mirror of
https://github.com/bahdotsh/wrkflw.git
synced 2026-09-02 12:16:16 +02:00
It turns out that resolve_action was blindly splitting on '@' for *all* action references, including Docker image refs like docker://alpine@sha256:abc123. The '@' in a Docker digest is not a version separator — it's part of the image reference. Splitting it produces a nonsensical repository and a fake "version" that happens to be a SHA256 digest. Nobody noticed because the Docker path doesn't use the version field, but the parsed data was still wrong. While at it, the auth retry path in fetch_and_parse was constructing a brand new reqwest::Client on every single 404-then-retry cycle. That means a fresh TLS handshake each time, which is wasteful when we already have a perfectly good static client pattern. Promote the no-redirect client to a static Lazy, same as HTTP_CLIENT. The auth redirect flow — where we send GITHUB_TOKEN to the origin but strip it before following a redirect to a CDN — had zero test coverage. This is the kind of security invariant that *really* should not depend on code review alone. Add wiremock-based tests that verify the token does not leak to redirect targets, plus tests for the basic auth retry and 404 paths. Parameterize fetch_and_parse with a base_url so wiremock can intercept the requests.
73 lines
2.2 KiB
TOML
73 lines
2.2 KiB
TOML
[workspace]
|
|
members = ["crates/*"]
|
|
resolver = "2"
|
|
|
|
[workspace.package]
|
|
version = "0.7.3"
|
|
edition = "2021"
|
|
description = "A GitHub Actions workflow validator and executor"
|
|
documentation = "https://github.com/bahdotsh/wrkflw"
|
|
homepage = "https://github.com/bahdotsh/wrkflw"
|
|
repository = "https://github.com/bahdotsh/wrkflw"
|
|
keywords = ["workflows", "github", "local"]
|
|
categories = ["command-line-utilities"]
|
|
license = "MIT"
|
|
|
|
[workspace.dependencies]
|
|
# Internal crate dependencies
|
|
wrkflw-models = { path = "crates/models", version = "0.7.3" }
|
|
wrkflw-evaluator = { path = "crates/evaluator", version = "0.7.3" }
|
|
wrkflw-executor = { path = "crates/executor", version = "0.7.3" }
|
|
wrkflw-github = { path = "crates/github", version = "0.7.3" }
|
|
wrkflw-gitlab = { path = "crates/gitlab", version = "0.7.3" }
|
|
wrkflw-logging = { path = "crates/logging", version = "0.7.3" }
|
|
wrkflw-matrix = { path = "crates/matrix", version = "0.7.3" }
|
|
wrkflw-parser = { path = "crates/parser", version = "0.7.3" }
|
|
wrkflw-runtime = { path = "crates/runtime", version = "0.7.3" }
|
|
wrkflw-secrets = { path = "crates/secrets", version = "0.7.3" }
|
|
wrkflw-ui = { path = "crates/ui", version = "0.7.3" }
|
|
wrkflw-utils = { path = "crates/utils", version = "0.7.3" }
|
|
wrkflw-validators = { path = "crates/validators", version = "0.7.3" }
|
|
|
|
# External dependencies
|
|
clap = { version = "4.3", features = ["derive"] }
|
|
colored = "2.0"
|
|
serde = { version = "1.0", features = ["derive"] }
|
|
serde_yaml = "0.9"
|
|
serde_json = "1.0"
|
|
jsonschema = "0.17"
|
|
tokio = { version = "1.28", features = ["full"] }
|
|
async-trait = "0.1"
|
|
bollard = "0.14"
|
|
futures-util = "0.3"
|
|
futures = "0.3"
|
|
chrono = "0.4"
|
|
uuid = { version = "1.3", features = ["v4"] }
|
|
tempfile = "3.6"
|
|
tar = "0.4"
|
|
dirs = "5.0"
|
|
thiserror = "1.0"
|
|
log = "0.4"
|
|
which = "4.4"
|
|
crossterm = "0.26.1"
|
|
ratatui = { version = "0.23.0", features = ["crossterm"] }
|
|
once_cell = "1.19.0"
|
|
itertools = "0.11.0"
|
|
indexmap = { version = "2.0.0", features = ["serde"] }
|
|
rayon = "1.7.0"
|
|
num_cpus = "1.16.0"
|
|
regex = "1.10"
|
|
lazy_static = "1.4"
|
|
reqwest = { version = "0.11", default-features = false, features = [
|
|
"rustls-tls",
|
|
"json",
|
|
] }
|
|
libc = "0.2"
|
|
nix = { version = "0.27.1", features = ["fs"] }
|
|
urlencoding = "2.1.3"
|
|
wiremock = "0.5"
|
|
|
|
[profile.release]
|
|
codegen-units = 1
|
|
lto = true
|