mirror of
https://github.com/actions/checkout.git
synced 2025-12-15 22:19:06 +08:00
Compare commits
4 Commits
c579c401c2
...
c56c910cb0
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c56c910cb0 | ||
|
|
8e8c483db8 | ||
|
|
033fa0dc0b | ||
|
|
d1d381abe7 |
16
.github/workflows/test.yml
vendored
16
.github/workflows/test.yml
vendored
@ -165,6 +165,22 @@ jobs:
|
|||||||
- name: Verify submodules recursive
|
- name: Verify submodules recursive
|
||||||
run: __test__/verify-submodules-recursive.sh
|
run: __test__/verify-submodules-recursive.sh
|
||||||
|
|
||||||
|
# Worktree credentials
|
||||||
|
- name: Checkout for worktree test
|
||||||
|
uses: ./
|
||||||
|
with:
|
||||||
|
path: worktree-test
|
||||||
|
- name: Verify worktree credentials
|
||||||
|
shell: bash
|
||||||
|
run: __test__/verify-worktree.sh worktree-test worktree-branch
|
||||||
|
|
||||||
|
# Worktree credentials in container step
|
||||||
|
- name: Verify worktree credentials in container step
|
||||||
|
if: runner.os == 'Linux'
|
||||||
|
uses: docker://bitnami/git:latest
|
||||||
|
with:
|
||||||
|
args: bash __test__/verify-worktree.sh worktree-test container-worktree-branch
|
||||||
|
|
||||||
# Basic checkout using REST API
|
# Basic checkout using REST API
|
||||||
- name: Remove basic
|
- name: Remove basic
|
||||||
if: runner.os != 'windows'
|
if: runner.os != 'windows'
|
||||||
|
|||||||
10
CHANGELOG.md
10
CHANGELOG.md
@ -1,19 +1,19 @@
|
|||||||
# Changelog
|
# Changelog
|
||||||
|
|
||||||
## V6.0.0
|
## v6.0.0
|
||||||
* Persist creds to a separate file by @ericsciple in https://github.com/actions/checkout/pull/2286
|
* Persist creds to a separate file by @ericsciple in https://github.com/actions/checkout/pull/2286
|
||||||
* Update README to include Node.js 24 support details and requirements by @salmanmkc in https://github.com/actions/checkout/pull/2248
|
* Update README to include Node.js 24 support details and requirements by @salmanmkc in https://github.com/actions/checkout/pull/2248
|
||||||
|
|
||||||
## V5.0.1
|
## v5.0.1
|
||||||
* Port v6 cleanup to v5 by @ericsciple in https://github.com/actions/checkout/pull/2301
|
* Port v6 cleanup to v5 by @ericsciple in https://github.com/actions/checkout/pull/2301
|
||||||
|
|
||||||
## V5.0.0
|
## v5.0.0
|
||||||
* Update actions checkout to use node 24 by @salmanmkc in https://github.com/actions/checkout/pull/2226
|
* Update actions checkout to use node 24 by @salmanmkc in https://github.com/actions/checkout/pull/2226
|
||||||
|
|
||||||
## V4.3.1
|
## v4.3.1
|
||||||
* Port v6 cleanup to v4 by @ericsciple in https://github.com/actions/checkout/pull/2305
|
* Port v6 cleanup to v4 by @ericsciple in https://github.com/actions/checkout/pull/2305
|
||||||
|
|
||||||
## V4.3.0
|
## v4.3.0
|
||||||
* docs: update README.md by @motss in https://github.com/actions/checkout/pull/1971
|
* docs: update README.md by @motss in https://github.com/actions/checkout/pull/1971
|
||||||
* Add internal repos for checking out multiple repositories by @mouismail in https://github.com/actions/checkout/pull/1977
|
* Add internal repos for checking out multiple repositories by @mouismail in https://github.com/actions/checkout/pull/1977
|
||||||
* Documentation update - add recommended permissions to Readme by @benwells in https://github.com/actions/checkout/pull/2043
|
* Documentation update - add recommended permissions to Readme by @benwells in https://github.com/actions/checkout/pull/2043
|
||||||
|
|||||||
@ -4,8 +4,9 @@
|
|||||||
|
|
||||||
## What's new
|
## What's new
|
||||||
|
|
||||||
- Updated `persist-credentials` to store the credentials under `$RUNNER_TEMP` instead of directly in the local git config.
|
- Improved credential security: `persist-credentials` now stores credentials in a separate file under `$RUNNER_TEMP` instead of directly in `.git/config`
|
||||||
- This requires a minimum Actions Runner version of [v2.329.0](https://github.com/actions/runner/releases/tag/v2.329.0) to access the persisted credentials for [Docker container action](https://docs.github.com/en/actions/tutorials/use-containerized-services/create-a-docker-container-action) scenarios.
|
- No workflow changes required — `git fetch`, `git push`, etc. continue to work automatically
|
||||||
|
- Running authenticated git commands from a [Docker container action](https://docs.github.com/actions/sharing-automations/creating-actions/creating-a-docker-container-action) requires Actions Runner [v2.329.0](https://github.com/actions/runner/releases/tag/v2.329.0) or later
|
||||||
|
|
||||||
# Checkout v5
|
# Checkout v5
|
||||||
|
|
||||||
@ -107,6 +108,10 @@ Please refer to the [release page](https://github.com/actions/checkout/releases/
|
|||||||
# Relative path under $GITHUB_WORKSPACE to place the repository
|
# Relative path under $GITHUB_WORKSPACE to place the repository
|
||||||
path: ''
|
path: ''
|
||||||
|
|
||||||
|
# Allow the checked-out repository to be placed outside of the workspace
|
||||||
|
# Default: false
|
||||||
|
allow-path-outside-workspace: ''
|
||||||
|
|
||||||
# Whether to execute `git clean -ffdx && git reset --hard HEAD` before fetching
|
# Whether to execute `git clean -ffdx && git reset --hard HEAD` before fetching
|
||||||
# Default: true
|
# Default: true
|
||||||
clean: ''
|
clean: ''
|
||||||
|
|||||||
51
__test__/verify-worktree.sh
Executable file
51
__test__/verify-worktree.sh
Executable file
@ -0,0 +1,51 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
set -e
|
||||||
|
|
||||||
|
# Verify worktree credentials
|
||||||
|
# This test verifies that git credentials work in worktrees created after checkout
|
||||||
|
# Usage: verify-worktree.sh <checkout-path> <worktree-name>
|
||||||
|
|
||||||
|
CHECKOUT_PATH="$1"
|
||||||
|
WORKTREE_NAME="$2"
|
||||||
|
|
||||||
|
if [ -z "$CHECKOUT_PATH" ] || [ -z "$WORKTREE_NAME" ]; then
|
||||||
|
echo "Usage: verify-worktree.sh <checkout-path> <worktree-name>"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
cd "$CHECKOUT_PATH"
|
||||||
|
|
||||||
|
# Add safe directory for container environments
|
||||||
|
git config --global --add safe.directory "*" 2>/dev/null || true
|
||||||
|
|
||||||
|
# Show the includeIf configuration
|
||||||
|
echo "Git config includeIf entries:"
|
||||||
|
git config --list --show-origin | grep -i include || true
|
||||||
|
|
||||||
|
# Create the worktree
|
||||||
|
echo "Creating worktree..."
|
||||||
|
git worktree add "../$WORKTREE_NAME" HEAD --detach
|
||||||
|
|
||||||
|
# Change to worktree directory
|
||||||
|
cd "../$WORKTREE_NAME"
|
||||||
|
|
||||||
|
# Verify we're in a worktree
|
||||||
|
echo "Verifying worktree gitdir:"
|
||||||
|
cat .git
|
||||||
|
|
||||||
|
# Verify credentials are available in worktree by checking extraheader is configured
|
||||||
|
echo "Checking credentials in worktree..."
|
||||||
|
if git config --list --show-origin | grep -q "extraheader"; then
|
||||||
|
echo "Credentials are configured in worktree"
|
||||||
|
else
|
||||||
|
echo "ERROR: Credentials are NOT configured in worktree"
|
||||||
|
echo "Full git config:"
|
||||||
|
git config --list --show-origin
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Verify fetch works in the worktree
|
||||||
|
echo "Fetching in worktree..."
|
||||||
|
git fetch origin
|
||||||
|
|
||||||
|
echo "Worktree credentials test passed!"
|
||||||
@ -54,6 +54,10 @@ inputs:
|
|||||||
default: true
|
default: true
|
||||||
path:
|
path:
|
||||||
description: 'Relative path under $GITHUB_WORKSPACE to place the repository'
|
description: 'Relative path under $GITHUB_WORKSPACE to place the repository'
|
||||||
|
allow-path-outside-workspace:
|
||||||
|
description: Allow the checked-out repository to be placed outside of the workspace.
|
||||||
|
default: false
|
||||||
|
required: false
|
||||||
clean:
|
clean:
|
||||||
description: 'Whether to execute `git clean -ffdx && git reset --hard HEAD` before fetching'
|
description: 'Whether to execute `git clean -ffdx && git reset --hard HEAD` before fetching'
|
||||||
default: true
|
default: true
|
||||||
|
|||||||
9
dist/index.js
vendored
9
dist/index.js
vendored
@ -412,6 +412,9 @@ class GitAuthHelper {
|
|||||||
// Configure host includeIf
|
// Configure host includeIf
|
||||||
const hostIncludeKey = `includeIf.gitdir:${gitDir}.path`;
|
const hostIncludeKey = `includeIf.gitdir:${gitDir}.path`;
|
||||||
yield this.git.config(hostIncludeKey, credentialsConfigPath);
|
yield this.git.config(hostIncludeKey, credentialsConfigPath);
|
||||||
|
// Configure host includeIf for worktrees
|
||||||
|
const hostWorktreeIncludeKey = `includeIf.gitdir:${gitDir}/worktrees/*.path`;
|
||||||
|
yield this.git.config(hostWorktreeIncludeKey, credentialsConfigPath);
|
||||||
// Container git directory
|
// Container git directory
|
||||||
const workingDirectory = this.git.getWorkingDirectory();
|
const workingDirectory = this.git.getWorkingDirectory();
|
||||||
const githubWorkspace = process.env['GITHUB_WORKSPACE'];
|
const githubWorkspace = process.env['GITHUB_WORKSPACE'];
|
||||||
@ -424,6 +427,9 @@ class GitAuthHelper {
|
|||||||
// Configure container includeIf
|
// Configure container includeIf
|
||||||
const containerIncludeKey = `includeIf.gitdir:${containerGitDir}.path`;
|
const containerIncludeKey = `includeIf.gitdir:${containerGitDir}.path`;
|
||||||
yield this.git.config(containerIncludeKey, containerCredentialsPath);
|
yield this.git.config(containerIncludeKey, containerCredentialsPath);
|
||||||
|
// Configure container includeIf for worktrees
|
||||||
|
const containerWorktreeIncludeKey = `includeIf.gitdir:${containerGitDir}/worktrees/*.path`;
|
||||||
|
yield this.git.config(containerWorktreeIncludeKey, containerCredentialsPath);
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@ -1973,7 +1979,8 @@ function getInputs() {
|
|||||||
// Repository path
|
// Repository path
|
||||||
result.repositoryPath = core.getInput('path') || '.';
|
result.repositoryPath = core.getInput('path') || '.';
|
||||||
result.repositoryPath = path.resolve(githubWorkspacePath, result.repositoryPath);
|
result.repositoryPath = path.resolve(githubWorkspacePath, result.repositoryPath);
|
||||||
if (!(result.repositoryPath + path.sep).startsWith(githubWorkspacePath + path.sep)) {
|
if (!core.getInput('allow-path-outside-workspace') &&
|
||||||
|
!(result.repositoryPath + path.sep).startsWith(githubWorkspacePath + path.sep)) {
|
||||||
throw new Error(`Repository path '${result.repositoryPath}' is not under '${githubWorkspacePath}'`);
|
throw new Error(`Repository path '${result.repositoryPath}' is not under '${githubWorkspacePath}'`);
|
||||||
}
|
}
|
||||||
// Workflow repository?
|
// Workflow repository?
|
||||||
|
|||||||
@ -374,6 +374,10 @@ class GitAuthHelper {
|
|||||||
const hostIncludeKey = `includeIf.gitdir:${gitDir}.path`
|
const hostIncludeKey = `includeIf.gitdir:${gitDir}.path`
|
||||||
await this.git.config(hostIncludeKey, credentialsConfigPath)
|
await this.git.config(hostIncludeKey, credentialsConfigPath)
|
||||||
|
|
||||||
|
// Configure host includeIf for worktrees
|
||||||
|
const hostWorktreeIncludeKey = `includeIf.gitdir:${gitDir}/worktrees/*.path`
|
||||||
|
await this.git.config(hostWorktreeIncludeKey, credentialsConfigPath)
|
||||||
|
|
||||||
// Container git directory
|
// Container git directory
|
||||||
const workingDirectory = this.git.getWorkingDirectory()
|
const workingDirectory = this.git.getWorkingDirectory()
|
||||||
const githubWorkspace = process.env['GITHUB_WORKSPACE']
|
const githubWorkspace = process.env['GITHUB_WORKSPACE']
|
||||||
@ -395,6 +399,13 @@ class GitAuthHelper {
|
|||||||
// Configure container includeIf
|
// Configure container includeIf
|
||||||
const containerIncludeKey = `includeIf.gitdir:${containerGitDir}.path`
|
const containerIncludeKey = `includeIf.gitdir:${containerGitDir}.path`
|
||||||
await this.git.config(containerIncludeKey, containerCredentialsPath)
|
await this.git.config(containerIncludeKey, containerCredentialsPath)
|
||||||
|
|
||||||
|
// Configure container includeIf for worktrees
|
||||||
|
const containerWorktreeIncludeKey = `includeIf.gitdir:${containerGitDir}/worktrees/*.path`
|
||||||
|
await this.git.config(
|
||||||
|
containerWorktreeIncludeKey,
|
||||||
|
containerCredentialsPath
|
||||||
|
)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@ -42,6 +42,7 @@ export async function getInputs(): Promise<IGitSourceSettings> {
|
|||||||
result.repositoryPath
|
result.repositoryPath
|
||||||
)
|
)
|
||||||
if (
|
if (
|
||||||
|
!core.getInput('allow-path-outside-workspace') &&
|
||||||
!(result.repositoryPath + path.sep).startsWith(
|
!(result.repositoryPath + path.sep).startsWith(
|
||||||
githubWorkspacePath + path.sep
|
githubWorkspacePath + path.sep
|
||||||
)
|
)
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user