96f299fb53
CD / Release (push) Successful in 10s
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/cache](https://github.com/actions/cache) | action | major | `v5.1.0` → `v6.1.0` | --- ### Release Notes <details> <summary>actions/cache (actions/cache)</summary> ### [`v6.1.0`](https://github.com/actions/cache/releases/tag/v6.1.0) [Compare Source](https://github.com/actions/cache/compare/v6.0.0...v6.1.0) ##### What's Changed - Bump [@​actions/cache](https://github.com/actions/cache) to v6.1.0 - handle read-only cache access by [@​jasongin](https://github.com/jasongin) in [#​1768](https://github.com/actions/cache/pull/1768) **Full Changelog**: <https://github.com/actions/cache/compare/v6...v6.1.0> ### [`v6.0.0`](https://github.com/actions/cache/releases/tag/v6.0.0) [Compare Source](https://github.com/actions/cache/compare/v6.0.0...v6.0.0) ##### What's Changed - Update packages, migrate to ESM by [@​Samirat](https://github.com/Samirat) in [#​1760](https://github.com/actions/cache/pull/1760) **Full Changelog**: <https://github.com/actions/cache/compare/v5...v6.0.0> ### [`v6`](https://github.com/actions/cache/compare/v5.1.0...v6.0.0) [Compare Source](https://github.com/actions/cache/compare/v5.1.0...v6.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjMuOSIsInVwZGF0ZWRJblZlciI6IjQzLjI2My45IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJhY3Rpb24iLCJkZXBzIl19--> Reviewed-on: #65 Reviewed-by: t.behrendt <2+t.behrendt@noreply.localhost> Co-authored-by: Renovate Bot <renovate@t00n.de> Co-committed-by: Renovate Bot <renovate@t00n.de>
95 lines
3.1 KiB
YAML
95 lines
3.1 KiB
YAML
name: "Setup OSV Scanner DB"
|
|
description: "Setup the osv-scanner offline vulnerability database, restoring from cache if available"
|
|
author: "Timo Behrendt <t.behrendt@t00n.de>"
|
|
branding:
|
|
icon: "database"
|
|
color: "blue"
|
|
|
|
inputs:
|
|
cache-dir:
|
|
description: "Path used as OSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY (default: ${{runner.temp}}/osv-scanner)"
|
|
required: false
|
|
default: "${{ runner.temp }}/osv-scanner"
|
|
ecosystems:
|
|
description: "Comma-separated list of OSV ecosystems to download. Empty downloads all ecosystems."
|
|
required: false
|
|
default: ""
|
|
|
|
outputs:
|
|
cache-dir:
|
|
description: "Path to the osv-scanner local DB cache directory"
|
|
value: ${{ inputs.cache-dir }}
|
|
|
|
runs:
|
|
using: "composite"
|
|
steps:
|
|
- id: current-date
|
|
shell: bash
|
|
run: |
|
|
echo "current-date=$(date +%Y-%m-%d)" >> $GITHUB_OUTPUT
|
|
- id: restore-db
|
|
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
|
|
with:
|
|
path: ${{ inputs.cache-dir }}
|
|
key: osv-scanner-db-${{ steps.current-date.outputs.current-date }}
|
|
restore-keys: |
|
|
osv-scanner-db-${{ steps.current-date.outputs.current-date }}
|
|
- name: Download offline databases
|
|
if: steps.restore-db.outputs.cache-hit != 'true'
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
CACHE_DIR="${{ inputs.cache-dir }}"
|
|
DB_DIR="${CACHE_DIR}/osv-scanner"
|
|
mkdir -p "${DB_DIR}"
|
|
|
|
ECOSYSTEMS_INPUT="${{ inputs.ecosystems }}"
|
|
if [ -n "${ECOSYSTEMS_INPUT}" ]; then
|
|
# shellcheck disable=SC2001
|
|
ECOSYSTEMS=$(echo "${ECOSYSTEMS_INPUT}" | tr ',' '\n' | sed 's/^[[:space:]]*//;s/[[:space:]]*$//' | grep -v '^$' || true)
|
|
else
|
|
ECOSYSTEMS=$(curl -fsSL https://osv-vulnerabilities.storage.googleapis.com/ecosystems.txt | grep -v '^$' | grep -v '^\[EMPTY\]$' || true)
|
|
fi
|
|
|
|
if [ -z "${ECOSYSTEMS}" ]; then
|
|
echo "No ecosystems to download" >&2
|
|
exit 1
|
|
fi
|
|
|
|
download_one() {
|
|
local ecosystem="$1"
|
|
local encoded
|
|
encoded=$(printf '%s' "${ecosystem}" | jq -sRr @uri)
|
|
local dest="${DB_DIR}/${ecosystem}"
|
|
mkdir -p "${dest}"
|
|
echo "Downloading ${ecosystem}..."
|
|
curl -fsSL "https://osv-vulnerabilities.storage.googleapis.com/${encoded}/all.zip" -o "${dest}/all.zip"
|
|
}
|
|
|
|
max_jobs=8
|
|
pids=()
|
|
while IFS= read -r ecosystem; do
|
|
[ -z "${ecosystem}" ] && continue
|
|
while [ "$(jobs -rp | wc -l)" -ge "${max_jobs}" ]; do
|
|
sleep 0.2
|
|
done
|
|
download_one "${ecosystem}" &
|
|
pids+=("$!")
|
|
done <<< "${ECOSYSTEMS}"
|
|
|
|
fail=0
|
|
for pid in "${pids[@]}"; do
|
|
wait "${pid}" || fail=1
|
|
done
|
|
if [ "${fail}" -ne 0 ]; then
|
|
echo "One or more ecosystem database downloads failed" >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "Downloaded $(find "${DB_DIR}" -name all.zip | wc -l) ecosystem database(s) to ${DB_DIR}"
|
|
- name: Export DB cache directory
|
|
shell: bash
|
|
run: |
|
|
echo "OSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY=${{ inputs.cache-dir }}" >> "$GITHUB_ENV"
|