SQSCANGHA-140 Add OpenPGP signature verification for scanner downloads (#235)

This commit is contained in:
Claire Villard authored and GitHub committed 2026-04-28 15:49:48 +02:00
1 parent 30dbe5c9ee
commit 55e44800a8
17 files changed
+33778 -41

No files matched your search

+31833
View File
File diff suppressed because it is too large. Load diff
+1
View File
@@ -0,0 +1 @@
{"version":3,"file":"exec-zlpfwmpH.js","sources":["../node_modules/@actions/core/lib/utils.js","../node_modules/@actions/core/lib/command.js","../node_modules/@actions/core/lib/file-command.js","../node_modules/@actions/http-client/lib/proxy.js","../node_modules/tunnel/lib/tunnel.js","../node_modules/tunnel/index.js","../node_modules/undici/lib/core/symbols.js","../node_modules/undici/lib/core/errors.js","../node_modules/undici/lib/core/constants.js","../node_modules/undici/lib/core/tree.js","../node_modules/undici/lib/core/util.js","../node_modules/undici/lib/core/diagnostics.js","../node_modules/undici/lib/core/request.js","../node_modules/undici/lib/dispatcher/dispatcher.js","../node_modules/undici/lib/dispatcher/dispatcher-base.js","../node_modules/undici/lib/util/timers.js","../node_modules/undici/lib/core/connect.js","../node_modules/undici/lib/llhttp/utils.js","../node_modules/undici/lib/llhttp/constants.js","../node_modules/undici/lib/llhttp/llhttp-wasm.js","../node_modules/undici/lib/llhttp/llhttp_simd-wasm.js","../node_modules/undici/lib/web/fetch/constants.js","../node_modules/undici/lib/web/fetch/global.js","../node_modules/undici/lib/web/fetch/data-url.js","../node_modules/undici/lib/web/fetch/webidl.js","../node_modules/undici/lib/web/fetch/util.js","../node_modules/undici/lib/web/fetch/symbols.js","../node_modules/undici/lib/web/fetch/file.js","../node_modules/undici/lib/web/fetch/formdata.js","../node_modules/undici/lib/web/fetch/formdata-parser.js","../node_modules/undici/lib/web/fetch/body.js","../node_modules/undici/lib/dispatcher/client-h1.js","../node_modules/undici/lib/dispatcher/client-h2.js","../node_modules/undici/lib/handler/redirect-handler.js","../node_modules/undici/lib/interceptor/redirect-interceptor.js","../node_modules/undici/lib/dispatcher/client.js","../node_modules/undici/lib/dispatcher/fixed-queue.js","../node_modules/undici/lib/dispatcher/pool-stats.js","../node_modules/undici/lib/dispatcher/pool-base.js","../node_modules/undici/lib/dispatcher/pool.js","../node_modules/undici/lib/dispatcher/balanced-pool.js","../node_modules/undici/lib/dispatcher/agent.js","../node_modules/undici/lib/dispatcher/proxy-agent.js","../node_modules/undici/lib/dispatcher/env-http-proxy-agent.js","../node_modules/undici/lib/handler/retry-handler.js","../node_modules/undici/lib/dispatcher/retry-agent.js","../node_modules/undici/lib/api/readable.js","../node_modules/undici/lib/api/util.js","../node_modules/undici/lib/api/api-request.js","../node_modules/undici/lib/api/abort-signal.js","../node_modules/undici/lib/api/api-stream.js","../node_modules/undici/lib/api/api-pipeline.js","../node_modules/undici/lib/api/api-upgrade.js","../node_modules/undici/lib/api/api-connect.js","../node_modules/undici/lib/api/index.js","../node_modules/undici/lib/mock/mock-errors.js","../node_modules/undici/lib/mock/mock-symbols.js","../node_modules/undici/lib/mock/mock-utils.js","../node_modules/undici/lib/mock/mock-interceptor.js","../node_modules/undici/lib/mock/mock-client.js","../node_modules/undici/lib/mock/mock-pool.js","../node_modules/undici/lib/mock/pluralizer.js","../node_modules/undici/lib/mock/pending-interceptors-formatter.js","../node_modules/undici/lib/mock/mock-agent.js","../node_modules/undici/lib/global.js","../node_modules/undici/lib/handler/decorator-handler.js","../node_modules/undici/lib/interceptor/redirect.js","../node_modules/undici/lib/interceptor/retry.js","../node_modules/undici/lib/interceptor/dump.js","../node_modules/undici/lib/interceptor/dns.js","../node_modules/undici/lib/web/fetch/headers.js","../node_modules/undici/lib/web/fetch/response.js","../node_modules/undici/lib/web/fetch/dispatcher-weakref.js","../node_modules/undici/lib/web/fetch/request.js","../node_modules/undici/lib/web/fetch/index.js","../node_modules/undici/lib/web/fileapi/symbols.js","../node_modules/undici/lib/web/fileapi/progressevent.js","../node_modules/undici/lib/web/fileapi/encoding.js","../node_modules/undici/lib/web/fileapi/util.js","../node_modules/undici/lib/web/fileapi/filereader.js","../node_modules/undici/lib/web/cache/symbols.js","../node_modules/undici/lib/web/cache/util.js","../node_modules/undici/lib/web/cache/cache.js","../node_modules/undici/lib/web/cache/cachestorage.js","../node_modules/undici/lib/web/cookies/constants.js","../node_modules/undici/lib/web/cookies/util.js","../node_modules/undici/lib/web/cookies/parse.js","../node_modules/undici/lib/web/cookies/index.js","../node_modules/undici/lib/web/websocket/events.js","../node_modules/undici/lib/web/websocket/constants.js","../node_modules/undici/lib/web/websocket/symbols.js","../node_modules/undici/lib/web/websocket/util.js","../node_modules/undici/lib/web/websocket/frame.js","../node_modules/undici/lib/web/websocket/connection.js","../node_modules/undici/lib/web/websocket/permessage-deflate.js","../node_modules/undici/lib/web/websocket/receiver.js","../node_modules/undici/lib/web/websocket/sender.js","../node_modules/undici/lib/web/websockLine truncated
+895 -21
View File
File diff suppressed because it is too large. Load diff
+1 -1
View File
@@ -1 +1 @@
{"version":3,"file":"index.js","sources":["../node_modules/semver/internal/constants.js","../node_modules/semver/internal/debug.js","../node_modules/semver/internal/re.js","../node_modules/semver/internal/parse-options.js","../node_modules/semver/internal/identifiers.js","../node_modules/semver/classes/semver.js","../node_modules/semver/functions/parse.js","../node_modules/semver/functions/valid.js","../node_modules/semver/functions/clean.js","../node_modules/semver/functions/inc.js","../node_modules/semver/functions/diff.js","../node_modules/semver/functions/major.js","../node_modules/semver/functions/minor.js","../node_modules/semver/functions/patch.js","../node_modules/semver/functions/prerelease.js","../node_modules/semver/functions/compare.js","../node_modules/semver/functions/rcompare.js","../node_modules/semver/functions/compare-loose.js","../node_modules/semver/functions/compare-build.js","../node_modules/semver/functions/sort.js","../node_modules/semver/functions/rsort.js","../node_modules/semver/functions/gt.js","../node_modules/semver/functions/lt.js","../node_modules/semver/functions/eq.js","../node_modules/semver/functions/neq.js","../node_modules/semver/functions/gte.js","../node_modules/semver/functions/lte.js","../node_modules/semver/functions/cmp.js","../node_modules/semver/functions/coerce.js","../node_modules/semver/internal/lrucache.js","../node_modules/semver/classes/range.js","../node_modules/semver/classes/comparator.js","../node_modules/semver/functions/satisfies.js","../node_modules/semver/ranges/to-comparators.js","../node_modules/semver/ranges/max-satisfying.js","../node_modules/semver/ranges/min-satisfying.js","../node_modules/semver/ranges/min-version.js","../node_modules/semver/ranges/valid.js","../node_modules/semver/ranges/outside.js","../node_modules/semver/ranges/gtr.js","../node_modules/semver/ranges/ltr.js","../node_modules/semver/ranges/intersects.js","../node_modules/semver/ranges/simplify.js","../node_modules/semver/ranges/subset.js","../node_modules/semver/index.js","../node_modules/@actions/tool-cache/lib/manifest.js","../node_modules/@actions/tool-cache/lib/retry-helper.js","../node_modules/@actions/tool-cache/lib/tool-cache.js","../src/main/utils.js","../src/main/install-sonar-scanner.js","../node_modules/string-argv/index.js","../src/main/run-sonar-scanner.js","../src/main/sanity-checks.js","../src/main/index.js"],"sourcesContent":["'use strict'\n\n// Note: this is the semver.org version of the spec that it implements\n// Not necessarily the package version of this code.\nconst SEMVER_SPEC_VERSION = '2.0.0'\n\nconst MAX_LENGTH = 256\nconst MAX_SAFE_INTEGER = Number.MAX_SAFE_INTEGER ||\n/* istanbul ignore next */ 9007199254740991\n\n// Max safe segment length for coercion.\nconst MAX_SAFE_COMPONENT_LENGTH = 16\n\n// Max safe length for a build identifier. The max length minus 6 characters for\n// the shortest version with a build 0.0.0+BUILD.\nconst MAX_SAFE_BUILD_LENGTH = MAX_LENGTH - 6\n\nconst RELEASE_TYPES = [\n 'major',\n 'premajor',\n 'minor',\n 'preminor',\n 'patch',\n 'prepatch',\n 'prerelease',\n]\n\nmodule.exports = {\n MAX_LENGTH,\n MAX_SAFE_COMPONENT_LENGTH,\n MAX_SAFE_BUILD_LENGTH,\n MAX_SAFE_INTEGER,\n RELEASE_TYPES,\n SEMVER_SPEC_VERSION,\n FLAG_INCLUDE_PRERELEASE: 0b001,\n FLAG_LOOSE: 0b010,\n}\n","'use strict'\n\nconst debug = (\n typeof process === 'object' &&\n process.env &&\n process.env.NODE_DEBUG &&\n /\\bsemver\\b/i.test(process.env.NODE_DEBUG)\n) ? (...args) => console.error('SEMVER', ...args)\n : () => {}\n\nmodule.exports = debug\n","'use strict'\n\nconst {\n MAX_SAFE_COMPONENT_LENGTH,\n MAX_SAFE_BUILD_LENGTH,\n MAX_LENGTH,\n} = require('./constants')\nconst debug = require('./debug')\nexports = module.exports = {}\n\n// The actual regexps go on exports.re\nconst re = exports.re = []\nconst safeRe = exports.safeRe = []\nconst src = exports.src = []\nconst safeSrc = exports.safeSrc = []\nconst t = exports.t = {}\nlet R = 0\n\nconst LETTERDASHNUMBER = '[a-zA-Z0-9-]'\n\n// Replace some greedy regex tokens to prevent regex dos issues. These regex are\n// used internally via the safeRe object since all inputs in this library get\n// normalized first to trim and collapse all extra whitespace. The original\n// regexes are exported for userland consumption and lower level usage. A\n// future breaking change could export the safer regex only with a note that\n// all input should have extra whitespace removed.\nconst safeRegexReplacements = [\n ['\\\\s', 1],\n ['\\\\d', MAX_LENGTH],\n [LETTERDASHNUMBER, MAX_SAFE_BUILD_LENGTH],\n]\n\nconst makeSafeRegex = (value) => {\n for (const [token, max] of safeRegexReplacements) {\n value = value\n .split(`${token}*`).join(`${token}{0,${max}}`)\n .split(`${token}+`).join(`${token}{1,${max}}`)\n }\n return value\n}\n\nconst createToken = (name, value, isGlobal) => {\n const safe = makeSafeRegex(value)\n const index = R++\n debug(name, index, value)\n t[name] = indLine truncated
{"version":3,"file":"index.js","sources":["../node_modules/semver/internal/constants.js","../node_modules/semver/internal/debug.js","../node_modules/semver/internal/re.js","../node_modules/semver/internal/parse-options.js","../node_modules/semver/internal/identifiers.js","../node_modules/semver/classes/semver.js","../node_modules/semver/functions/parse.js","../node_modules/semver/functions/valid.js","../node_modules/semver/functions/clean.js","../node_modules/semver/functions/inc.js","../node_modules/semver/functions/diff.js","../node_modules/semver/functions/major.js","../node_modules/semver/functions/minor.js","../node_modules/semver/functions/patch.js","../node_modules/semver/functions/prerelease.js","../node_modules/semver/functions/compare.js","../node_modules/semver/functions/rcompare.js","../node_modules/semver/functions/compare-loose.js","../node_modules/semver/functions/compare-build.js","../node_modules/semver/functions/sort.js","../node_modules/semver/functions/rsort.js","../node_modules/semver/functions/gt.js","../node_modules/semver/functions/lt.js","../node_modules/semver/functions/eq.js","../node_modules/semver/functions/neq.js","../node_modules/semver/functions/gte.js","../node_modules/semver/functions/lte.js","../node_modules/semver/functions/cmp.js","../node_modules/semver/functions/coerce.js","../node_modules/semver/internal/lrucache.js","../node_modules/semver/classes/range.js","../node_modules/semver/classes/comparator.js","../node_modules/semver/functions/satisfies.js","../node_modules/semver/ranges/to-comparators.js","../node_modules/semver/ranges/max-satisfying.js","../node_modules/semver/ranges/min-satisfying.js","../node_modules/semver/ranges/min-version.js","../node_modules/semver/ranges/valid.js","../node_modules/semver/ranges/outside.js","../node_modules/semver/ranges/gtr.js","../node_modules/semver/ranges/ltr.js","../node_modules/semver/ranges/intersects.js","../node_modules/semver/ranges/simplify.js","../node_modules/semver/ranges/subset.js","../node_modules/semver/index.js","../node_modules/@actions/tool-cache/lib/manifest.js","../node_modules/@actions/tool-cache/node_modules/@actions/exec/lib/toolrunner.js","../node_modules/@actions/tool-cache/node_modules/@actions/exec/lib/exec.js","../node_modules/@actions/tool-cache/lib/retry-helper.js","../node_modules/@actions/tool-cache/lib/tool-cache.js","../src/main/utils.js","../src/main/gpg-verification.js","../src/main/install-sonar-scanner.js","../node_modules/string-argv/index.js","../src/main/run-sonar-scanner.js","../src/main/sanity-checks.js","../src/main/index.js"],"sourcesContent":["'use strict'\n\n// Note: this is the semver.org version of the spec that it implements\n// Not necessarily the package version of this code.\nconst SEMVER_SPEC_VERSION = '2.0.0'\n\nconst MAX_LENGTH = 256\nconst MAX_SAFE_INTEGER = Number.MAX_SAFE_INTEGER ||\n/* istanbul ignore next */ 9007199254740991\n\n// Max safe segment length for coercion.\nconst MAX_SAFE_COMPONENT_LENGTH = 16\n\n// Max safe length for a build identifier. The max length minus 6 characters for\n// the shortest version with a build 0.0.0+BUILD.\nconst MAX_SAFE_BUILD_LENGTH = MAX_LENGTH - 6\n\nconst RELEASE_TYPES = [\n 'major',\n 'premajor',\n 'minor',\n 'preminor',\n 'patch',\n 'prepatch',\n 'prerelease',\n]\n\nmodule.exports = {\n MAX_LENGTH,\n MAX_SAFE_COMPONENT_LENGTH,\n MAX_SAFE_BUILD_LENGTH,\n MAX_SAFE_INTEGER,\n RELEASE_TYPES,\n SEMVER_SPEC_VERSION,\n FLAG_INCLUDE_PRERELEASE: 0b001,\n FLAG_LOOSE: 0b010,\n}\n","'use strict'\n\nconst debug = (\n typeof process === 'object' &&\n process.env &&\n process.env.NODE_DEBUG &&\n /\\bsemver\\b/i.test(process.env.NODE_DEBUG)\n) ? (...args) => console.error('SEMVER', ...args)\n : () => {}\n\nmodule.exports = debug\n","'use strict'\n\nconst {\n MAX_SAFE_COMPONENT_LENGTH,\n MAX_SAFE_BUILD_LENGTH,\n MAX_LENGTH,\n} = require('./constants')\nconst debug = require('./debug')\nexports = module.exports = {}\n\n// The actual regexps go on exports.re\nconst re = exports.re = []\nconst safeRe = exports.safeRe = []\nconst src = exports.src = []\nconst safeSrc = exports.safeSrc = []\nconst t = exports.t = {}\nlet R = 0\n\nconst LETTERDASHNUMBER = '[a-zA-Z0-9-]'\n\n// Replace some greedy regex tokens to prevent regex dos issues. These regex are\n// used internally via the safeRe object since all inputs in this library get\n// normalized first to trim and collapse all extra whitespace. The original\n// regexes are exported for userland consumption and lower level usage. A\n// future breaking change could export the safer regex only with a note that\n// all input should have extra whitespace removed.\nconst safeRegexReplacements = [\n ['\\\\s', 1],\n ['\\\\d', MAX_LENGTH],\n [LETTERDASHNUMBER, MAX_SAFE_BUILD_LENGTH],\n]\n\nconst makeSafeRegex = (value) => {\n for (const [token, max] of safeRegexReplacements) {\n value = value\n .split(`${token}*`).join(`${token}{0,${max}}`)\n .split(`${token}+`).join(`${tokeLine truncated
+7 -7
View File
@@ -1,4 +1,4 @@
import { h as getExecOutput, b as addPath, i as info, j as setOutput, s as setFailed, e as exec, k as startGroup, l as endGroup } from './core-DpWEmnbG.js';
import { f as execExports, h as addPath, a as info, n as setOutput, s as setFailed, o as startGroup, p as endGroup } from './exec-zlpfwmpH.js';
import * as fs from 'fs';
import * as path from 'path';
import 'os';
@@ -124,7 +124,7 @@ function getSuffixAndName(runnerOS, runnerArch) {
async function getRealPath(filePath, runnerOS) {
switch (runnerOS) {
case "Windows": {
const windowsResult = await getExecOutput("cygpath", [
const windowsResult = await execExports.getExecOutput("cygpath", [
"--absolute",
"--windows",
filePath,
@@ -132,14 +132,14 @@ async function getRealPath(filePath, runnerOS) {
return windowsResult.stdout.trim();
}
case "Linux": {
const linuxResult = await getExecOutput("readlink", [
const linuxResult = await execExports.getExecOutput("readlink", [
"-f",
filePath,
]);
return linuxResult.stdout.trim();
}
case "macOS": {
const macResult = await getExecOutput("greadlink", ["-f", filePath]);
const macResult = await execExports.getExecOutput("greadlink", ["-f", filePath]);
return macResult.stdout.trim();
}
default:
@@ -169,7 +169,7 @@ async function getRealPath(filePath, runnerOS) {
async function installMacOSPackages() {
if (process.platform === "darwin") {
info("Installing required packages for macOS");
await exec("brew", ["install", "coreutils"]);
await execExports.exec("brew", ["install", "coreutils"]);
}
}
@@ -207,10 +207,10 @@ async function downloadAndInstallBuildWrapper(downloadUrl, runnerEnv) {
fs.mkdirSync(runnerTemp, { recursive: true });
}
await exec("curl", ["-sSLo", tmpZipPath, downloadUrl]);
await execExports.exec("curl", ["-sSLo", tmpZipPath, downloadUrl]);
info("Decompressing");
await exec("unzip", ["-o", "-d", runnerTemp, tmpZipPath]);
await execExports.exec("unzip", ["-o", "-d", runnerTemp, tmpZipPath]);
endGroup();
}
+1 -1
View File
@@ -1 +1 @@
{"version":3,"file":"install-build-wrapper.js","sources":["../src/install-build-wrapper/utils.js","../src/install-build-wrapper/install-build-wrapper.js"],"sourcesContent":["// SonarQube Scan Action\n// Copyright (C) SonarSource Sàrl\n// mailto:contact AT sonarsource DOT com\n//\n// This program is free software; you can redistribute it and/or\n// modify it under the terms of the GNU Lesser General Public\n// License as published by the Free Software Foundation; either\n// version 3 of the License, or (at your option) any later version.\n//\n// This program is distributed in the hope that it will be useful,\n// but WITHOUT ANY WARRANTY; without even the implied warranty of\n// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU\n// Lesser General Public License for more details.\n//\n// You should have received a copy of the GNU Lesser General Public License\n// along with this program; if not, write to the Free Software Foundation,\n// Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.\n\nimport * as exec from \"@actions/exec\";\nimport * as path from \"path\";\n\n/**\n * Compute all names and paths related to the build wrapper\n * based on the runner environment\n */\nexport function getBuildWrapperInfo({\n runnerOS,\n runnerArch,\n runnerTemp,\n sonarHostUrl,\n}) {\n const { buildWrapperSuffix, buildWrapperName } = getSuffixAndName(\n runnerOS,\n runnerArch\n );\n\n const buildWrapperDir = `${runnerTemp}/build-wrapper-${buildWrapperSuffix}`;\n const buildWrapperUrl = `${sonarHostUrl}/static/cpp/build-wrapper-${buildWrapperSuffix}.zip`;\n const buildWrapperBin = `${buildWrapperDir}/${buildWrapperName}`;\n\n return {\n buildWrapperUrl,\n buildWrapperDir,\n buildWrapperBin,\n };\n}\n\nfunction getSuffixAndName(runnerOS, runnerArch) {\n if (\n runnerArch !== \"X64\" &&\n !(runnerArch === \"ARM64\" && (runnerOS === \"macOS\" || runnerOS === \"Linux\"))\n ) {\n throw new Error(\n `Architecture '${runnerArch}' is unsupported by build-wrapper`\n );\n }\n\n switch (runnerOS) {\n case \"Windows\":\n return {\n buildWrapperSuffix: \"win-x86\",\n buildWrapperName: \"build-wrapper-win-x86-64.exe\",\n };\n\n case \"Linux\":\n switch (runnerArch) {\n case \"X64\":\n return {\n buildWrapperSuffix: \"linux-x86\",\n buildWrapperName: \"build-wrapper-linux-x86-64\",\n };\n\n case \"ARM64\":\n return {\n buildWrapperSuffix: \"linux-aarch64\",\n buildWrapperName: \"build-wrapper-linux-aarch64\",\n };\n }\n break; // handled before the switch\n\n case \"macOS\":\n return {\n buildWrapperSuffix: \"macosx-x86\",\n buildWrapperName: \"build-wrapper-macosx-x86\",\n };\n\n default:\n throw new Error(`Unsupported runner OS '${runnerOS}'`);\n }\n}\n\nexport async function getRealPath(filePath, runnerOS) {\n switch (runnerOS) {\n case \"Windows\": {\n const windowsResult = await exec.getExecOutput(\"cygpath\", [\n \"--absolute\",\n \"--windows\",\n filePath,\n ]);\n return windowsResult.stdout.trim();\n }\n case \"Linux\": {\n const linuxResult = await exec.getExecOutput(\"readlink\", [\n \"-f\",\n filePath,\n ]);\n return linuxResult.stdout.trim();\n }\n case \"macOS\": {\n const macResult = await exec.getExecOutput(\"greadlink\", [\"-f\", filePath]);\n return macResult.stdout.trim();\n }\n default:\n return path.resolve(filePath);\n }\n}\n","// SonarQube Scan Action\n// Copyright (C) SonarSource Sàrl\n// mailto:contact AT sonarsource DOT com\n//\n// This program is free software; you can redistribute it and/or\n// modify it under the terms of the GNU Lesser General Public\n// License as published by the Free Software Foundation; either\n// version 3 of the License, or (at your option) any later version.\n//\n// This program is distributed in the hope that it will be useful,\n// but WITHOUT ANY WARRANTY; without even the implied warranty of\n// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU\n// Lesser General Public License for more details.\n//\n// You should have received a copy of the GNU Lesser General Public License\n// along with this program; if not, write to the Free Software Foundation,\n// Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.\n\nimport * as core from \"@actions/core\";\nimport * as exec from \"@actions/exec\";\nimport * as fs from \"fs\";\nimport * as path from \"path\";\nimport { getBuildWrapperInfo, getRealPath } from \"./utils\";\n\nasync function installMacOSPackages() {\n if (process.platform === \"darwin\") {\n core.info(\"Installing required packages for macOS\");\n await exec.exec(\"brew\", [\"install\", \"coreutils\"]);\n }\n}\n\n/**\n * These RUNNER_XX env variables come from GitHub by default.\n * See hLine truncated
{"version":3,"file":"install-build-wrapper.js","sources":["../src/install-build-wrapper/utils.js","../src/install-build-wrapper/install-build-wrapper.js"],"sourcesContent":["// SonarQube Scan Action\n// Copyright (C) SonarSource Sàrl\n// mailto:contact AT sonarsource DOT com\n//\n// This program is free software; you can redistribute it and/or\n// modify it under the terms of the GNU Lesser General Public\n// License as published by the Free Software Foundation; either\n// version 3 of the License, or (at your option) any later version.\n//\n// This program is distributed in the hope that it will be useful,\n// but WITHOUT ANY WARRANTY; without even the implied warranty of\n// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU\n// Lesser General Public License for more details.\n//\n// You should have received a copy of the GNU Lesser General Public License\n// along with this program; if not, write to the Free Software Foundation,\n// Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.\n\nimport * as exec from \"@actions/exec\";\nimport * as path from \"path\";\n\n/**\n * Compute all names and paths related to the build wrapper\n * based on the runner environment\n */\nexport function getBuildWrapperInfo({\n runnerOS,\n runnerArch,\n runnerTemp,\n sonarHostUrl,\n}) {\n const { buildWrapperSuffix, buildWrapperName } = getSuffixAndName(\n runnerOS,\n runnerArch\n );\n\n const buildWrapperDir = `${runnerTemp}/build-wrapper-${buildWrapperSuffix}`;\n const buildWrapperUrl = `${sonarHostUrl}/static/cpp/build-wrapper-${buildWrapperSuffix}.zip`;\n const buildWrapperBin = `${buildWrapperDir}/${buildWrapperName}`;\n\n return {\n buildWrapperUrl,\n buildWrapperDir,\n buildWrapperBin,\n };\n}\n\nfunction getSuffixAndName(runnerOS, runnerArch) {\n if (\n runnerArch !== \"X64\" &&\n !(runnerArch === \"ARM64\" && (runnerOS === \"macOS\" || runnerOS === \"Linux\"))\n ) {\n throw new Error(\n `Architecture '${runnerArch}' is unsupported by build-wrapper`\n );\n }\n\n switch (runnerOS) {\n case \"Windows\":\n return {\n buildWrapperSuffix: \"win-x86\",\n buildWrapperName: \"build-wrapper-win-x86-64.exe\",\n };\n\n case \"Linux\":\n switch (runnerArch) {\n case \"X64\":\n return {\n buildWrapperSuffix: \"linux-x86\",\n buildWrapperName: \"build-wrapper-linux-x86-64\",\n };\n\n case \"ARM64\":\n return {\n buildWrapperSuffix: \"linux-aarch64\",\n buildWrapperName: \"build-wrapper-linux-aarch64\",\n };\n }\n break; // handled before the switch\n\n case \"macOS\":\n return {\n buildWrapperSuffix: \"macosx-x86\",\n buildWrapperName: \"build-wrapper-macosx-x86\",\n };\n\n default:\n throw new Error(`Unsupported runner OS '${runnerOS}'`);\n }\n}\n\nexport async function getRealPath(filePath, runnerOS) {\n switch (runnerOS) {\n case \"Windows\": {\n const windowsResult = await exec.getExecOutput(\"cygpath\", [\n \"--absolute\",\n \"--windows\",\n filePath,\n ]);\n return windowsResult.stdout.trim();\n }\n case \"Linux\": {\n const linuxResult = await exec.getExecOutput(\"readlink\", [\n \"-f\",\n filePath,\n ]);\n return linuxResult.stdout.trim();\n }\n case \"macOS\": {\n const macResult = await exec.getExecOutput(\"greadlink\", [\"-f\", filePath]);\n return macResult.stdout.trim();\n }\n default:\n return path.resolve(filePath);\n }\n}\n","// SonarQube Scan Action\n// Copyright (C) SonarSource Sàrl\n// mailto:contact AT sonarsource DOT com\n//\n// This program is free software; you can redistribute it and/or\n// modify it under the terms of the GNU Lesser General Public\n// License as published by the Free Software Foundation; either\n// version 3 of the License, or (at your option) any later version.\n//\n// This program is distributed in the hope that it will be useful,\n// but WITHOUT ANY WARRANTY; without even the implied warranty of\n// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU\n// Lesser General Public License for more details.\n//\n// You should have received a copy of the GNU Lesser General Public License\n// along with this program; if not, write to the Free Software Foundation,\n// Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.\n\nimport * as core from \"@actions/core\";\nimport * as exec from \"@actions/exec\";\nimport * as fs from \"fs\";\nimport * as path from \"path\";\nimport { getBuildWrapperInfo, getRealPath } from \"./utils\";\n\nasync function installMacOSPackages() {\n if (process.platform === \"darwin\") {\n core.info(\"Installing required packages for macOS\");\n await exec.exec(\"brew\", [\"install\", \"coreutils\"]);\n }\n}\n\n/**\n * These RUNNER_XX env variables come from GitHub by default.\n * See hLine truncated