2025-12-08 10:49:24 -08:00
|
|
|
import * as github from '@actions/github'
|
|
|
|
|
import {retry} from '@octokit/plugin-retry'
|
|
|
|
|
import {RequestHeaders} from '@octokit/types'
|
|
|
|
|
|
|
|
|
|
const CREATE_STORAGE_RECORD_REQUEST = 'POST /orgs/{owner}/artifacts/metadata/storage-record'
|
|
|
|
|
const DEFAULT_RETRY_COUNT = 5
|
|
|
|
|
|
2025-12-08 11:02:59 -08:00
|
|
|
export type ArtifactParams = {
|
|
|
|
|
name: string
|
|
|
|
|
digest: string
|
|
|
|
|
version?: string
|
|
|
|
|
status?: string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
export type PackageRegistryParams = {
|
|
|
|
|
registryUrl: string
|
|
|
|
|
artifactUrl?: string
|
2025-12-08 13:49:54 -08:00
|
|
|
repo?: string
|
2025-12-08 11:02:59 -08:00
|
|
|
path?: string
|
|
|
|
|
}
|
|
|
|
|
|
2025-12-08 10:49:24 -08:00
|
|
|
export type WriteOptions = {
|
|
|
|
|
retry?: number
|
|
|
|
|
headers?: RequestHeaders
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
2025-12-08 11:02:59 -08:00
|
|
|
* Writes a storage record on behalf of an artifact that has been attested
|
|
|
|
|
* @param artifactParams - parameters for the artifact.
|
|
|
|
|
* @param packageRegistryParams - parameters for the package registry.
|
2025-12-08 10:49:24 -08:00
|
|
|
* @param token - The GitHub token for authentication.
|
2025-12-08 11:02:59 -08:00
|
|
|
* @param options - Optional parameters for the write operation.
|
2025-12-08 10:49:24 -08:00
|
|
|
* @returns The ID of the storage record.
|
|
|
|
|
* @throws Error if the storage record fails to persist.
|
|
|
|
|
*/
|
2025-12-08 13:49:54 -08:00
|
|
|
export async function createStorageRecord(
|
2025-12-08 11:02:59 -08:00
|
|
|
artifactParams: ArtifactParams,
|
|
|
|
|
packageRegistryParams: PackageRegistryParams,
|
2025-12-08 10:49:24 -08:00
|
|
|
token: string,
|
|
|
|
|
options: WriteOptions = {}
|
2025-12-08 13:49:54 -08:00
|
|
|
): Promise<Array<string>> {
|
2025-12-08 10:49:24 -08:00
|
|
|
const retries = options.retry ?? DEFAULT_RETRY_COUNT
|
|
|
|
|
const octokit = github.getOctokit(token, {retry: {retries}}, retry)
|
|
|
|
|
|
|
|
|
|
try {
|
|
|
|
|
const response = await octokit.request(CREATE_STORAGE_RECORD_REQUEST, {
|
|
|
|
|
owner: github.context.repo.owner,
|
|
|
|
|
headers: options.headers,
|
2025-12-08 13:49:54 -08:00
|
|
|
...buildRequestParams(artifactParams, packageRegistryParams),
|
2025-12-08 10:49:24 -08:00
|
|
|
})
|
|
|
|
|
|
|
|
|
|
const data =
|
|
|
|
|
typeof response.data == 'string'
|
|
|
|
|
? JSON.parse(response.data)
|
|
|
|
|
: response.data
|
2025-12-08 13:17:08 -08:00
|
|
|
|
|
|
|
|
return data?.storage_records.map((r: { id: any }) => r.id)
|
2025-12-08 10:49:24 -08:00
|
|
|
} catch (err) {
|
|
|
|
|
const message = err instanceof Error ? err.message : err
|
|
|
|
|
throw new Error(`Failed to persist storage record: ${message}`)
|
|
|
|
|
}
|
|
|
|
|
}
|
2025-12-08 13:49:54 -08:00
|
|
|
|
|
|
|
|
const buildRequestParams = (artifactParams: ArtifactParams, registryParams: PackageRegistryParams) => {
|
|
|
|
|
const { registryUrl, artifactUrl, ...rest } = registryParams
|
|
|
|
|
return {
|
|
|
|
|
...artifactParams,
|
|
|
|
|
...rest,
|
|
|
|
|
// rename parameters to match API expectations
|
|
|
|
|
artifact_url: artifactUrl,
|
|
|
|
|
registry_url: registryUrl,
|
|
|
|
|
}
|
|
|
|
|
}
|