adaeda2dc6
Round-2 review fixes for the GITHUB_OUTPUT helper and the release scripts
that emit through it.
emitGithubOutputs (scripts/release/lib/github-output.ts):
- Replace the key newline/CR check with a full GitHub-Actions-safe charset
check: /^[A-Za-z_][A-Za-z0-9_-]*$/. A key containing "=" or whitespace
would silently corrupt the key=value line; rejecting up-front is
strictly safer. Value validation (single-line) is unchanged — "=" in
values is legal because GitHub splits on the first "=".
- Update the docblock accordingly.
prerelease.ts:
- Remove the dead `?? getCurrentVersion(scope)` fallback. The empty-list
guard above makes packages[0] guaranteed, and the fallback would have
masked a package.json missing its version field by emitting a version
divergent from what the loop publishes. Fail loudly with an explicit
exit instead.
- Drop the now-unused getCurrentVersion import.
- Add a comment above the dry-run emitGithubOutputs call explaining that
emitting in dry-run is safe — the publish workflow gates publish + the
verify guard on inputs.dry-run != true, so the dry-run emission only
serves local/e2e contract verification.
publish-release.ts:
- Hoist getPackagesForScope + empty-list guard above the prerelease-suffix
and registry checks. A misconfigured scope now fails with the clear
"no packages found" error instead of a misleading "not greater than
published" one. Loop is unchanged.
github-output.test.ts:
- Loosen the key-newline assertion from the JSON.stringify-coupled
/bad\\nkey/ to the stable /alphanumeric/ phrase from the new message.
- Add tests: "=" in key throws, space in key throws, empty key throws,
and "=" in value is accepted and written verbatim (note=a=b).
- Move vi.restoreAllMocks() to the top of afterEach so spies cannot leak
into env restore + rmSync cleanup.
Call sites audited:
- emitGithubOutputs: only ever called with {version, scope} (prerelease,
publish-release) — all valid under the new charset.
- publishVersion derivation: only used inside prerelease.ts main().
- getCurrentVersion: still imported by publish-release.ts, bump-prerelease.ts,
prepare-release.ts; only the prerelease.ts import was removed.
- getPackagesForScope hoist in publish-release.ts: `packages` was only
read inside the publish loop below; nothing earlier depended on it.
37 lines
1.7 KiB
TypeScript
37 lines
1.7 KiB
TypeScript
import fs from "fs";
|
|
|
|
/**
|
|
* Append step outputs to the file GitHub Actions exposes via GITHUB_OUTPUT.
|
|
*
|
|
* The publish-release workflow's "Verify publish step emitted version" guard
|
|
* and the downstream summary/tag steps read `steps.publish.outputs.version`
|
|
* (and `scope`), so every publish script must emit these after publishing.
|
|
* No-op outside CI (GITHUB_OUTPUT unset), e.g. when running locally.
|
|
*
|
|
* Keys must match GitHub Actions' safe output-name shape
|
|
* (`/^[A-Za-z_][A-Za-z0-9_-]*$/`); values must be single-line (no newline or
|
|
* carriage return), since GITHUB_OUTPUT's `key=value` form splits on the first
|
|
* `=` and cannot carry newlines (multi-line values would need the heredoc
|
|
* form, which this helper deliberately does not support).
|
|
*/
|
|
export function emitGithubOutputs(outputs: Record<string, string>): void {
|
|
for (const [key, value] of Object.entries(outputs)) {
|
|
if (!/^[A-Za-z_][A-Za-z0-9_-]*$/.test(key)) {
|
|
throw new Error(
|
|
`emitGithubOutputs: key ${JSON.stringify(key)} is not a valid GitHub Actions output name; keys must be alphanumeric/underscore/dash and start with a letter or underscore.`,
|
|
);
|
|
}
|
|
if (/[\n\r]/.test(value)) {
|
|
throw new Error(
|
|
`emitGithubOutputs: value for key ${JSON.stringify(key)} contains a newline or carriage return; GITHUB_OUTPUT's key=value form cannot carry newlines (multi-line values would need the heredoc form, which this helper deliberately does not support).`,
|
|
);
|
|
}
|
|
}
|
|
const outputPath = process.env.GITHUB_OUTPUT;
|
|
if (!outputPath) return;
|
|
const lines = Object.entries(outputs)
|
|
.map(([key, value]) => `${key}=${value}\n`)
|
|
.join("");
|
|
fs.appendFileSync(outputPath, lines);
|
|
}
|