Skip to content

Commit d0e6e4d

Browse files
dependabot[bot]brunoborgesCopilot
authored
chore(deps): bump the monthly-npm-updates group with 13 updates (#1276)
* chore(deps): bump the monthly-npm-updates group with 13 updates Bumps the monthly-npm-updates group with 13 updates: | Package | From | To | | --- | --- | --- | | [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) | `5.11.0` | `5.11.1` | | [@jest/globals](https://github.com/jestjs/jest/tree/HEAD/packages/jest-globals) | `30.4.1` | `30.5.2` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.2.0` | `26.6.2` | | [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.67.0` | `8.70.1` | | [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.67.0` | `8.70.1` | | [eslint](https://github.com/eslint/eslint) | `10.8.1` | `10.11.0` | | [eslint-plugin-jest](https://github.com/jest-community/eslint-plugin-jest) | `29.16.1` | `29.16.6` | | [globals](https://github.com/sindresorhus/globals) | `17.11.0` | `17.12.0` | | [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) | `30.4.2` | `30.5.2` | | [lint-staged](https://github.com/lint-staged/lint-staged) | `17.3.0` | `17.5.1` | | [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` | | [ts-jest](https://github.com/kulshekhar/ts-jest) | `29.4.12` | `29.4.13` | | [typescript](https://github.com/microsoft/TypeScript) | `6.0.3` | `7.0.2` | Updates `fast-xml-parser` from 5.11.0 to 5.11.1 - [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases) - [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md) - [Commits](NaturalIntelligence/fast-xml-parser@v5.11.0...v5.11.1) Updates `@jest/globals` from 30.4.1 to 30.5.2 - [Release notes](https://github.com/jestjs/jest/releases) - [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md) - [Commits](https://github.com/jestjs/jest/commits/v30.5.2/packages/jest-globals) Updates `@types/node` from 26.2.0 to 26.6.2 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `@typescript-eslint/eslint-plugin` from 8.67.0 to 8.70.1 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/eslint-plugin) Updates `@typescript-eslint/parser` from 8.67.0 to 8.70.1 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/parser) Updates `eslint` from 10.8.1 to 10.11.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.8.1...v10.11.0) Updates `eslint-plugin-jest` from 29.16.1 to 29.16.6 - [Release notes](https://github.com/jest-community/eslint-plugin-jest/releases) - [Changelog](https://github.com/jest-community/eslint-plugin-jest/blob/main/CHANGELOG.md) - [Commits](jest-community/eslint-plugin-jest@v29.16.1...v29.16.6) Updates `globals` from 17.11.0 to 17.12.0 - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.11.0...v17.12.0) Updates `jest` from 30.4.2 to 30.5.2 - [Release notes](https://github.com/jestjs/jest/releases) - [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md) - [Commits](https://github.com/jestjs/jest/commits/v30.5.2/packages/jest) Updates `lint-staged` from 17.3.0 to 17.5.1 - [Release notes](https://github.com/lint-staged/lint-staged/releases) - [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md) - [Commits](lint-staged/lint-staged@v17.3.0...v17.5.1) Updates `prettier` from 3.9.6 to 3.9.9 - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](prettier/prettier@3.9.6...3.9.9) Updates `ts-jest` from 29.4.12 to 29.4.13 - [Release notes](https://github.com/kulshekhar/ts-jest/releases) - [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md) - [Commits](kulshekhar/ts-jest@v29.4.12...v29.4.13) Updates `typescript` from 6.0.3 to 7.0.2 - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](microsoft/TypeScript@v6.0.3...v7.0.2) --- updated-dependencies: - dependency-name: fast-xml-parser dependency-version: 5.11.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: monthly-npm-updates - dependency-name: "@jest/globals" dependency-version: 30.5.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: monthly-npm-updates - dependency-name: "@types/node" dependency-version: 26.6.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: monthly-npm-updates - dependency-name: "@typescript-eslint/eslint-plugin" dependency-version: 8.70.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: monthly-npm-updates - dependency-name: "@typescript-eslint/parser" dependency-version: 8.70.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: monthly-npm-updates - dependency-name: eslint dependency-version: 10.11.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: monthly-npm-updates - dependency-name: eslint-plugin-jest dependency-version: 29.16.6 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: monthly-npm-updates - dependency-name: globals dependency-version: 17.12.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: monthly-npm-updates - dependency-name: jest dependency-version: 30.5.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: monthly-npm-updates - dependency-name: lint-staged dependency-version: 17.5.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: monthly-npm-updates - dependency-name: prettier dependency-version: 3.9.9 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: monthly-npm-updates - dependency-name: ts-jest dependency-version: 29.4.13 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: monthly-npm-updates - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major dependency-group: monthly-npm-updates ... Signed-off-by: dependabot[bot] <support@github.com> * Fix monthly npm update checks Keep TypeScript on the compatible 6.x line for the current @typescript-eslint peer range, rebuild dist, and refresh the fast-xml-parser license cache. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix monthly npm validation failures Update vulnerable transitive packages in the lockfile, rebuild dist, and correct the JetBrains test expectation for mocked Windows availability. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update licensed cache for npm updates Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Bruno Borges <brborges@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
1 parent b24925b commit d0e6e4d

6 files changed

Lines changed: 1194 additions & 662 deletions

File tree

‎.licenses/npm/fast-xml-parser.dep.yml‎

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎__tests__/distributors/jetbrains-installer.test.ts‎

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,6 @@ import type {IncomingMessage} from 'http';
1414
import {Readable} from 'stream';
1515

1616
import manifestData from '../data/jetbrains.json' with {type: 'json'};
17-
import os from 'os';
1817

1918
// Mock @actions/core before importing source modules that depend on it
2019
jest.unstable_mockModule('@actions/core', () => ({
@@ -81,6 +80,7 @@ describe('getAvailableVersions', () => {
8180
jest.setTimeout(10_000);
8281

8382
let spyHttpClient: any;
83+
let spyHttpClientHead: any;
8484
let spyCoreError: any;
8585
const originalGitHubToken = process.env.GITHUB_TOKEN;
8686

@@ -93,6 +93,10 @@ describe('getAvailableVersions', () => {
9393
headers: {},
9494
result: []
9595
});
96+
spyHttpClientHead = jest.spyOn(HttpClient.prototype, 'head');
97+
spyHttpClientHead.mockResolvedValue({
98+
message: {statusCode: 200}
99+
} as any);
96100

97101
// Mock core.error to suppress error logs
98102
spyCoreError = core.error as jest.Mock;
@@ -133,9 +137,7 @@ describe('getAvailableVersions', () => {
133137
const availableVersions = await distribution['getAvailableVersions']();
134138
expect(availableVersions).not.toBeNull();
135139

136-
const length =
137-
os.platform() === 'win32' ? manifestData.length : manifestData.length + 2;
138-
expect(availableVersions.length).toBe(length);
140+
expect(availableVersions.length).toBe(manifestData.length + 2);
139141
}, 10_000);
140142

141143
it('continues a stable request after an all-prerelease page', async () => {
@@ -358,6 +360,7 @@ describe('getAvailableVersions', () => {
358360

359361
it('retries a GitHub rate limit using Retry-After', async () => {
360362
spyHttpClient.mockRestore();
363+
spyHttpClientHead.mockRestore();
361364
const sleep = jest.fn(async () => undefined);
362365
const requestRaw = jest
363366
.spyOn(HttpClient.prototype, 'requestRaw')

‎dist/cleanup/767.index.js‎

Lines changed: 97 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -18360,9 +18360,102 @@ function readAttributeStr(xmlData, i) {
1836018360
}
1836118361

1836218362
/**
18363-
* Select all the attributes whether valid or invalid.
18364-
*/
18365-
const validAttrStrRegxp = new RegExp('(\\s*)([^\\s=]+)(\\s*=)?(\\s*([\'"])(([\\s\\S])*?)\\5)?', 'g');
18363+
* Walk `attrStr` once, left to right, splitting it into attribute tokens.
18364+
*
18365+
* This replaces a regex that used to do the same job
18366+
* (`(\s*)([^\s=]+)(\s*=)?(\s*(['"])(([\s\S])*?)\5)?`). That regex led with an
18367+
* optional whitespace group followed by a required "non-whitespace" group.
18368+
* On a long run of whitespace that never resolves into an attribute name
18369+
* (e.g. a tag with thousands of trailing spaces before `>`), the engine
18370+
* backtracks the whitespace group one character at a time before giving up
18371+
* and moving to the next starting position — one full backtrack per
18372+
* position, which is quadratic in the length of the run.
18373+
*
18374+
* A single forward-only scan can never backtrack, so it can't be made slow
18375+
* this way no matter how much whitespace the input contains — it's always
18376+
* proportional to the length of the string, once.
18377+
*
18378+
* Each returned token mirrors the shape the old regex match array had, so
18379+
* the validation logic below (which reads token[1]..token[6]) didn't need
18380+
* to change:
18381+
* token.startIndex - where this token begins in attrStr
18382+
* token[1] - leading whitespace before the name
18383+
* token[2] - the attribute name
18384+
* token[3] - whitespace + '=' if present, else undefined
18385+
* token[4] - marker (any defined value) if a quoted value was found
18386+
* token[5] - the quote character used ('"' or "'")
18387+
* token[6] - the value's text, without the surrounding quotes
18388+
*
18389+
* A malformed leading character (e.g. a stray '=' with no name before it)
18390+
* is simply skipped over, one character at a time — the same outcome the
18391+
* old regex produced by failing to match at that position and retrying at
18392+
* the next one.
18393+
*/
18394+
function scanAttributeTokens(attrStr) {
18395+
const tokens = [];
18396+
const len = attrStr.length;
18397+
let i = 0;
18398+
18399+
while (i < len) {
18400+
const tokenStart = i;
18401+
18402+
// Leading whitespace before the name.
18403+
while (i < len && isWhiteSpace(attrStr[i])) i++;
18404+
if (i >= len) break; // trailing whitespace only — nothing left to read
18405+
18406+
if (attrStr[i] === '=') {
18407+
// No name before this '=' — not a valid attribute start. Move past
18408+
// just this one character and try again from the next position.
18409+
i = tokenStart + 1;
18410+
continue;
18411+
}
18412+
18413+
const leadingWs = attrStr.slice(tokenStart, i);
18414+
18415+
// Attribute name — everything up to the next whitespace or '='.
18416+
const nameStart = i;
18417+
while (i < len && !isWhiteSpace(attrStr[i]) && attrStr[i] !== '=') i++;
18418+
const name = attrStr.slice(nameStart, i);
18419+
18420+
// Optional whitespace + '='.
18421+
let equalsGroup; // whitespace + '=' text, or undefined if absent
18422+
let j = i;
18423+
while (j < len && isWhiteSpace(attrStr[j])) j++;
18424+
if (j < len && attrStr[j] === '=') {
18425+
equalsGroup = attrStr.slice(i, j + 1);
18426+
i = j + 1;
18427+
}
18428+
18429+
// Optional whitespace + quoted value.
18430+
let quoteChar;
18431+
let value;
18432+
let k = i;
18433+
while (k < len && isWhiteSpace(attrStr[k])) k++;
18434+
if (k < len && (attrStr[k] === '"' || attrStr[k] === "'")) {
18435+
const valueStart = k + 1;
18436+
const closeIdx = attrStr.indexOf(attrStr[k], valueStart);
18437+
if (closeIdx !== -1) {
18438+
quoteChar = attrStr[k];
18439+
value = attrStr.slice(valueStart, closeIdx);
18440+
i = closeIdx + 1;
18441+
}
18442+
// No closing quote found anywhere in the rest of the string — leave
18443+
// quoteChar/value undefined, same as the old regex's group failing
18444+
// to match a backreference-less run.
18445+
}
18446+
18447+
const token = { startIndex: tokenStart };
18448+
token[1] = leadingWs;
18449+
token[2] = name;
18450+
token[3] = equalsGroup;
18451+
token[4] = quoteChar !== undefined ? true : undefined;
18452+
token[5] = quoteChar;
18453+
token[6] = value;
18454+
tokens.push(token);
18455+
}
18456+
18457+
return tokens;
18458+
}
1836618459

1836718460
//attr, ="sd", a="amit's", a="sd"b="saf", ab cd=""
1836818461

@@ -18371,7 +18464,7 @@ function validateAttributeString(attrStr, options) {
1837118464

1837218465
//if(attrStr.trim().length === 0) return true; //empty string
1837318466

18374-
const matches = getAllMatches(attrStr, validAttrStrRegxp);
18467+
const matches = scanAttributeTokens(attrStr);
1837518468
const attrNames = {};
1837618469

1837718470
for (let i = 0; i < matches.length; i++) {
@@ -18473,7 +18566,6 @@ function getLineNumberForPosition(xmlData, index) {
1847318566
function getPositionFromMatch(match) {
1847418567
return match.startIndex + match[1].length;
1847518568
}
18476-
1847718569
;// CONCATENATED MODULE: ./node_modules/fast-xml-parser/src/fxp.js
1847818570

1847918571

‎dist/setup/824.index.js‎

Lines changed: 96 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -418,9 +418,102 @@ function readAttributeStr(xmlData, i) {
418418
}
419419

420420
/**
421-
* Select all the attributes whether valid or invalid.
421+
* Walk `attrStr` once, left to right, splitting it into attribute tokens.
422+
*
423+
* This replaces a regex that used to do the same job
424+
* (`(\s*)([^\s=]+)(\s*=)?(\s*(['"])(([\s\S])*?)\5)?`). That regex led with an
425+
* optional whitespace group followed by a required "non-whitespace" group.
426+
* On a long run of whitespace that never resolves into an attribute name
427+
* (e.g. a tag with thousands of trailing spaces before `>`), the engine
428+
* backtracks the whitespace group one character at a time before giving up
429+
* and moving to the next starting position — one full backtrack per
430+
* position, which is quadratic in the length of the run.
431+
*
432+
* A single forward-only scan can never backtrack, so it can't be made slow
433+
* this way no matter how much whitespace the input contains — it's always
434+
* proportional to the length of the string, once.
435+
*
436+
* Each returned token mirrors the shape the old regex match array had, so
437+
* the validation logic below (which reads token[1]..token[6]) didn't need
438+
* to change:
439+
* token.startIndex - where this token begins in attrStr
440+
* token[1] - leading whitespace before the name
441+
* token[2] - the attribute name
442+
* token[3] - whitespace + '=' if present, else undefined
443+
* token[4] - marker (any defined value) if a quoted value was found
444+
* token[5] - the quote character used ('"' or "'")
445+
* token[6] - the value's text, without the surrounding quotes
446+
*
447+
* A malformed leading character (e.g. a stray '=' with no name before it)
448+
* is simply skipped over, one character at a time — the same outcome the
449+
* old regex produced by failing to match at that position and retrying at
450+
* the next one.
422451
*/
423-
const validAttrStrRegxp = new RegExp('(\\s*)([^\\s=]+)(\\s*=)?(\\s*([\'"])(([\\s\\S])*?)\\5)?', 'g');
452+
function scanAttributeTokens(attrStr) {
453+
const tokens = [];
454+
const len = attrStr.length;
455+
let i = 0;
456+
457+
while (i < len) {
458+
const tokenStart = i;
459+
460+
// Leading whitespace before the name.
461+
while (i < len && isWhiteSpace(attrStr[i])) i++;
462+
if (i >= len) break; // trailing whitespace only — nothing left to read
463+
464+
if (attrStr[i] === '=') {
465+
// No name before this '=' — not a valid attribute start. Move past
466+
// just this one character and try again from the next position.
467+
i = tokenStart + 1;
468+
continue;
469+
}
470+
471+
const leadingWs = attrStr.slice(tokenStart, i);
472+
473+
// Attribute name — everything up to the next whitespace or '='.
474+
const nameStart = i;
475+
while (i < len && !isWhiteSpace(attrStr[i]) && attrStr[i] !== '=') i++;
476+
const name = attrStr.slice(nameStart, i);
477+
478+
// Optional whitespace + '='.
479+
let equalsGroup; // whitespace + '=' text, or undefined if absent
480+
let j = i;
481+
while (j < len && isWhiteSpace(attrStr[j])) j++;
482+
if (j < len && attrStr[j] === '=') {
483+
equalsGroup = attrStr.slice(i, j + 1);
484+
i = j + 1;
485+
}
486+
487+
// Optional whitespace + quoted value.
488+
let quoteChar;
489+
let value;
490+
let k = i;
491+
while (k < len && isWhiteSpace(attrStr[k])) k++;
492+
if (k < len && (attrStr[k] === '"' || attrStr[k] === "'")) {
493+
const valueStart = k + 1;
494+
const closeIdx = attrStr.indexOf(attrStr[k], valueStart);
495+
if (closeIdx !== -1) {
496+
quoteChar = attrStr[k];
497+
value = attrStr.slice(valueStart, closeIdx);
498+
i = closeIdx + 1;
499+
}
500+
// No closing quote found anywhere in the rest of the string — leave
501+
// quoteChar/value undefined, same as the old regex's group failing
502+
// to match a backreference-less run.
503+
}
504+
505+
const token = { startIndex: tokenStart };
506+
token[1] = leadingWs;
507+
token[2] = name;
508+
token[3] = equalsGroup;
509+
token[4] = quoteChar !== undefined ? true : undefined;
510+
token[5] = quoteChar;
511+
token[6] = value;
512+
tokens.push(token);
513+
}
514+
515+
return tokens;
516+
}
424517

425518
//attr, ="sd", a="amit's", a="sd"b="saf", ab cd=""
426519

@@ -429,7 +522,7 @@ function validateAttributeString(attrStr, options) {
429522

430523
//if(attrStr.trim().length === 0) return true; //empty string
431524

432-
const matches = (0,_util_js__WEBPACK_IMPORTED_MODULE_0__/* .getAllMatches */ .Xe)(attrStr, validAttrStrRegxp);
525+
const matches = scanAttributeTokens(attrStr);
433526
const attrNames = {};
434527

435528
for (let i = 0; i < matches.length; i++) {
@@ -532,7 +625,6 @@ function getPositionFromMatch(match) {
532625
return match.startIndex + match[1].length;
533626
}
534627

535-
536628
/***/ }),
537629

538630
/***/ 6009:

0 commit comments

Comments
 (0)