mirror of
https://github.com/actions/toolkit.git
synced 2026-08-22 00:00:21 +02:00
@actions/glob: extend hashFiles options (#2357)
* @actions/glob: extend hashFiles options * improve hashFiles symlink handling * Improve error handling and messaging in hashFiles function * apply relative exclude patterns across all roots and use named minimatch import * format error message
This commit is contained in:
@@ -76,6 +76,36 @@ for await (const file of globber.globGenerator()) {
|
||||
}
|
||||
```
|
||||
|
||||
## Hashing files (`hashFiles`)
|
||||
|
||||
`hashFiles` computes a hash of files matched by glob patterns.
|
||||
|
||||
By default, only files under the workspace (`GITHUB_WORKSPACE`) are eligible to be hashed.
|
||||
|
||||
To improve security, file eligibility is evaluated using each file's resolved (real) path to prevent symbolic link traversal outside the allowed root path(s).
|
||||
|
||||
### Options
|
||||
|
||||
- `roots?: string[]` — Allowlist of root paths. Only files that resolve under (or equal) one of these roots are hashed. Defaults to `[GITHUB_WORKSPACE]` (or `currentWorkspace` if provided).
|
||||
- `allowFilesOutsideWorkspace?: boolean` — Explicit opt-in to include files outside the specified root path(s). Defaults to `false`.
|
||||
- `exclude?: string[]` — Glob patterns to exclude from hashing. Defaults to `[]`.
|
||||
|
||||
If files match your patterns but are outside the allowed roots and `allowFilesOutsideWorkspace` is not enabled, those files are skipped and a warning is emitted. If no eligible files remain after filtering, `hashFiles` returns an empty string (`''`).
|
||||
|
||||
### Example
|
||||
|
||||
```js
|
||||
const glob = require('@actions/glob')
|
||||
|
||||
const hash = await glob.hashFiles('**/*.json', process.env.GITHUB_WORKSPACE || '', {
|
||||
roots: [process.env.GITHUB_WORKSPACE, process.env.GITHUB_ACTION_PATH].filter(Boolean),
|
||||
allowFilesOutsideWorkspace: true,
|
||||
exclude: ['**/node_modules/**']
|
||||
})
|
||||
|
||||
console.log(hash)
|
||||
```
|
||||
|
||||
## Patterns
|
||||
|
||||
### Glob behavior
|
||||
|
||||
Reference in New Issue
Block a user