mirror of
https://github.com/astral-sh/setup-uv.git
synced 2026-09-02 21:59:22 +00:00
Disable automatic caching for sensitive events (#992)
## Summary - disable `enable-cache: auto` for `pull_request_target`, `workflow_run`, and `release` events - disable automatic caching for tag pushes while leaving branch pushes unchanged - preserve explicit `enable-cache: true` as an override - run a `workflow_run` integration fixture with `act` in pull request CI and verify caching is disabled - document the behavior and update the published bundles ## Testing - `npm run all` - `actionlint .github/workflows/test.yml __tests__/workflows/workflow-run.yml` - `uvx zizmor __tests__/workflows/workflow-run.yml` Closes #984 Refs: pi-session 019fec42-9b26-714e-a359-830ac4401ecd
This commit is contained in:
@@ -12,6 +12,8 @@ import {
|
||||
|
||||
let mockInputs: Record<string, string> = {};
|
||||
const tempDirs: string[] = [];
|
||||
const ORIGINAL_GITHUB_EVENT_NAME = process.env.GITHUB_EVENT_NAME;
|
||||
const ORIGINAL_GITHUB_REF = process.env.GITHUB_REF;
|
||||
const ORIGINAL_HOME = process.env.HOME;
|
||||
const ORIGINAL_RUNNER_ENVIRONMENT = process.env.RUNNER_ENVIRONMENT;
|
||||
const ORIGINAL_RUNNER_TEMP = process.env.RUNNER_TEMP;
|
||||
@@ -52,6 +54,8 @@ function createTempProject(files: Record<string, string> = {}): string {
|
||||
function resetEnvironment(): void {
|
||||
jest.clearAllMocks();
|
||||
mockInputs = {};
|
||||
delete process.env.GITHUB_EVENT_NAME;
|
||||
delete process.env.GITHUB_REF;
|
||||
process.env.HOME = "/home/testuser";
|
||||
delete process.env.RUNNER_ENVIRONMENT;
|
||||
delete process.env.RUNNER_TEMP;
|
||||
@@ -64,6 +68,8 @@ function restoreEnvironment(): void {
|
||||
fs.rmSync(dir, { force: true, recursive: true });
|
||||
}
|
||||
|
||||
process.env.GITHUB_EVENT_NAME = ORIGINAL_GITHUB_EVENT_NAME;
|
||||
process.env.GITHUB_REF = ORIGINAL_GITHUB_REF;
|
||||
process.env.HOME = ORIGINAL_HOME;
|
||||
process.env.RUNNER_ENVIRONMENT = ORIGINAL_RUNNER_ENVIRONMENT;
|
||||
process.env.RUNNER_TEMP = ORIGINAL_RUNNER_TEMP;
|
||||
@@ -94,6 +100,64 @@ describe("loadInputs", () => {
|
||||
expect(inputs.resolutionStrategy).toBe("highest");
|
||||
});
|
||||
|
||||
it.each([
|
||||
"pull_request_target",
|
||||
"workflow_run",
|
||||
"release",
|
||||
])("disables automatic caching for the %s event", (eventName) => {
|
||||
mockInputs["working-directory"] = "/workspace";
|
||||
mockInputs["enable-cache"] = "auto";
|
||||
process.env.RUNNER_ENVIRONMENT = "github-hosted";
|
||||
process.env.RUNNER_TEMP = "/runner-temp";
|
||||
process.env.GITHUB_EVENT_NAME = eventName;
|
||||
|
||||
const inputs = loadInputs();
|
||||
|
||||
expect(inputs.enableCache).toBe(false);
|
||||
expect(mockInfo).toHaveBeenCalledWith(
|
||||
`Caching is disabled for the ${eventName} event`,
|
||||
);
|
||||
});
|
||||
|
||||
it("disables automatic caching for tag pushes", () => {
|
||||
mockInputs["working-directory"] = "/workspace";
|
||||
mockInputs["enable-cache"] = "auto";
|
||||
process.env.RUNNER_ENVIRONMENT = "github-hosted";
|
||||
process.env.RUNNER_TEMP = "/runner-temp";
|
||||
process.env.GITHUB_EVENT_NAME = "push";
|
||||
process.env.GITHUB_REF = "refs/tags/v1.0.0";
|
||||
|
||||
const inputs = loadInputs();
|
||||
|
||||
expect(inputs.enableCache).toBe(false);
|
||||
expect(mockInfo).toHaveBeenCalledWith("Caching is disabled for tag pushes");
|
||||
});
|
||||
|
||||
it("enables automatic caching for branch pushes", () => {
|
||||
mockInputs["working-directory"] = "/workspace";
|
||||
mockInputs["enable-cache"] = "auto";
|
||||
process.env.RUNNER_ENVIRONMENT = "github-hosted";
|
||||
process.env.RUNNER_TEMP = "/runner-temp";
|
||||
process.env.GITHUB_EVENT_NAME = "push";
|
||||
process.env.GITHUB_REF = "refs/heads/main";
|
||||
|
||||
const inputs = loadInputs();
|
||||
|
||||
expect(inputs.enableCache).toBe(true);
|
||||
});
|
||||
|
||||
it("honors explicitly enabled caching for sensitive events", () => {
|
||||
mockInputs["working-directory"] = "/workspace";
|
||||
mockInputs["enable-cache"] = "true";
|
||||
process.env.RUNNER_ENVIRONMENT = "github-hosted";
|
||||
process.env.RUNNER_TEMP = "/runner-temp";
|
||||
process.env.GITHUB_EVENT_NAME = "release";
|
||||
|
||||
const inputs = loadInputs();
|
||||
|
||||
expect(inputs.enableCache).toBe(true);
|
||||
});
|
||||
|
||||
it("uses cache-dir from pyproject.toml when present", () => {
|
||||
mockInputs["working-directory"] = createTempProject({
|
||||
"pyproject.toml": `[project]
|
||||
|
||||
@@ -0,0 +1,42 @@
|
||||
name: "test workflow_run caching"
|
||||
|
||||
on: # zizmor: ignore[dangerous-triggers] this workflow is a test fixture executed by act only
|
||||
workflow_run:
|
||||
workflows:
|
||||
- test
|
||||
types:
|
||||
- completed
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
test-cache-disabled:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Setup uv with automatic caching
|
||||
id: setup-uv
|
||||
uses: ./
|
||||
- name: Verify automatic caching is disabled
|
||||
env:
|
||||
CACHE_KEY: ${{ steps.setup-uv.outputs.cache-key }}
|
||||
run: |
|
||||
if [ "$GITHUB_EVENT_NAME" != "workflow_run" ]; then
|
||||
echo "Expected workflow_run event, got: $GITHUB_EVENT_NAME"
|
||||
exit 1
|
||||
fi
|
||||
if [ "$RUNNER_ENVIRONMENT" != "github-hosted" ]; then
|
||||
echo "Expected a simulated GitHub-hosted runner, got: $RUNNER_ENVIRONMENT"
|
||||
exit 1
|
||||
fi
|
||||
if [ -n "$CACHE_KEY" ]; then
|
||||
echo "Cache key should not be set for a workflow_run event: $CACHE_KEY"
|
||||
exit 1
|
||||
fi
|
||||
if [ -n "$UV_CACHE_DIR" ]; then
|
||||
echo "UV_CACHE_DIR should not be set for a workflow_run event: $UV_CACHE_DIR"
|
||||
exit 1
|
||||
fi
|
||||
Reference in New Issue
Block a user