roleCredentials.Credentials)),
|
||||||
// (e.g. an EC2 instance profile) and the access-key-id check would spuriously fail.
|
'validateCredentials',
|
||||||
// Skip when using a profile: validation runs after the profile file is written below.
|
);
|
||||||
if ((!process.env.GITHUB_ACTIONS || AccessKeyId) && !awsProfile && outputEnvCredentials) {
|
// Enforce the allowed-account-ids guardrail against the assumed (final) account.
|
||||||
await withRetry(
|
validateAccountId(expectedAccountIds, identity.Account);
|
||||||
() =>
|
|
||||||
credentialsClient.validateCredentials(
|
|
||||||
roleCredentials.Credentials?.AccessKeyId,
|
|
||||||
roleChaining,
|
|
||||||
expectedAccountIds,
|
|
||||||
),
|
|
||||||
'validateCredentials',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (outputEnvCredentials) {
|
if (outputEnvCredentials) {
|
||||||
await withRetry(() => exportAccountId(credentialsClient, maskAccountId), 'exportAccountId');
|
exportAccountId(identity, maskAccountId);
|
||||||
}
|
}
|
||||||
|
|
||||||
// Write profile files if profile mode is enabled
|
// Write profile files if profile mode is enabled
|
||||||
@@ -279,18 +283,8 @@ export async function run() {
|
|||||||
}
|
}
|
||||||
// If user provided IAM User Credentials and then we assumed a role, overwrite the profile file to add
|
// If user provided IAM User Credentials and then we assumed a role, overwrite the profile file to add
|
||||||
// the session token. (this only overwrites the profile within a single run of the action).
|
// the session token. (this only overwrites the profile within a single run of the action).
|
||||||
// We then validate the credentials to make sure they work.
|
|
||||||
if (AccessKeyId || !process.env.GITHUB_ACTIONS) {
|
if (AccessKeyId || !process.env.GITHUB_ACTIONS) {
|
||||||
writeProfileFiles(awsProfile, roleCredentials.Credentials, region, true);
|
writeProfileFiles(awsProfile, roleCredentials.Credentials, region, true);
|
||||||
await withRetry(
|
|
||||||
() =>
|
|
||||||
credentialsClient.validateCredentials(
|
|
||||||
roleCredentials.Credentials?.AccessKeyId,
|
|
||||||
roleChaining,
|
|
||||||
expectedAccountIds,
|
|
||||||
),
|
|
||||||
'validateCredentials',
|
|
||||||
);
|
|
||||||
} else {
|
} else {
|
||||||
writeProfileFiles(awsProfile, roleCredentials.Credentials, region, overwriteAwsProfile);
|
writeProfileFiles(awsProfile, roleCredentials.Credentials, region, overwriteAwsProfile);
|
||||||
}
|
}
|
||||||
|
|||||||
+76
-5
@@ -618,6 +618,9 @@ describe('Configure AWS Credentials', {}, () => {
|
|||||||
});
|
});
|
||||||
it("doesn't export credentials as environment variables if told not to", {}, async () => {
|
it("doesn't export credentials as environment variables if told not to", {}, async () => {
|
||||||
mockedSTSClient.on(AssumeRoleWithWebIdentityCommand).resolvesOnce(mocks.outputs.STS_CREDENTIALS);
|
mockedSTSClient.on(AssumeRoleWithWebIdentityCommand).resolvesOnce(mocks.outputs.STS_CREDENTIALS);
|
||||||
|
// Credentials are validated (and their account resolved) even when not exported to the
|
||||||
|
// environment, so GetCallerIdentity is now called on the explicit assumed-role credentials.
|
||||||
|
mockedSTSClient.on(GetCallerIdentityCommand).resolves({ ...mocks.outputs.GET_CALLER_IDENTITY });
|
||||||
vi.mocked(core.getInput).mockImplementation(mocks.getInput(mocks.NO_ENV_CREDS_INPUTS));
|
vi.mocked(core.getInput).mockImplementation(mocks.getInput(mocks.NO_ENV_CREDS_INPUTS));
|
||||||
vi.mocked(core.getIDToken).mockResolvedValue('testoidctoken');
|
vi.mocked(core.getIDToken).mockResolvedValue('testoidctoken');
|
||||||
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = 'fake-token';
|
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = 'fake-token';
|
||||||
@@ -628,6 +631,7 @@ describe('Configure AWS Credentials', {}, () => {
|
|||||||
});
|
});
|
||||||
it('can export creds as step outputs without exporting as env variables', {}, async () => {
|
it('can export creds as step outputs without exporting as env variables', {}, async () => {
|
||||||
mockedSTSClient.on(AssumeRoleWithWebIdentityCommand).resolvesOnce(mocks.outputs.STS_CREDENTIALS);
|
mockedSTSClient.on(AssumeRoleWithWebIdentityCommand).resolvesOnce(mocks.outputs.STS_CREDENTIALS);
|
||||||
|
mockedSTSClient.on(GetCallerIdentityCommand).resolves({ ...mocks.outputs.GET_CALLER_IDENTITY });
|
||||||
vi.mocked(core.getInput).mockImplementation(mocks.getInput(mocks.STEP_BUT_NO_ENV_INPUTS));
|
vi.mocked(core.getInput).mockImplementation(mocks.getInput(mocks.STEP_BUT_NO_ENV_INPUTS));
|
||||||
vi.mocked(core.getIDToken).mockResolvedValue('testoidctoken');
|
vi.mocked(core.getIDToken).mockResolvedValue('testoidctoken');
|
||||||
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = 'fake-token';
|
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = 'fake-token';
|
||||||
@@ -897,6 +901,65 @@ describe('Configure AWS Credentials', {}, () => {
|
|||||||
expect(core.info).toHaveBeenCalledWith('Authenticated as assumedRoleId AROAFAKEASSUMEDROLEID');
|
expect(core.info).toHaveBeenCalledWith('Authenticated as assumedRoleId AROAFAKEASSUMEDROLEID');
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it('fails with OIDC when account ID does not match allowed list', async () => {
|
||||||
|
// Regression test for the allowed-account-ids bypass: in a real runner (GITHUB_ACTIONS=true)
|
||||||
|
// authenticating via OIDC, the account-ID guardrail was previously never enforced.
|
||||||
|
vi.mocked(core.getInput).mockImplementation(
|
||||||
|
mocks.getInput({
|
||||||
|
...mocks.GH_OIDC_INPUTS,
|
||||||
|
'allowed-account-ids': '999999999999',
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
vi.mocked(core.getIDToken).mockResolvedValue('testoidctoken');
|
||||||
|
mockedSTSClient.on(AssumeRoleWithWebIdentityCommand).resolves(mocks.outputs.STS_CREDENTIALS);
|
||||||
|
mockedSTSClient.on(GetCallerIdentityCommand).resolves({ ...mocks.outputs.GET_CALLER_IDENTITY });
|
||||||
|
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = 'fake-token';
|
||||||
|
|
||||||
|
await run();
|
||||||
|
expect(core.setFailed).toHaveBeenCalledWith(
|
||||||
|
'The account ID of the provided credentials (111111111111) does not match any of the expected account IDs: 999999999999',
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('fails with OIDC and output-env-credentials false when account ID does not match', async () => {
|
||||||
|
// The guardrail must hold even when credentials are never written to the environment.
|
||||||
|
vi.mocked(core.getInput).mockImplementation(
|
||||||
|
mocks.getInput({
|
||||||
|
...mocks.NO_ENV_CREDS_INPUTS,
|
||||||
|
'allowed-account-ids': '999999999999',
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
vi.mocked(core.getIDToken).mockResolvedValue('testoidctoken');
|
||||||
|
mockedSTSClient.on(AssumeRoleWithWebIdentityCommand).resolves(mocks.outputs.STS_CREDENTIALS);
|
||||||
|
mockedSTSClient.on(GetCallerIdentityCommand).resolves({ ...mocks.outputs.GET_CALLER_IDENTITY });
|
||||||
|
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = 'fake-token';
|
||||||
|
|
||||||
|
await run();
|
||||||
|
expect(core.setFailed).toHaveBeenCalledWith(
|
||||||
|
'The account ID of the provided credentials (111111111111) does not match any of the expected account IDs: 999999999999',
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('fails with assume role when assumed account ID does not match allowed list', async () => {
|
||||||
|
vi.mocked(core.getInput).mockImplementation(
|
||||||
|
mocks.getInput({
|
||||||
|
...mocks.IAM_ASSUMEROLE_INPUTS,
|
||||||
|
'allowed-account-ids': '999999999999',
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
mockedSTSClient.on(AssumeRoleCommand).resolves(mocks.outputs.STS_CREDENTIALS);
|
||||||
|
mockedSTSClient.on(GetCallerIdentityCommand).resolves({ ...mocks.outputs.GET_CALLER_IDENTITY });
|
||||||
|
// biome-ignore lint/suspicious/noExplicitAny: any required to mock private method
|
||||||
|
vi.spyOn(CredentialsClient.prototype as any, 'loadCredentials')
|
||||||
|
.mockResolvedValueOnce({ accessKeyId: 'MYAWSACCESSKEYID' })
|
||||||
|
.mockResolvedValueOnce({ accessKeyId: 'STSAWSACCESSKEYID' });
|
||||||
|
|
||||||
|
await run();
|
||||||
|
expect(core.setFailed).toHaveBeenCalledWith(
|
||||||
|
'The account ID of the provided credentials (111111111111) does not match any of the expected account IDs: 999999999999',
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
it('handles GetCallerIdentity API failure gracefully', async () => {
|
it('handles GetCallerIdentity API failure gracefully', async () => {
|
||||||
vi.mocked(core.getInput).mockImplementation(
|
vi.mocked(core.getInput).mockImplementation(
|
||||||
mocks.getInput({
|
mocks.getInput({
|
||||||
@@ -911,7 +974,11 @@ describe('Configure AWS Credentials', {}, () => {
|
|||||||
});
|
});
|
||||||
|
|
||||||
await run();
|
await run();
|
||||||
expect(core.setFailed).toHaveBeenCalledWith('Could not validate account ID of credentials: API Error');
|
// The account allow-list now reuses the single liveness GetCallerIdentity call, so an STS
|
||||||
|
// failure surfaces as a credential-loading failure rather than a dedicated account-check error.
|
||||||
|
expect(core.setFailed).toHaveBeenCalledWith(
|
||||||
|
'Credentials could not be loaded, please check your action inputs: API Error',
|
||||||
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
it('ignores validation when allowed-account-ids is empty', async () => {
|
it('ignores validation when allowed-account-ids is empty', async () => {
|
||||||
@@ -1373,7 +1440,7 @@ describe('Configure AWS Credentials', {}, () => {
|
|||||||
});
|
});
|
||||||
|
|
||||||
describe('Retry Behavior', {}, () => {
|
describe('Retry Behavior', {}, () => {
|
||||||
it('retries exportAccountId on transient GetCallerIdentity failure', async () => {
|
it('retries validateCredentials on transient GetCallerIdentity failure', async () => {
|
||||||
vi.mocked(core.getInput).mockImplementation(mocks.getInput(mocks.IAM_USER_INPUTS));
|
vi.mocked(core.getInput).mockImplementation(mocks.getInput(mocks.IAM_USER_INPUTS));
|
||||||
// biome-ignore lint/suspicious/noExplicitAny: any required to mock private method
|
// biome-ignore lint/suspicious/noExplicitAny: any required to mock private method
|
||||||
vi.spyOn(CredentialsClient.prototype as any, 'loadCredentials').mockResolvedValue({
|
vi.spyOn(CredentialsClient.prototype as any, 'loadCredentials').mockResolvedValue({
|
||||||
@@ -1384,7 +1451,9 @@ describe('Configure AWS Credentials', {}, () => {
|
|||||||
.rejectsOnce(new Error('throttled'))
|
.rejectsOnce(new Error('throttled'))
|
||||||
.resolves({ ...mocks.outputs.GET_CALLER_IDENTITY });
|
.resolves({ ...mocks.outputs.GET_CALLER_IDENTITY });
|
||||||
await run();
|
await run();
|
||||||
expect(core.info).toHaveBeenCalledWith(expect.stringContaining('Retry exportAccountId'));
|
// The single liveness GetCallerIdentity call lives in validateCredentials, so transient STS
|
||||||
|
// failures are retried under that label (the account ID is then resolved without a second call).
|
||||||
|
expect(core.info).toHaveBeenCalledWith(expect.stringContaining('Retry validateCredentials'));
|
||||||
expect(core.setFailed).not.toHaveBeenCalled();
|
expect(core.setFailed).not.toHaveBeenCalled();
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -1414,7 +1483,7 @@ describe('Configure AWS Credentials', {}, () => {
|
|||||||
expect(core.info).not.toHaveBeenCalledWith(expect.stringContaining('Retry'));
|
expect(core.info).not.toHaveBeenCalledWith(expect.stringContaining('Retry'));
|
||||||
});
|
});
|
||||||
|
|
||||||
it('retries exportAccountId after role assumption (issue #1681)', async () => {
|
it('retries the post-assume identity check on a transient invalid-token error (issue #1681)', async () => {
|
||||||
vi.mocked(core.getInput).mockImplementation(mocks.getInput(mocks.GH_OIDC_INPUTS));
|
vi.mocked(core.getInput).mockImplementation(mocks.getInput(mocks.GH_OIDC_INPUTS));
|
||||||
vi.mocked(core.getIDToken).mockResolvedValue('testoidctoken');
|
vi.mocked(core.getIDToken).mockResolvedValue('testoidctoken');
|
||||||
mockedSTSClient.on(AssumeRoleWithWebIdentityCommand).resolves(mocks.outputs.STS_CREDENTIALS);
|
mockedSTSClient.on(AssumeRoleWithWebIdentityCommand).resolves(mocks.outputs.STS_CREDENTIALS);
|
||||||
@@ -1424,7 +1493,9 @@ describe('Configure AWS Credentials', {}, () => {
|
|||||||
.resolves({ ...mocks.outputs.GET_CALLER_IDENTITY });
|
.resolves({ ...mocks.outputs.GET_CALLER_IDENTITY });
|
||||||
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = 'fake-token';
|
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = 'fake-token';
|
||||||
await run();
|
await run();
|
||||||
expect(core.info).toHaveBeenCalledWith(expect.stringContaining('Retry exportAccountId'));
|
// Freshly-assumed credentials can be briefly rejected by STS (eventual consistency). The
|
||||||
|
// liveness GetCallerIdentity now runs inside validateCredentials, so the retry happens there.
|
||||||
|
expect(core.info).toHaveBeenCalledWith(expect.stringContaining('Retry validateCredentials'));
|
||||||
expect(core.info).toHaveBeenCalledWith(
|
expect(core.info).toHaveBeenCalledWith(
|
||||||
expect.stringContaining('The security token included in the request is invalid'),
|
expect.stringContaining('The security token included in the request is invalid'),
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -50,7 +50,7 @@ describe('Profile Manager', {}, () => {
|
|||||||
|
|
||||||
it('guards against __proto__ section pollution', {}, () => {
|
it('guards against __proto__ section pollution', {}, () => {
|
||||||
const result = parseIni('[__proto__]\npolluted=true\n[safe]\nkey=val\n');
|
const result = parseIni('[__proto__]\npolluted=true\n[safe]\nkey=val\n');
|
||||||
expect(result.__proto__).not.toHaveProperty('polluted');
|
expect(Object.getPrototypeOf(result)).not.toHaveProperty('polluted');
|
||||||
expect(result.safe).toEqual({ key: 'val' });
|
expect(result.safe).toEqual({ key: 'val' });
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user