mirror of
https://github.com/actions/setup-node.git
synced 2026-07-28 12:43:02 +00:00
fix: update brace-expansion to address GHSA-3jxr-9vmj-r5cp and rebuild dist
- brace-expansion 1.1.13 → 1.1.16 (GHSA-3jxr-9vmj-r5cp patched floor: 1.1.16) - brace-expansion 2.1.1 → 2.1.2 (GHSA-3jxr-9vmj-r5cp patched floor: 2.1.2) - brace-expansion 5.0.6 → 5.0.8 (GHSA-3jxr-9vmj-r5cp patched floor: 5.0.7; also fixes GHSA-mh99-v99m-4gvg) - Regenerated package-lock.json - Rebuilt dist/setup/index.js and dist/cache-save/index.js with patched dependency Closes #1596
This commit is contained in:
committed by
GitHub
parent
964e93801c
commit
540e66a9b9
Vendored
+241
-170
@@ -5290,10 +5290,13 @@ function parseCommaParts(str) {
|
|||||||
return parts;
|
return parts;
|
||||||
}
|
}
|
||||||
|
|
||||||
function expandTop(str) {
|
function expandTop(str, options) {
|
||||||
if (!str)
|
if (!str)
|
||||||
return [];
|
return [];
|
||||||
|
|
||||||
|
options = options || {};
|
||||||
|
var max = options.max == null ? Infinity : options.max;
|
||||||
|
|
||||||
// I don't know why Bash 4.3 does this, but it does.
|
// I don't know why Bash 4.3 does this, but it does.
|
||||||
// Anything starting with {} will have the first two bytes preserved
|
// Anything starting with {} will have the first two bytes preserved
|
||||||
// but *only* at the top level, so {},a}b will not expand to anything,
|
// but *only* at the top level, so {},a}b will not expand to anything,
|
||||||
@@ -5304,7 +5307,7 @@ function expandTop(str) {
|
|||||||
str = '\\{\\}' + str.substr(2);
|
str = '\\{\\}' + str.substr(2);
|
||||||
}
|
}
|
||||||
|
|
||||||
return expand(escapeBraces(str), true).map(unescapeBraces);
|
return expand(escapeBraces(str), max, true).map(unescapeBraces);
|
||||||
}
|
}
|
||||||
|
|
||||||
function identity(e) {
|
function identity(e) {
|
||||||
@@ -5325,106 +5328,112 @@ function gte(i, y) {
|
|||||||
return i >= y;
|
return i >= y;
|
||||||
}
|
}
|
||||||
|
|
||||||
function expand(str, isTop) {
|
function expand(str, max, isTop) {
|
||||||
var expansions = [];
|
var expansions = [];
|
||||||
|
|
||||||
var m = balanced('{', '}', str);
|
// The `{a},b}` rewrite below restarts expansion on a rewritten string with
|
||||||
if (!m || /\$$/.test(m.pre)) return [str];
|
// the same `max` and `isTop = true`. Loop instead of recursing so a long run
|
||||||
|
// of non-expanding `{}` groups can't exhaust the call stack.
|
||||||
|
for (;;) {
|
||||||
|
var m = balanced('{', '}', str);
|
||||||
|
if (!m || /\$$/.test(m.pre)) return [str];
|
||||||
|
|
||||||
var isNumericSequence = /^-?\d+\.\.-?\d+(?:\.\.-?\d+)?$/.test(m.body);
|
var isNumericSequence = /^-?\d+\.\.-?\d+(?:\.\.-?\d+)?$/.test(m.body);
|
||||||
var isAlphaSequence = /^[a-zA-Z]\.\.[a-zA-Z](?:\.\.-?\d+)?$/.test(m.body);
|
var isAlphaSequence = /^[a-zA-Z]\.\.[a-zA-Z](?:\.\.-?\d+)?$/.test(m.body);
|
||||||
var isSequence = isNumericSequence || isAlphaSequence;
|
var isSequence = isNumericSequence || isAlphaSequence;
|
||||||
var isOptions = m.body.indexOf(',') >= 0;
|
var isOptions = m.body.indexOf(',') >= 0;
|
||||||
if (!isSequence && !isOptions) {
|
if (!isSequence && !isOptions) {
|
||||||
// {a},b}
|
// {a},b}
|
||||||
if (m.post.match(/,(?!,).*\}/)) {
|
if (m.post.match(/,(?!,).*\}/)) {
|
||||||
str = m.pre + '{' + m.body + escClose + m.post;
|
str = m.pre + '{' + m.body + escClose + m.post;
|
||||||
return expand(str);
|
isTop = true
|
||||||
}
|
continue
|
||||||
return [str];
|
|
||||||
}
|
|
||||||
|
|
||||||
var n;
|
|
||||||
if (isSequence) {
|
|
||||||
n = m.body.split(/\.\./);
|
|
||||||
} else {
|
|
||||||
n = parseCommaParts(m.body);
|
|
||||||
if (n.length === 1) {
|
|
||||||
// x{{a,b}}y ==> x{a}y x{b}y
|
|
||||||
n = expand(n[0], false).map(embrace);
|
|
||||||
if (n.length === 1) {
|
|
||||||
var post = m.post.length
|
|
||||||
? expand(m.post, false)
|
|
||||||
: [''];
|
|
||||||
return post.map(function(p) {
|
|
||||||
return m.pre + n[0] + p;
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
|
return [str];
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
// at this point, n is the parts, and we know it's not a comma set
|
var n;
|
||||||
// with a single entry.
|
if (isSequence) {
|
||||||
|
n = m.body.split(/\.\./);
|
||||||
// no need to expand pre, since it is guaranteed to be free of brace-sets
|
} else {
|
||||||
var pre = m.pre;
|
n = parseCommaParts(m.body);
|
||||||
var post = m.post.length
|
if (n.length === 1) {
|
||||||
? expand(m.post, false)
|
// x{{a,b}}y ==> x{a}y x{b}y
|
||||||
: [''];
|
n = expand(n[0], max, false).map(embrace);
|
||||||
|
if (n.length === 1) {
|
||||||
var N;
|
var post = m.post.length
|
||||||
|
? expand(m.post, max, false)
|
||||||
if (isSequence) {
|
: [''];
|
||||||
var x = numeric(n[0]);
|
return post.map(function(p) {
|
||||||
var y = numeric(n[1]);
|
return m.pre + n[0] + p;
|
||||||
var width = Math.max(n[0].length, n[1].length)
|
});
|
||||||
var incr = n.length == 3
|
|
||||||
? Math.max(Math.abs(numeric(n[2])), 1)
|
|
||||||
: 1;
|
|
||||||
var test = lte;
|
|
||||||
var reverse = y < x;
|
|
||||||
if (reverse) {
|
|
||||||
incr *= -1;
|
|
||||||
test = gte;
|
|
||||||
}
|
|
||||||
var pad = n.some(isPadded);
|
|
||||||
|
|
||||||
N = [];
|
|
||||||
|
|
||||||
for (var i = x; test(i, y); i += incr) {
|
|
||||||
var c;
|
|
||||||
if (isAlphaSequence) {
|
|
||||||
c = String.fromCharCode(i);
|
|
||||||
if (c === '\\')
|
|
||||||
c = '';
|
|
||||||
} else {
|
|
||||||
c = String(i);
|
|
||||||
if (pad) {
|
|
||||||
var need = width - c.length;
|
|
||||||
if (need > 0) {
|
|
||||||
var z = new Array(need + 1).join('0');
|
|
||||||
if (i < 0)
|
|
||||||
c = '-' + z + c.slice(1);
|
|
||||||
else
|
|
||||||
c = z + c;
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
N.push(c);
|
|
||||||
}
|
}
|
||||||
} else {
|
|
||||||
N = concatMap(n, function(el) { return expand(el, false) });
|
|
||||||
}
|
|
||||||
|
|
||||||
for (var j = 0; j < N.length; j++) {
|
// at this point, n is the parts, and we know it's not a comma set
|
||||||
for (var k = 0; k < post.length; k++) {
|
// with a single entry.
|
||||||
var expansion = pre + N[j] + post[k];
|
|
||||||
if (!isTop || isSequence || expansion)
|
// no need to expand pre, since it is guaranteed to be free of brace-sets
|
||||||
expansions.push(expansion);
|
var pre = m.pre;
|
||||||
|
var post = m.post.length
|
||||||
|
? expand(m.post, max, false)
|
||||||
|
: [''];
|
||||||
|
|
||||||
|
var N;
|
||||||
|
|
||||||
|
if (isSequence) {
|
||||||
|
var x = numeric(n[0]);
|
||||||
|
var y = numeric(n[1]);
|
||||||
|
var width = Math.max(n[0].length, n[1].length)
|
||||||
|
var incr = n.length == 3
|
||||||
|
? Math.max(Math.abs(numeric(n[2])), 1)
|
||||||
|
: 1;
|
||||||
|
var test = lte;
|
||||||
|
var reverse = y < x;
|
||||||
|
if (reverse) {
|
||||||
|
incr *= -1;
|
||||||
|
test = gte;
|
||||||
|
}
|
||||||
|
var pad = n.some(isPadded);
|
||||||
|
|
||||||
|
N = [];
|
||||||
|
|
||||||
|
for (var i = x; test(i, y) && N.length < max; i += incr) {
|
||||||
|
var c;
|
||||||
|
if (isAlphaSequence) {
|
||||||
|
c = String.fromCharCode(i);
|
||||||
|
if (c === '\\')
|
||||||
|
c = '';
|
||||||
|
} else {
|
||||||
|
c = String(i);
|
||||||
|
if (pad) {
|
||||||
|
var need = width - c.length;
|
||||||
|
if (need > 0) {
|
||||||
|
var z = new Array(need + 1).join('0');
|
||||||
|
if (i < 0)
|
||||||
|
c = '-' + z + c.slice(1);
|
||||||
|
else
|
||||||
|
c = z + c;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
N.push(c);
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
N = concatMap(n, function(el) { return expand(el, max, false) });
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
return expansions;
|
for (var j = 0; j < N.length; j++) {
|
||||||
|
for (var k = 0; k < post.length && expansions.length < max; k++) {
|
||||||
|
var expansion = pre + N[j] + post[k];
|
||||||
|
if (!isTop || isSequence || expansion)
|
||||||
|
expansions.push(expansion);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return expansions;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
@@ -89638,6 +89647,17 @@ const closePattern = /\\}/g;
|
|||||||
const commaPattern = /\\,/g;
|
const commaPattern = /\\,/g;
|
||||||
const periodPattern = /\\\./g;
|
const periodPattern = /\\\./g;
|
||||||
const EXPANSION_MAX = 100_000;
|
const EXPANSION_MAX = 100_000;
|
||||||
|
// `EXPANSION_MAX` caps the *number* of expansions, but not their length. An
|
||||||
|
// input like `'{a,b}'.repeat(1500)` stays under that count - its output is
|
||||||
|
// truncated to 100k results - while making every result ~1500 characters
|
||||||
|
// long. The result set, and the intermediate arrays built while combining
|
||||||
|
// brace sets, then grow large enough to exhaust memory and crash the process
|
||||||
|
// (CVE-2026-14257). `EXPANSION_MAX_LENGTH` bounds the total number of
|
||||||
|
// characters the accumulator may hold at any point, so memory stays flat no
|
||||||
|
// matter how many brace groups are chained. The limit sits well above any
|
||||||
|
// realistic expansion (100k results hitting `EXPANSION_MAX` measure ~1M
|
||||||
|
// characters) so legitimate input is unaffected.
|
||||||
|
const EXPANSION_MAX_LENGTH = 4_000_000;
|
||||||
function numeric(str) {
|
function numeric(str) {
|
||||||
return !isNaN(str) ? parseInt(str, 10) : str.charCodeAt(0);
|
return !isNaN(str) ? parseInt(str, 10) : str.charCodeAt(0);
|
||||||
}
|
}
|
||||||
@@ -89687,7 +89707,7 @@ function expand(str, options = {}) {
|
|||||||
if (!str) {
|
if (!str) {
|
||||||
return [];
|
return [];
|
||||||
}
|
}
|
||||||
const { max = EXPANSION_MAX } = options;
|
const { max = EXPANSION_MAX, maxLength = EXPANSION_MAX_LENGTH } = options;
|
||||||
// I don't know why Bash 4.3 does this, but it does.
|
// I don't know why Bash 4.3 does this, but it does.
|
||||||
// Anything starting with {} will have the first two bytes preserved
|
// Anything starting with {} will have the first two bytes preserved
|
||||||
// but *only* at the top level, so {},a}b will not expand to anything,
|
// but *only* at the top level, so {},a}b will not expand to anything,
|
||||||
@@ -89697,7 +89717,7 @@ function expand(str, options = {}) {
|
|||||||
if (str.slice(0, 2) === '{}') {
|
if (str.slice(0, 2) === '{}') {
|
||||||
str = '\\{\\}' + str.slice(2);
|
str = '\\{\\}' + str.slice(2);
|
||||||
}
|
}
|
||||||
return expand_(escapeBraces(str), max, true).map(unescapeBraces);
|
return expand_(escapeBraces(str), max, maxLength, true).map(unescapeBraces);
|
||||||
}
|
}
|
||||||
function embrace(str) {
|
function embrace(str) {
|
||||||
return '{' + str + '}';
|
return '{' + str + '}';
|
||||||
@@ -89711,22 +89731,113 @@ function lte(i, y) {
|
|||||||
function gte(i, y) {
|
function gte(i, y) {
|
||||||
return i >= y;
|
return i >= y;
|
||||||
}
|
}
|
||||||
function expand_(str, max, isTop) {
|
// Build `{ acc[a] + pre + values[v] }` for every combination, capping the
|
||||||
/** @type {string[]} */
|
// number of results at `max` and the total number of characters at `maxLength`.
|
||||||
const expansions = [];
|
// This is the one place output grows, so bounding it here keeps the single
|
||||||
const m = balanced('{', '}', str);
|
// accumulator - and therefore memory - flat regardless of how many brace groups
|
||||||
if (!m)
|
// are combined (CVE-2026-14257).
|
||||||
return [str];
|
function combine(acc, pre, values, max, maxLength, dropEmpties) {
|
||||||
// no need to expand pre, since it is guaranteed to be free of brace-sets
|
const out = [];
|
||||||
const pre = m.pre;
|
let length = 0;
|
||||||
const post = m.post.length ? expand_(m.post, max, false) : [''];
|
for (let a = 0; a < acc.length; a++) {
|
||||||
if (/\$$/.test(m.pre)) {
|
for (let v = 0; v < values.length; v++) {
|
||||||
for (let k = 0; k < post.length && k < max; k++) {
|
if (out.length >= max)
|
||||||
const expansion = pre + '{' + m.body + '}' + post[k];
|
return out;
|
||||||
expansions.push(expansion);
|
const expansion = acc[a] + pre + values[v];
|
||||||
|
// Bash drops empty results at the top level. Skip them before they count
|
||||||
|
// against `max`, so `max` bounds the number of *kept* results.
|
||||||
|
if (dropEmpties && !expansion)
|
||||||
|
continue;
|
||||||
|
if (length + expansion.length > maxLength)
|
||||||
|
return out;
|
||||||
|
out.push(expansion);
|
||||||
|
length += expansion.length;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
else {
|
return out;
|
||||||
|
}
|
||||||
|
// The expansion values of a single numeric (`1..5`) or alphabetic (`a..e..2`)
|
||||||
|
// sequence body.
|
||||||
|
function expandSequence(body, isAlphaSequence, max) {
|
||||||
|
const n = body.split(/\.\./);
|
||||||
|
const N = [];
|
||||||
|
// A sequence body always splits into two or three parts, but the compiler
|
||||||
|
// can't know that.
|
||||||
|
/* c8 ignore start */
|
||||||
|
if (n[0] === undefined || n[1] === undefined) {
|
||||||
|
return N;
|
||||||
|
}
|
||||||
|
/* c8 ignore stop */
|
||||||
|
const x = numeric(n[0]);
|
||||||
|
const y = numeric(n[1]);
|
||||||
|
const width = Math.max(n[0].length, n[1].length);
|
||||||
|
let incr = n.length === 3 && n[2] !== undefined ?
|
||||||
|
Math.max(Math.abs(numeric(n[2])), 1)
|
||||||
|
: 1;
|
||||||
|
let test = lte;
|
||||||
|
const reverse = y < x;
|
||||||
|
if (reverse) {
|
||||||
|
incr *= -1;
|
||||||
|
test = gte;
|
||||||
|
}
|
||||||
|
const pad = n.some(isPadded);
|
||||||
|
for (let i = x; test(i, y) && N.length < max; i += incr) {
|
||||||
|
let c;
|
||||||
|
if (isAlphaSequence) {
|
||||||
|
c = String.fromCharCode(i);
|
||||||
|
if (c === '\\') {
|
||||||
|
c = '';
|
||||||
|
}
|
||||||
|
}
|
||||||
|
else {
|
||||||
|
c = String(i);
|
||||||
|
if (pad) {
|
||||||
|
const need = width - c.length;
|
||||||
|
if (need > 0) {
|
||||||
|
const z = new Array(need + 1).join('0');
|
||||||
|
if (i < 0) {
|
||||||
|
c = '-' + z + c.slice(1);
|
||||||
|
}
|
||||||
|
else {
|
||||||
|
c = z + c;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
N.push(c);
|
||||||
|
}
|
||||||
|
return N;
|
||||||
|
}
|
||||||
|
function expand_(str, max, maxLength, isTop) {
|
||||||
|
// Consume the string's top-level brace groups left to right, threading a
|
||||||
|
// running set of combined prefixes (`acc`). Expanding the tail iteratively -
|
||||||
|
// rather than recursing on `m.post` once per group - keeps the native stack
|
||||||
|
// depth constant, so deeply chained input (`'{a,b}'.repeat(3000)`) can no
|
||||||
|
// longer overflow the stack, and leaves a single accumulator whose size
|
||||||
|
// `maxLength` bounds directly (CVE-2026-14257).
|
||||||
|
let acc = [''];
|
||||||
|
// Bash drops empty results, but only when the *first* top-level group is a
|
||||||
|
// comma set - a sequence like `{a..\}` may legitimately yield ''. The drop
|
||||||
|
// is on the final strings, so it is applied to whichever `combine` produces
|
||||||
|
// them (the one with no brace set left in the tail).
|
||||||
|
let dropEmpties = false;
|
||||||
|
let firstGroup = true;
|
||||||
|
for (;;) {
|
||||||
|
const m = balanced('{', '}', str);
|
||||||
|
// No brace set left: the rest of the string is literal.
|
||||||
|
if (!m) {
|
||||||
|
return combine(acc, str, [''], max, maxLength, dropEmpties);
|
||||||
|
}
|
||||||
|
// no need to expand pre, since it is guaranteed to be free of brace-sets
|
||||||
|
const pre = m.pre;
|
||||||
|
if (/\$$/.test(pre)) {
|
||||||
|
acc = combine(acc, pre + '{' + m.body + '}', [''], max, maxLength, dropEmpties && !m.post.length);
|
||||||
|
firstGroup = false;
|
||||||
|
if (!m.post.length)
|
||||||
|
break;
|
||||||
|
str = m.post;
|
||||||
|
continue;
|
||||||
|
}
|
||||||
const isNumericSequence = /^-?\d+\.\.-?\d+(?:\.\.-?\d+)?$/.test(m.body);
|
const isNumericSequence = /^-?\d+\.\.-?\d+(?:\.\.-?\d+)?$/.test(m.body);
|
||||||
const isAlphaSequence = /^[a-zA-Z]\.\.[a-zA-Z](?:\.\.-?\d+)?$/.test(m.body);
|
const isAlphaSequence = /^[a-zA-Z]\.\.[a-zA-Z](?:\.\.-?\d+)?$/.test(m.body);
|
||||||
const isSequence = isNumericSequence || isAlphaSequence;
|
const isSequence = isNumericSequence || isAlphaSequence;
|
||||||
@@ -89735,87 +89846,47 @@ function expand_(str, max, isTop) {
|
|||||||
// {a},b}
|
// {a},b}
|
||||||
if (m.post.match(/,(?!,).*\}/)) {
|
if (m.post.match(/,(?!,).*\}/)) {
|
||||||
str = m.pre + '{' + m.body + escClose + m.post;
|
str = m.pre + '{' + m.body + escClose + m.post;
|
||||||
return expand_(str, max, true);
|
isTop = true;
|
||||||
|
continue;
|
||||||
}
|
}
|
||||||
return [str];
|
// Nothing here expands, so the whole remaining string is literal.
|
||||||
|
return combine(acc, pre + '{' + m.body + '}' + m.post, [''], max, maxLength, dropEmpties);
|
||||||
}
|
}
|
||||||
let n;
|
if (firstGroup) {
|
||||||
|
dropEmpties = isTop && !isSequence;
|
||||||
|
firstGroup = false;
|
||||||
|
}
|
||||||
|
let values;
|
||||||
if (isSequence) {
|
if (isSequence) {
|
||||||
n = m.body.split(/\.\./);
|
values = expandSequence(m.body, isAlphaSequence, max);
|
||||||
}
|
}
|
||||||
else {
|
else {
|
||||||
n = parseCommaParts(m.body);
|
let n = parseCommaParts(m.body);
|
||||||
if (n.length === 1 && n[0] !== undefined) {
|
if (n.length === 1 && n[0] !== undefined) {
|
||||||
// x{{a,b}}y ==> x{a}y x{b}y
|
// x{{a,b}}y ==> x{a}y x{b}y
|
||||||
n = expand_(n[0], max, false).map(embrace);
|
n = expand_(n[0], max, maxLength, false).map(embrace);
|
||||||
//XXX is this necessary? Can't seem to hit it in tests.
|
//XXX is this necessary? Can't seem to hit it in tests.
|
||||||
/* c8 ignore start */
|
/* c8 ignore start */
|
||||||
if (n.length === 1) {
|
if (n.length === 1) {
|
||||||
return post.map(p => m.pre + n[0] + p);
|
acc = combine(acc, pre + n[0], [''], max, maxLength, dropEmpties && !m.post.length);
|
||||||
|
if (!m.post.length)
|
||||||
|
break;
|
||||||
|
str = m.post;
|
||||||
|
continue;
|
||||||
}
|
}
|
||||||
/* c8 ignore stop */
|
/* c8 ignore stop */
|
||||||
}
|
}
|
||||||
}
|
values = [];
|
||||||
// at this point, n is the parts, and we know it's not a comma set
|
|
||||||
// with a single entry.
|
|
||||||
let N;
|
|
||||||
if (isSequence && n[0] !== undefined && n[1] !== undefined) {
|
|
||||||
const x = numeric(n[0]);
|
|
||||||
const y = numeric(n[1]);
|
|
||||||
const width = Math.max(n[0].length, n[1].length);
|
|
||||||
let incr = n.length === 3 && n[2] !== undefined ?
|
|
||||||
Math.max(Math.abs(numeric(n[2])), 1)
|
|
||||||
: 1;
|
|
||||||
let test = lte;
|
|
||||||
const reverse = y < x;
|
|
||||||
if (reverse) {
|
|
||||||
incr *= -1;
|
|
||||||
test = gte;
|
|
||||||
}
|
|
||||||
const pad = n.some(isPadded);
|
|
||||||
N = [];
|
|
||||||
for (let i = x; test(i, y) && N.length < max; i += incr) {
|
|
||||||
let c;
|
|
||||||
if (isAlphaSequence) {
|
|
||||||
c = String.fromCharCode(i);
|
|
||||||
if (c === '\\') {
|
|
||||||
c = '';
|
|
||||||
}
|
|
||||||
}
|
|
||||||
else {
|
|
||||||
c = String(i);
|
|
||||||
if (pad) {
|
|
||||||
const need = width - c.length;
|
|
||||||
if (need > 0) {
|
|
||||||
const z = new Array(need + 1).join('0');
|
|
||||||
if (i < 0) {
|
|
||||||
c = '-' + z + c.slice(1);
|
|
||||||
}
|
|
||||||
else {
|
|
||||||
c = z + c;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
N.push(c);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
else {
|
|
||||||
N = [];
|
|
||||||
for (let j = 0; j < n.length; j++) {
|
for (let j = 0; j < n.length; j++) {
|
||||||
N.push.apply(N, expand_(n[j], max, false));
|
values.push.apply(values, expand_(n[j], max, maxLength, false));
|
||||||
}
|
|
||||||
}
|
|
||||||
for (let j = 0; j < N.length; j++) {
|
|
||||||
for (let k = 0; k < post.length && expansions.length < max; k++) {
|
|
||||||
const expansion = pre + N[j] + post[k];
|
|
||||||
if (!isTop || isSequence || expansion) {
|
|
||||||
expansions.push(expansion);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
acc = combine(acc, pre, values, max, maxLength, dropEmpties && !m.post.length);
|
||||||
|
if (!m.post.length)
|
||||||
|
break;
|
||||||
|
str = m.post;
|
||||||
}
|
}
|
||||||
return expansions;
|
return acc;
|
||||||
}
|
}
|
||||||
//# sourceMappingURL=index.js.map
|
//# sourceMappingURL=index.js.map
|
||||||
;// CONCATENATED MODULE: ./node_modules/@actions/glob/node_modules/minimatch/dist/esm/assert-valid-pattern.js
|
;// CONCATENATED MODULE: ./node_modules/@actions/glob/node_modules/minimatch/dist/esm/assert-valid-pattern.js
|
||||||
|
|||||||
Vendored
+241
-170
@@ -6133,10 +6133,13 @@ function parseCommaParts(str) {
|
|||||||
return parts;
|
return parts;
|
||||||
}
|
}
|
||||||
|
|
||||||
function expandTop(str) {
|
function expandTop(str, options) {
|
||||||
if (!str)
|
if (!str)
|
||||||
return [];
|
return [];
|
||||||
|
|
||||||
|
options = options || {};
|
||||||
|
var max = options.max == null ? Infinity : options.max;
|
||||||
|
|
||||||
// I don't know why Bash 4.3 does this, but it does.
|
// I don't know why Bash 4.3 does this, but it does.
|
||||||
// Anything starting with {} will have the first two bytes preserved
|
// Anything starting with {} will have the first two bytes preserved
|
||||||
// but *only* at the top level, so {},a}b will not expand to anything,
|
// but *only* at the top level, so {},a}b will not expand to anything,
|
||||||
@@ -6147,7 +6150,7 @@ function expandTop(str) {
|
|||||||
str = '\\{\\}' + str.substr(2);
|
str = '\\{\\}' + str.substr(2);
|
||||||
}
|
}
|
||||||
|
|
||||||
return expand(escapeBraces(str), true).map(unescapeBraces);
|
return expand(escapeBraces(str), max, true).map(unescapeBraces);
|
||||||
}
|
}
|
||||||
|
|
||||||
function identity(e) {
|
function identity(e) {
|
||||||
@@ -6168,106 +6171,112 @@ function gte(i, y) {
|
|||||||
return i >= y;
|
return i >= y;
|
||||||
}
|
}
|
||||||
|
|
||||||
function expand(str, isTop) {
|
function expand(str, max, isTop) {
|
||||||
var expansions = [];
|
var expansions = [];
|
||||||
|
|
||||||
var m = balanced('{', '}', str);
|
// The `{a},b}` rewrite below restarts expansion on a rewritten string with
|
||||||
if (!m || /\$$/.test(m.pre)) return [str];
|
// the same `max` and `isTop = true`. Loop instead of recursing so a long run
|
||||||
|
// of non-expanding `{}` groups can't exhaust the call stack.
|
||||||
|
for (;;) {
|
||||||
|
var m = balanced('{', '}', str);
|
||||||
|
if (!m || /\$$/.test(m.pre)) return [str];
|
||||||
|
|
||||||
var isNumericSequence = /^-?\d+\.\.-?\d+(?:\.\.-?\d+)?$/.test(m.body);
|
var isNumericSequence = /^-?\d+\.\.-?\d+(?:\.\.-?\d+)?$/.test(m.body);
|
||||||
var isAlphaSequence = /^[a-zA-Z]\.\.[a-zA-Z](?:\.\.-?\d+)?$/.test(m.body);
|
var isAlphaSequence = /^[a-zA-Z]\.\.[a-zA-Z](?:\.\.-?\d+)?$/.test(m.body);
|
||||||
var isSequence = isNumericSequence || isAlphaSequence;
|
var isSequence = isNumericSequence || isAlphaSequence;
|
||||||
var isOptions = m.body.indexOf(',') >= 0;
|
var isOptions = m.body.indexOf(',') >= 0;
|
||||||
if (!isSequence && !isOptions) {
|
if (!isSequence && !isOptions) {
|
||||||
// {a},b}
|
// {a},b}
|
||||||
if (m.post.match(/,(?!,).*\}/)) {
|
if (m.post.match(/,(?!,).*\}/)) {
|
||||||
str = m.pre + '{' + m.body + escClose + m.post;
|
str = m.pre + '{' + m.body + escClose + m.post;
|
||||||
return expand(str);
|
isTop = true
|
||||||
}
|
continue
|
||||||
return [str];
|
|
||||||
}
|
|
||||||
|
|
||||||
var n;
|
|
||||||
if (isSequence) {
|
|
||||||
n = m.body.split(/\.\./);
|
|
||||||
} else {
|
|
||||||
n = parseCommaParts(m.body);
|
|
||||||
if (n.length === 1) {
|
|
||||||
// x{{a,b}}y ==> x{a}y x{b}y
|
|
||||||
n = expand(n[0], false).map(embrace);
|
|
||||||
if (n.length === 1) {
|
|
||||||
var post = m.post.length
|
|
||||||
? expand(m.post, false)
|
|
||||||
: [''];
|
|
||||||
return post.map(function(p) {
|
|
||||||
return m.pre + n[0] + p;
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
|
return [str];
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
// at this point, n is the parts, and we know it's not a comma set
|
var n;
|
||||||
// with a single entry.
|
if (isSequence) {
|
||||||
|
n = m.body.split(/\.\./);
|
||||||
// no need to expand pre, since it is guaranteed to be free of brace-sets
|
} else {
|
||||||
var pre = m.pre;
|
n = parseCommaParts(m.body);
|
||||||
var post = m.post.length
|
if (n.length === 1) {
|
||||||
? expand(m.post, false)
|
// x{{a,b}}y ==> x{a}y x{b}y
|
||||||
: [''];
|
n = expand(n[0], max, false).map(embrace);
|
||||||
|
if (n.length === 1) {
|
||||||
var N;
|
var post = m.post.length
|
||||||
|
? expand(m.post, max, false)
|
||||||
if (isSequence) {
|
: [''];
|
||||||
var x = numeric(n[0]);
|
return post.map(function(p) {
|
||||||
var y = numeric(n[1]);
|
return m.pre + n[0] + p;
|
||||||
var width = Math.max(n[0].length, n[1].length)
|
});
|
||||||
var incr = n.length == 3
|
|
||||||
? Math.max(Math.abs(numeric(n[2])), 1)
|
|
||||||
: 1;
|
|
||||||
var test = lte;
|
|
||||||
var reverse = y < x;
|
|
||||||
if (reverse) {
|
|
||||||
incr *= -1;
|
|
||||||
test = gte;
|
|
||||||
}
|
|
||||||
var pad = n.some(isPadded);
|
|
||||||
|
|
||||||
N = [];
|
|
||||||
|
|
||||||
for (var i = x; test(i, y); i += incr) {
|
|
||||||
var c;
|
|
||||||
if (isAlphaSequence) {
|
|
||||||
c = String.fromCharCode(i);
|
|
||||||
if (c === '\\')
|
|
||||||
c = '';
|
|
||||||
} else {
|
|
||||||
c = String(i);
|
|
||||||
if (pad) {
|
|
||||||
var need = width - c.length;
|
|
||||||
if (need > 0) {
|
|
||||||
var z = new Array(need + 1).join('0');
|
|
||||||
if (i < 0)
|
|
||||||
c = '-' + z + c.slice(1);
|
|
||||||
else
|
|
||||||
c = z + c;
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
N.push(c);
|
|
||||||
}
|
}
|
||||||
} else {
|
|
||||||
N = concatMap(n, function(el) { return expand(el, false) });
|
|
||||||
}
|
|
||||||
|
|
||||||
for (var j = 0; j < N.length; j++) {
|
// at this point, n is the parts, and we know it's not a comma set
|
||||||
for (var k = 0; k < post.length; k++) {
|
// with a single entry.
|
||||||
var expansion = pre + N[j] + post[k];
|
|
||||||
if (!isTop || isSequence || expansion)
|
// no need to expand pre, since it is guaranteed to be free of brace-sets
|
||||||
expansions.push(expansion);
|
var pre = m.pre;
|
||||||
|
var post = m.post.length
|
||||||
|
? expand(m.post, max, false)
|
||||||
|
: [''];
|
||||||
|
|
||||||
|
var N;
|
||||||
|
|
||||||
|
if (isSequence) {
|
||||||
|
var x = numeric(n[0]);
|
||||||
|
var y = numeric(n[1]);
|
||||||
|
var width = Math.max(n[0].length, n[1].length)
|
||||||
|
var incr = n.length == 3
|
||||||
|
? Math.max(Math.abs(numeric(n[2])), 1)
|
||||||
|
: 1;
|
||||||
|
var test = lte;
|
||||||
|
var reverse = y < x;
|
||||||
|
if (reverse) {
|
||||||
|
incr *= -1;
|
||||||
|
test = gte;
|
||||||
|
}
|
||||||
|
var pad = n.some(isPadded);
|
||||||
|
|
||||||
|
N = [];
|
||||||
|
|
||||||
|
for (var i = x; test(i, y) && N.length < max; i += incr) {
|
||||||
|
var c;
|
||||||
|
if (isAlphaSequence) {
|
||||||
|
c = String.fromCharCode(i);
|
||||||
|
if (c === '\\')
|
||||||
|
c = '';
|
||||||
|
} else {
|
||||||
|
c = String(i);
|
||||||
|
if (pad) {
|
||||||
|
var need = width - c.length;
|
||||||
|
if (need > 0) {
|
||||||
|
var z = new Array(need + 1).join('0');
|
||||||
|
if (i < 0)
|
||||||
|
c = '-' + z + c.slice(1);
|
||||||
|
else
|
||||||
|
c = z + c;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
N.push(c);
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
N = concatMap(n, function(el) { return expand(el, max, false) });
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
return expansions;
|
for (var j = 0; j < N.length; j++) {
|
||||||
|
for (var k = 0; k < post.length && expansions.length < max; k++) {
|
||||||
|
var expansion = pre + N[j] + post[k];
|
||||||
|
if (!isTop || isSequence || expansion)
|
||||||
|
expansions.push(expansion);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return expansions;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
@@ -95006,6 +95015,17 @@ const closePattern = /\\}/g;
|
|||||||
const commaPattern = /\\,/g;
|
const commaPattern = /\\,/g;
|
||||||
const periodPattern = /\\\./g;
|
const periodPattern = /\\\./g;
|
||||||
const EXPANSION_MAX = 100_000;
|
const EXPANSION_MAX = 100_000;
|
||||||
|
// `EXPANSION_MAX` caps the *number* of expansions, but not their length. An
|
||||||
|
// input like `'{a,b}'.repeat(1500)` stays under that count - its output is
|
||||||
|
// truncated to 100k results - while making every result ~1500 characters
|
||||||
|
// long. The result set, and the intermediate arrays built while combining
|
||||||
|
// brace sets, then grow large enough to exhaust memory and crash the process
|
||||||
|
// (CVE-2026-14257). `EXPANSION_MAX_LENGTH` bounds the total number of
|
||||||
|
// characters the accumulator may hold at any point, so memory stays flat no
|
||||||
|
// matter how many brace groups are chained. The limit sits well above any
|
||||||
|
// realistic expansion (100k results hitting `EXPANSION_MAX` measure ~1M
|
||||||
|
// characters) so legitimate input is unaffected.
|
||||||
|
const EXPANSION_MAX_LENGTH = 4_000_000;
|
||||||
function numeric(str) {
|
function numeric(str) {
|
||||||
return !isNaN(str) ? parseInt(str, 10) : str.charCodeAt(0);
|
return !isNaN(str) ? parseInt(str, 10) : str.charCodeAt(0);
|
||||||
}
|
}
|
||||||
@@ -95055,7 +95075,7 @@ function esm_expand(str, options = {}) {
|
|||||||
if (!str) {
|
if (!str) {
|
||||||
return [];
|
return [];
|
||||||
}
|
}
|
||||||
const { max = EXPANSION_MAX } = options;
|
const { max = EXPANSION_MAX, maxLength = EXPANSION_MAX_LENGTH } = options;
|
||||||
// I don't know why Bash 4.3 does this, but it does.
|
// I don't know why Bash 4.3 does this, but it does.
|
||||||
// Anything starting with {} will have the first two bytes preserved
|
// Anything starting with {} will have the first two bytes preserved
|
||||||
// but *only* at the top level, so {},a}b will not expand to anything,
|
// but *only* at the top level, so {},a}b will not expand to anything,
|
||||||
@@ -95065,7 +95085,7 @@ function esm_expand(str, options = {}) {
|
|||||||
if (str.slice(0, 2) === '{}') {
|
if (str.slice(0, 2) === '{}') {
|
||||||
str = '\\{\\}' + str.slice(2);
|
str = '\\{\\}' + str.slice(2);
|
||||||
}
|
}
|
||||||
return expand_(escapeBraces(str), max, true).map(unescapeBraces);
|
return expand_(escapeBraces(str), max, maxLength, true).map(unescapeBraces);
|
||||||
}
|
}
|
||||||
function embrace(str) {
|
function embrace(str) {
|
||||||
return '{' + str + '}';
|
return '{' + str + '}';
|
||||||
@@ -95079,22 +95099,113 @@ function lte(i, y) {
|
|||||||
function gte(i, y) {
|
function gte(i, y) {
|
||||||
return i >= y;
|
return i >= y;
|
||||||
}
|
}
|
||||||
function expand_(str, max, isTop) {
|
// Build `{ acc[a] + pre + values[v] }` for every combination, capping the
|
||||||
/** @type {string[]} */
|
// number of results at `max` and the total number of characters at `maxLength`.
|
||||||
const expansions = [];
|
// This is the one place output grows, so bounding it here keeps the single
|
||||||
const m = balanced('{', '}', str);
|
// accumulator - and therefore memory - flat regardless of how many brace groups
|
||||||
if (!m)
|
// are combined (CVE-2026-14257).
|
||||||
return [str];
|
function combine(acc, pre, values, max, maxLength, dropEmpties) {
|
||||||
// no need to expand pre, since it is guaranteed to be free of brace-sets
|
const out = [];
|
||||||
const pre = m.pre;
|
let length = 0;
|
||||||
const post = m.post.length ? expand_(m.post, max, false) : [''];
|
for (let a = 0; a < acc.length; a++) {
|
||||||
if (/\$$/.test(m.pre)) {
|
for (let v = 0; v < values.length; v++) {
|
||||||
for (let k = 0; k < post.length && k < max; k++) {
|
if (out.length >= max)
|
||||||
const expansion = pre + '{' + m.body + '}' + post[k];
|
return out;
|
||||||
expansions.push(expansion);
|
const expansion = acc[a] + pre + values[v];
|
||||||
|
// Bash drops empty results at the top level. Skip them before they count
|
||||||
|
// against `max`, so `max` bounds the number of *kept* results.
|
||||||
|
if (dropEmpties && !expansion)
|
||||||
|
continue;
|
||||||
|
if (length + expansion.length > maxLength)
|
||||||
|
return out;
|
||||||
|
out.push(expansion);
|
||||||
|
length += expansion.length;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
else {
|
return out;
|
||||||
|
}
|
||||||
|
// The expansion values of a single numeric (`1..5`) or alphabetic (`a..e..2`)
|
||||||
|
// sequence body.
|
||||||
|
function expandSequence(body, isAlphaSequence, max) {
|
||||||
|
const n = body.split(/\.\./);
|
||||||
|
const N = [];
|
||||||
|
// A sequence body always splits into two or three parts, but the compiler
|
||||||
|
// can't know that.
|
||||||
|
/* c8 ignore start */
|
||||||
|
if (n[0] === undefined || n[1] === undefined) {
|
||||||
|
return N;
|
||||||
|
}
|
||||||
|
/* c8 ignore stop */
|
||||||
|
const x = numeric(n[0]);
|
||||||
|
const y = numeric(n[1]);
|
||||||
|
const width = Math.max(n[0].length, n[1].length);
|
||||||
|
let incr = n.length === 3 && n[2] !== undefined ?
|
||||||
|
Math.max(Math.abs(numeric(n[2])), 1)
|
||||||
|
: 1;
|
||||||
|
let test = lte;
|
||||||
|
const reverse = y < x;
|
||||||
|
if (reverse) {
|
||||||
|
incr *= -1;
|
||||||
|
test = gte;
|
||||||
|
}
|
||||||
|
const pad = n.some(isPadded);
|
||||||
|
for (let i = x; test(i, y) && N.length < max; i += incr) {
|
||||||
|
let c;
|
||||||
|
if (isAlphaSequence) {
|
||||||
|
c = String.fromCharCode(i);
|
||||||
|
if (c === '\\') {
|
||||||
|
c = '';
|
||||||
|
}
|
||||||
|
}
|
||||||
|
else {
|
||||||
|
c = String(i);
|
||||||
|
if (pad) {
|
||||||
|
const need = width - c.length;
|
||||||
|
if (need > 0) {
|
||||||
|
const z = new Array(need + 1).join('0');
|
||||||
|
if (i < 0) {
|
||||||
|
c = '-' + z + c.slice(1);
|
||||||
|
}
|
||||||
|
else {
|
||||||
|
c = z + c;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
N.push(c);
|
||||||
|
}
|
||||||
|
return N;
|
||||||
|
}
|
||||||
|
function expand_(str, max, maxLength, isTop) {
|
||||||
|
// Consume the string's top-level brace groups left to right, threading a
|
||||||
|
// running set of combined prefixes (`acc`). Expanding the tail iteratively -
|
||||||
|
// rather than recursing on `m.post` once per group - keeps the native stack
|
||||||
|
// depth constant, so deeply chained input (`'{a,b}'.repeat(3000)`) can no
|
||||||
|
// longer overflow the stack, and leaves a single accumulator whose size
|
||||||
|
// `maxLength` bounds directly (CVE-2026-14257).
|
||||||
|
let acc = [''];
|
||||||
|
// Bash drops empty results, but only when the *first* top-level group is a
|
||||||
|
// comma set - a sequence like `{a..\}` may legitimately yield ''. The drop
|
||||||
|
// is on the final strings, so it is applied to whichever `combine` produces
|
||||||
|
// them (the one with no brace set left in the tail).
|
||||||
|
let dropEmpties = false;
|
||||||
|
let firstGroup = true;
|
||||||
|
for (;;) {
|
||||||
|
const m = balanced('{', '}', str);
|
||||||
|
// No brace set left: the rest of the string is literal.
|
||||||
|
if (!m) {
|
||||||
|
return combine(acc, str, [''], max, maxLength, dropEmpties);
|
||||||
|
}
|
||||||
|
// no need to expand pre, since it is guaranteed to be free of brace-sets
|
||||||
|
const pre = m.pre;
|
||||||
|
if (/\$$/.test(pre)) {
|
||||||
|
acc = combine(acc, pre + '{' + m.body + '}', [''], max, maxLength, dropEmpties && !m.post.length);
|
||||||
|
firstGroup = false;
|
||||||
|
if (!m.post.length)
|
||||||
|
break;
|
||||||
|
str = m.post;
|
||||||
|
continue;
|
||||||
|
}
|
||||||
const isNumericSequence = /^-?\d+\.\.-?\d+(?:\.\.-?\d+)?$/.test(m.body);
|
const isNumericSequence = /^-?\d+\.\.-?\d+(?:\.\.-?\d+)?$/.test(m.body);
|
||||||
const isAlphaSequence = /^[a-zA-Z]\.\.[a-zA-Z](?:\.\.-?\d+)?$/.test(m.body);
|
const isAlphaSequence = /^[a-zA-Z]\.\.[a-zA-Z](?:\.\.-?\d+)?$/.test(m.body);
|
||||||
const isSequence = isNumericSequence || isAlphaSequence;
|
const isSequence = isNumericSequence || isAlphaSequence;
|
||||||
@@ -95103,87 +95214,47 @@ function expand_(str, max, isTop) {
|
|||||||
// {a},b}
|
// {a},b}
|
||||||
if (m.post.match(/,(?!,).*\}/)) {
|
if (m.post.match(/,(?!,).*\}/)) {
|
||||||
str = m.pre + '{' + m.body + escClose + m.post;
|
str = m.pre + '{' + m.body + escClose + m.post;
|
||||||
return expand_(str, max, true);
|
isTop = true;
|
||||||
|
continue;
|
||||||
}
|
}
|
||||||
return [str];
|
// Nothing here expands, so the whole remaining string is literal.
|
||||||
|
return combine(acc, pre + '{' + m.body + '}' + m.post, [''], max, maxLength, dropEmpties);
|
||||||
}
|
}
|
||||||
let n;
|
if (firstGroup) {
|
||||||
|
dropEmpties = isTop && !isSequence;
|
||||||
|
firstGroup = false;
|
||||||
|
}
|
||||||
|
let values;
|
||||||
if (isSequence) {
|
if (isSequence) {
|
||||||
n = m.body.split(/\.\./);
|
values = expandSequence(m.body, isAlphaSequence, max);
|
||||||
}
|
}
|
||||||
else {
|
else {
|
||||||
n = parseCommaParts(m.body);
|
let n = parseCommaParts(m.body);
|
||||||
if (n.length === 1 && n[0] !== undefined) {
|
if (n.length === 1 && n[0] !== undefined) {
|
||||||
// x{{a,b}}y ==> x{a}y x{b}y
|
// x{{a,b}}y ==> x{a}y x{b}y
|
||||||
n = expand_(n[0], max, false).map(embrace);
|
n = expand_(n[0], max, maxLength, false).map(embrace);
|
||||||
//XXX is this necessary? Can't seem to hit it in tests.
|
//XXX is this necessary? Can't seem to hit it in tests.
|
||||||
/* c8 ignore start */
|
/* c8 ignore start */
|
||||||
if (n.length === 1) {
|
if (n.length === 1) {
|
||||||
return post.map(p => m.pre + n[0] + p);
|
acc = combine(acc, pre + n[0], [''], max, maxLength, dropEmpties && !m.post.length);
|
||||||
|
if (!m.post.length)
|
||||||
|
break;
|
||||||
|
str = m.post;
|
||||||
|
continue;
|
||||||
}
|
}
|
||||||
/* c8 ignore stop */
|
/* c8 ignore stop */
|
||||||
}
|
}
|
||||||
}
|
values = [];
|
||||||
// at this point, n is the parts, and we know it's not a comma set
|
|
||||||
// with a single entry.
|
|
||||||
let N;
|
|
||||||
if (isSequence && n[0] !== undefined && n[1] !== undefined) {
|
|
||||||
const x = numeric(n[0]);
|
|
||||||
const y = numeric(n[1]);
|
|
||||||
const width = Math.max(n[0].length, n[1].length);
|
|
||||||
let incr = n.length === 3 && n[2] !== undefined ?
|
|
||||||
Math.max(Math.abs(numeric(n[2])), 1)
|
|
||||||
: 1;
|
|
||||||
let test = lte;
|
|
||||||
const reverse = y < x;
|
|
||||||
if (reverse) {
|
|
||||||
incr *= -1;
|
|
||||||
test = gte;
|
|
||||||
}
|
|
||||||
const pad = n.some(isPadded);
|
|
||||||
N = [];
|
|
||||||
for (let i = x; test(i, y) && N.length < max; i += incr) {
|
|
||||||
let c;
|
|
||||||
if (isAlphaSequence) {
|
|
||||||
c = String.fromCharCode(i);
|
|
||||||
if (c === '\\') {
|
|
||||||
c = '';
|
|
||||||
}
|
|
||||||
}
|
|
||||||
else {
|
|
||||||
c = String(i);
|
|
||||||
if (pad) {
|
|
||||||
const need = width - c.length;
|
|
||||||
if (need > 0) {
|
|
||||||
const z = new Array(need + 1).join('0');
|
|
||||||
if (i < 0) {
|
|
||||||
c = '-' + z + c.slice(1);
|
|
||||||
}
|
|
||||||
else {
|
|
||||||
c = z + c;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
N.push(c);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
else {
|
|
||||||
N = [];
|
|
||||||
for (let j = 0; j < n.length; j++) {
|
for (let j = 0; j < n.length; j++) {
|
||||||
N.push.apply(N, expand_(n[j], max, false));
|
values.push.apply(values, expand_(n[j], max, maxLength, false));
|
||||||
}
|
|
||||||
}
|
|
||||||
for (let j = 0; j < N.length; j++) {
|
|
||||||
for (let k = 0; k < post.length && expansions.length < max; k++) {
|
|
||||||
const expansion = pre + N[j] + post[k];
|
|
||||||
if (!isTop || isSequence || expansion) {
|
|
||||||
expansions.push(expansion);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
acc = combine(acc, pre, values, max, maxLength, dropEmpties && !m.post.length);
|
||||||
|
if (!m.post.length)
|
||||||
|
break;
|
||||||
|
str = m.post;
|
||||||
}
|
}
|
||||||
return expansions;
|
return acc;
|
||||||
}
|
}
|
||||||
//# sourceMappingURL=index.js.map
|
//# sourceMappingURL=index.js.map
|
||||||
;// CONCATENATED MODULE: ./node_modules/@actions/glob/node_modules/minimatch/dist/esm/assert-valid-pattern.js
|
;// CONCATENATED MODULE: ./node_modules/@actions/glob/node_modules/minimatch/dist/esm/assert-valid-pattern.js
|
||||||
|
|||||||
Generated
+22
-22
@@ -133,15 +133,15 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@actions/glob/node_modules/brace-expansion": {
|
"node_modules/@actions/glob/node_modules/brace-expansion": {
|
||||||
"version": "5.0.6",
|
"version": "5.0.8",
|
||||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.6.tgz",
|
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.8.tgz",
|
||||||
"integrity": "sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==",
|
"integrity": "sha512-JZyDyq3D4AUifKTPOB7DELf6XsB3WdPuNxCtob1vFXPsSXhdAiHBWJ/tJ8HAc9aH84BK+5JFZLNkJKx3G9kzQg==",
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"balanced-match": "^4.0.2"
|
"balanced-match": "^4.0.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": "18 || 20 || >=22"
|
"node": "20 || >=22"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@actions/glob/node_modules/minimatch": {
|
"node_modules/@actions/glob/node_modules/minimatch": {
|
||||||
@@ -995,16 +995,16 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@eslint/config-array/node_modules/brace-expansion": {
|
"node_modules/@eslint/config-array/node_modules/brace-expansion": {
|
||||||
"version": "5.0.6",
|
"version": "5.0.8",
|
||||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.6.tgz",
|
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.8.tgz",
|
||||||
"integrity": "sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==",
|
"integrity": "sha512-JZyDyq3D4AUifKTPOB7DELf6XsB3WdPuNxCtob1vFXPsSXhdAiHBWJ/tJ8HAc9aH84BK+5JFZLNkJKx3G9kzQg==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"balanced-match": "^4.0.2"
|
"balanced-match": "^4.0.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": "18 || 20 || >=22"
|
"node": "20 || >=22"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@eslint/config-array/node_modules/minimatch": {
|
"node_modules/@eslint/config-array/node_modules/minimatch": {
|
||||||
@@ -2221,16 +2221,16 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@typescript-eslint/typescript-estree/node_modules/brace-expansion": {
|
"node_modules/@typescript-eslint/typescript-estree/node_modules/brace-expansion": {
|
||||||
"version": "5.0.6",
|
"version": "5.0.8",
|
||||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.6.tgz",
|
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.8.tgz",
|
||||||
"integrity": "sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==",
|
"integrity": "sha512-JZyDyq3D4AUifKTPOB7DELf6XsB3WdPuNxCtob1vFXPsSXhdAiHBWJ/tJ8HAc9aH84BK+5JFZLNkJKx3G9kzQg==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"balanced-match": "^4.0.2"
|
"balanced-match": "^4.0.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": "18 || 20 || >=22"
|
"node": "20 || >=22"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@typescript-eslint/typescript-estree/node_modules/minimatch": {
|
"node_modules/@typescript-eslint/typescript-estree/node_modules/minimatch": {
|
||||||
@@ -2891,9 +2891,9 @@
|
|||||||
"license": "Apache-2.0"
|
"license": "Apache-2.0"
|
||||||
},
|
},
|
||||||
"node_modules/brace-expansion": {
|
"node_modules/brace-expansion": {
|
||||||
"version": "1.1.13",
|
"version": "1.1.16",
|
||||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.13.tgz",
|
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.16.tgz",
|
||||||
"integrity": "sha512-9ZLprWS6EENmhEOpjCYW2c8VkmOvckIJZfkr7rBW6dObmfgJ/L1GpSYW5Hpo9lDz4D1+n0Ckz8rU7FwHDQiG/w==",
|
"integrity": "sha512-IDw48K2/2kRkg9LdJxurvq3lV3aBgq0REY89duEqFRthjlPdXHKMj7EnQOXVckxzgisinf3nHfrcE2FufFLXMw==",
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"balanced-match": "^1.0.0",
|
"balanced-match": "^1.0.0",
|
||||||
@@ -3574,16 +3574,16 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/eslint/node_modules/brace-expansion": {
|
"node_modules/eslint/node_modules/brace-expansion": {
|
||||||
"version": "5.0.6",
|
"version": "5.0.8",
|
||||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.6.tgz",
|
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.8.tgz",
|
||||||
"integrity": "sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==",
|
"integrity": "sha512-JZyDyq3D4AUifKTPOB7DELf6XsB3WdPuNxCtob1vFXPsSXhdAiHBWJ/tJ8HAc9aH84BK+5JFZLNkJKx3G9kzQg==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"balanced-match": "^4.0.2"
|
"balanced-match": "^4.0.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": "18 || 20 || >=22"
|
"node": "20 || >=22"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/eslint/node_modules/eslint-visitor-keys": {
|
"node_modules/eslint/node_modules/eslint-visitor-keys": {
|
||||||
@@ -4040,9 +4040,9 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/glob/node_modules/brace-expansion": {
|
"node_modules/glob/node_modules/brace-expansion": {
|
||||||
"version": "2.1.1",
|
"version": "2.1.2",
|
||||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.1.1.tgz",
|
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.1.2.tgz",
|
||||||
"integrity": "sha512-WR1cURNjuvBLMZBMbqM0UoE+WAfdUcEV1ccD8PVBVOI+Z3ND4+SZbN8RsfT2bMuG1qwz5RFvPukSZm5fF2D5eA==",
|
"integrity": "sha512-w5JZcKgdhDOgOwm8H+KgbosopHMuGcl6qbulwjtz3SM7I7P3yW1eAjzMPLrIE+NQ9vjgANKHWeMHnrT0OXW1oA==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
|
|||||||
Reference in New Issue
Block a user