Skip to content

chore: Cherry-pick changes from upstream - #302

Open
anurag-stepsecurity wants to merge 3 commits into
mainfrom
auto-cherry-pick
Open

chore: Cherry-pick changes from upstream#302
anurag-stepsecurity wants to merge 3 commits into
mainfrom
auto-cherry-pick

Conversation

@anurag-stepsecurity

Copy link
Copy Markdown
Contributor

Signed-off-by: Anurag Rajawat <anurag@stepsecurity.io>
Signed-off-by: Anurag Rajawat <anurag@stepsecurity.io>
@anurag-stepsecurity
anurag-stepsecurity force-pushed the auto-cherry-pick branch 2 times, most recently from 6f91dcd to 7532f62 Compare September 11, 2026 05:35
@anurag-stepsecurity

Copy link
Copy Markdown
Contributor Author

📦 Target Release Version: v2.9.2
📋 Previous Release Version: v2.9.1

Signed-off-by: Anurag Rajawat <anurag@stepsecurity.io>
@github-actions

Copy link
Copy Markdown
Contributor

🔍 Cherry-Pick Verification Report

📦 Upstream Changes: v2.9.1...v2.9.2

📋 File-by-File Analysis:

.github/workflows/binstall.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 34 additions, 0 deletions)

.github/workflows/check-dist.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+3 -3)

.github/workflows/coverage.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+2 -2)

.github/workflows/dependabot.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 3 additions, 3 deletions)

.github/workflows/git-registry.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+1 -1)

.github/workflows/install.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+1 -1)

.github/workflows/multi-job-cache.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+2 -2)

.github/workflows/nix.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+2 -2)

.github/workflows/save-restore.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 70 additions, 0 deletions)

.github/workflows/simple.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+1 -1)

.github/workflows/target-dir.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+1 -1)

.github/workflows/warpbuild.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -5) | Missing 1 additions | Missing 1 deletions

.github/workflows/workspaces.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+1 -1)

.github/workflows/zizmor.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 2 additions, 2 deletions)

CHANGELOG.md

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 11 additions, 0 deletions)

README.md

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -5) | Missing 1 additions

action.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+3 -3)

rollup.config.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+11 -0)

src/cleanup.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All upstream changes applied (+36 -38) with 2 additional changes

src/config.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+31 -20)

src/restore.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+8 -7)

src/save.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+4 -4)

src/utils.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+6 -16)

src/workspace.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All upstream changes applied (+12 -5) with 3 additional changes

tsconfig.json

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+10 -5) | Missing 2 deletions

📊 Summary:

  • Total files changed upstream: 25
  • Files present in PR: 11/25
  • Files with matching changes: 8/25

Overall Status: 🔴 INCOMPLETE - Missing files or changes

@github-actions

Copy link
Copy Markdown
Contributor

PR Review

Action Type

Node-based - uses node24 runtime with dist/restore.js as main and dist/save.js as post entry points (migrated from ncc to Rollup flat-dist layout in this PR).


Passed Checks

  • SECURITY.md - present.
  • FUNDING.yml - not present.
  • renovate.json - not present.
  • PULL_REQUEST.md - not present.
  • ISSUE_TEMPLATE folder - not present.
  • CHANGELOG.md - not present.
  • .vscode folder - not present.
  • .github/workflows/auto_cherry_pick.yml - present.
  • .github/workflows/actions_release.yml - present, uses reusable-workflows@v1.
  • README.md banner - StepSecurity maintained-action banner is present.
  • README.md usage examples - use step-security/rust-cache@v2 (major version only).
  • Subscription check URL - src/restore.ts calls the correct maintained-actions-subscription endpoint.
  • Upstream variable - upstream = Swatinem/rust-cache matches original-owner + repo-name in auto_cherry_pick.yml.
  • action.yml author - field absent; skipped per rules.
  • package.json author - field absent; skipped per rules.
  • package.json repository - contains step-security.
  • dist folder - present with restore.js, save.js, and all chunk modules.
  • All dependencies used - all eight runtime deps are referenced in source files.
  • build script present - package.json has a build field; script input check on release workflows not required.
  • auto_cherry_pick.yml - migrated from branch pin to stable tag @v1.

Failed Checks

  • LICENSE - missing original author copyright. The LICENSE file has Copyright (c) 2024 StepSecurity but no copyright line for the original upstream author Swatinem. Both copyrights must appear. Please add: Copyright (c) Swatinem and contributors

Warnings

  • Dead condition in auto_cherry_pick.yml - The job if: clause includes github.event_name == workflow_run but the workflow on: block only declares workflow_dispatch and pull_request triggers. This clause can never be true. Either add a workflow_run trigger to on: or remove the clause.

  • Subscription check absent from save.ts - validateSubscription() is called only in restore.ts; the post-step save.ts has no check. Confirm this is deliberate if failing early at restore is the intended design.

  • cmdFormat allows shell metacharacters - config.ts validates exactly one placeholder but does not strip shell metacharacters. Low severity since only the workflow author controls this input.

  • Stale Rollup chunks - dist/ now contains many content-hashed chunk files that accumulate across builds. Consider a clean step in the build script.


Security Findings

No critical security issues found. The cmdFormat metacharacter concern is low severity and scoped to the workflow author.


Summary

This PR cherry-picks upstream v2.9.1 to v2.9.2 changes: removes buildjet support, migrates build toolchain from ncc to Rollup (ESM output), fixes missing await on getCacheProvider(), and expands SAVE_TARGETS to include cdylib/dylib/rlib/staticlib. The single blocking issue is the LICENSE file missing a copyright line for the original upstream author (Swatinem). The dead workflow_run condition in auto_cherry_pick.yml should also be cleaned up.

cherry-pick:
if: github.event_name == 'workflow_dispatch' || contains(fromJson(toJson(github.event.pull_request.labels)).*.name, 'review-required')
uses: step-security/reusable-workflows/.github/workflows/auto_cherry_pick.yaml@fix_Verify_cherry_pick-Logic
if: (github.event_name == 'workflow_run' && github.event.workflow_run.conclusion == 'success') || github.event_name == 'workflow_dispatch' || contains(fromJson(toJson(github.event.pull_request.labels)).*.name, 'review-required')

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dead condition — workflow_run trigger is missing.

The if: clause includes github.event_name == 'workflow_run' but the workflow's on: block only declares workflow_dispatch and pull_request triggers. A workflow_run event can never reach this workflow, so this branch of the condition is unreachable dead code.

Either add a workflow_run: trigger to on: (if the intent is to fire after another workflow completes), or remove the workflow_run clause:

Suggested change
if: (github.event_name == 'workflow_run' && github.event.workflow_run.conclusion == 'success') || github.event_name == 'workflow_dispatch' || contains(fromJson(toJson(github.event.pull_request.labels)).*.name, 'review-required')
if: github.event_name == 'workflow_dispatch' || contains(fromJson(toJson(github.event.pull_request.labels)).*.name, 'review-required')

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant