Skip to content

Commit a0c1927

Browse files
authored
fix: publish hardened workflow sync action
* fix: write multiline action outputs safely Signed-off-by: Vitor Mattos <vitor@php.rio> * test: cover multiline action outputs Signed-off-by: Vitor Mattos <vitor@php.rio> * fix: pin hardened workflow sync action Signed-off-by: Vitor Mattos <vitor@php.rio> * fix: pin hardened workflow sync action Signed-off-by: Vitor Mattos <vitor@php.rio> * test: cover single-line action outputs Signed-off-by: Vitor Mattos <vitor@php.rio> --------- Signed-off-by: Vitor Mattos <vitor@php.rio>
1 parent 9ab86c3 commit a0c1927

4 files changed

Lines changed: 37 additions & 4 deletions

File tree

‎actions/sync-workflows/sync.py‎

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -245,8 +245,14 @@ def render_summary(report: dict[str, object]) -> str:
245245

246246
def write_output(name: str, value: str) -> None:
247247
output = os.environ.get("GITHUB_OUTPUT")
248-
if output:
249-
with Path(output).open("a", encoding="utf-8") as handle:
248+
if not output:
249+
return
250+
251+
with Path(output).open("a", encoding="utf-8") as handle:
252+
if "\n" in value:
253+
delimiter = f"WORKFLOW_SYNC_{name.upper()}"
254+
handle.write(f"{name}<<{delimiter}\n{value}{delimiter}\n")
255+
else:
250256
handle.write(f"{name}={value}\n")
251257

252258

‎patches/nextcloud/sync-workflow-templates.yml.patch‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -113,7 +113,7 @@
113113
- echo "DRAFT_ONLY=${draft_only}" >> $GITHUB_ENV
114114
+ - name: Synchronize workflow templates
115115
+ id: sync
116-
+ uses: LibreCodeCoop/github-workflows/actions/sync-workflows@57e644fe4882e942ac19bbe99729b4b7e3c9014e
116+
+ uses: LibreCodeCoop/github-workflows/actions/sync-workflows@5006416b915ee2d0f10f6349b4762f588a899bcd
117117
+ with:
118118
+ source: source/workflow-templates
119119
+ target: target

‎tests/test_sync_workflows_action.py‎

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,9 +3,11 @@
33

44
import hashlib
55
import importlib.util
6+
import os
67
import tempfile
78
import unittest
89
from pathlib import Path
10+
from unittest.mock import patch
911

1012
MODULE_PATH = (
1113
Path(__file__).resolve().parents[1]
@@ -194,6 +196,31 @@ def test_broken_patch_sets_draft_signal_and_keeps_catalog_lock(self) -> None:
194196
sync_module.md5(source_file),
195197
)
196198

199+
def test_writes_single_line_github_output(self) -> None:
200+
with tempfile.TemporaryDirectory() as directory:
201+
output = Path(directory) / "output"
202+
with patch.dict(os.environ, {"GITHUB_OUTPUT": str(output)}):
203+
sync_module.write_output("changed", "true")
204+
205+
self.assertEqual(
206+
output.read_text(encoding="utf-8"),
207+
"changed=true\n",
208+
)
209+
210+
def test_writes_multiline_github_output(self) -> None:
211+
with tempfile.TemporaryDirectory() as directory:
212+
output = Path(directory) / "output"
213+
with patch.dict(os.environ, {"GITHUB_OUTPUT": str(output)}):
214+
sync_module.write_output("summary", "line one\nline two\n")
215+
216+
self.assertEqual(
217+
output.read_text(encoding="utf-8"),
218+
"summary<<WORKFLOW_SYNC_SUMMARY\n"
219+
"line one\n"
220+
"line two\n"
221+
"WORKFLOW_SYNC_SUMMARY\n",
222+
)
223+
197224
def test_mixed_result_summary_is_deterministic(self) -> None:
198225
summary = sync_module.render_summary(
199226
{

‎workflow-templates/sync-workflow-templates.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,7 +67,7 @@ jobs:
6767

6868
- name: Synchronize workflow templates
6969
id: sync
70-
uses: LibreCodeCoop/github-workflows/actions/sync-workflows@57e644fe4882e942ac19bbe99729b4b7e3c9014e
70+
uses: LibreCodeCoop/github-workflows/actions/sync-workflows@5006416b915ee2d0f10f6349b4762f588a899bcd
7171
with:
7272
source: source/workflow-templates
7373
target: target

0 commit comments

Comments
 (0)