Skip to content

Commit f7fef95

Browse files
ai analysis addressed
ai analysis addressed feat: subscription check added
1 parent 44ddd98 commit f7fef95

3 files changed

Lines changed: 86 additions & 11 deletions

File tree

‎README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -354,7 +354,7 @@ dynamic values:
354354
> - If there's a cache hit, this will be 'true' or 'false' to indicate if there's an exact match for `key`.
355355
> - If there's a cache miss, this will be an empty string.
356356

357-
Example usage (inspired by [actions/cache@v5](https://github.com/actions/cache/blob/v5/README.md#skipping-steps-based-on-cache-hit) and [#346](https://github.com/step-security/flutter-action/pull/346)) to skip `melos bootstrap` if there was a pub cache hit:
357+
Example usage (inspired by [actions/cache@v5](https://github.com/actions/cache/blob/v5/README.md#skipping-steps-based-on-cache-hit) to skip `melos bootstrap` if there was a pub cache hit:
358358

359359
```yaml
360360
steps:

‎action.yaml‎

Lines changed: 63 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -90,6 +90,50 @@ outputs:
9090
runs:
9191
using: composite
9292
steps:
93+
- name: Subscription check
94+
shell: bash
95+
env:
96+
REPO_PRIVATE: ${{ github.event.repository.private }}
97+
run: |
98+
UPSTREAM="subosito/flutter-action"
99+
ACTION_REPO="${GITHUB_ACTION_REPOSITORY:-}"
100+
DOCS_URL="https://docs.stepsecurity.io/actions/stepsecurity-maintained-actions"
101+
102+
echo ""
103+
echo -e "\033[1;36mStepSecurity Maintained Action\033[0m"
104+
echo "Secure drop-in replacement for $UPSTREAM"
105+
if [ "$REPO_PRIVATE" = "false" ]; then
106+
echo -e "\033[32m✓ Free for public repositories\033[0m"
107+
fi
108+
echo -e "\033[36mLearn more:\033[0m $DOCS_URL"
109+
echo ""
110+
111+
if [ "$REPO_PRIVATE" != "false" ]; then
112+
SERVER_URL="${GITHUB_SERVER_URL:-https://github.com}"
113+
114+
if [ "$SERVER_URL" != "https://github.com" ]; then
115+
BODY=$(printf '{"action":"%s","ghes_server":"%s"}' "$ACTION_REPO" "$SERVER_URL")
116+
else
117+
BODY=$(printf '{"action":"%s"}' "$ACTION_REPO")
118+
fi
119+
120+
API_URL="https://agent.api.stepsecurity.io/v1/github/$GITHUB_REPOSITORY/actions/maintained-actions-subscription"
121+
122+
RESPONSE=$(curl --max-time 3 -s -w "%{http_code}" \
123+
-X POST \
124+
-H "Content-Type: application/json" \
125+
-d "$BODY" \
126+
"$API_URL" -o /dev/null) && CURL_EXIT_CODE=0 || CURL_EXIT_CODE=$?
127+
128+
if [ $CURL_EXIT_CODE -ne 0 ]; then
129+
echo "Timeout or API not reachable. Continuing to next step."
130+
elif [ "$RESPONSE" = "403" ]; then
131+
echo -e "::error::\033[1;31mThis action requires a StepSecurity subscription for private repositories.\033[0m"
132+
echo -e "::error::\033[31mLearn how to enable a subscription: $DOCS_URL\033[0m"
133+
exit 1
134+
fi
135+
fi
136+
93137
# This is a cross-platform composite action that needs yq in order to parse
94138
# the pubspec.yaml file.
95139
# It's not preinstalled on Windows runners.
@@ -106,17 +150,27 @@ runs:
106150
- name: Set action inputs
107151
id: flutter-action
108152
shell: bash
153+
env:
154+
FLUTTER_VERSION: ${{ inputs.flutter-version }}
155+
FLUTTER_VERSION_FILE: ${{ inputs.flutter-version-file }}
156+
FLUTTER_ARCHITECTURE: ${{ inputs.architecture }}
157+
FLUTTER_CACHE_KEY: ${{ inputs.cache-key }}
158+
FLUTTER_CACHE_PATH: ${{ inputs.cache-path }}
159+
FLUTTER_PUB_CACHE_KEY: ${{ inputs.pub-cache-key }}
160+
FLUTTER_PUB_CACHE_PATH: ${{ inputs.pub-cache-path }}
161+
FLUTTER_GIT_SOURCE: ${{ inputs.git-source }}
162+
FLUTTER_CHANNEL: ${{ inputs.channel }}
109163
run: |
110164
$GITHUB_ACTION_PATH/setup.sh -p \
111-
-n '${{ inputs.flutter-version }}' \
112-
-f '${{ inputs.flutter-version-file }}' \
113-
-a '${{ inputs.architecture }}' \
114-
-k '${{ inputs.cache-key }}' \
115-
-c '${{ inputs.cache-path }}' \
116-
-l '${{ inputs.pub-cache-key }}' \
117-
-d '${{ inputs.pub-cache-path }}' \
118-
-g '${{ inputs.git-source }}' \
119-
${{ inputs.channel }}
165+
-n "$FLUTTER_VERSION" \
166+
-f "$FLUTTER_VERSION_FILE" \
167+
-a "$FLUTTER_ARCHITECTURE" \
168+
-k "$FLUTTER_CACHE_KEY" \
169+
-c "$FLUTTER_CACHE_PATH" \
170+
-l "$FLUTTER_PUB_CACHE_KEY" \
171+
-d "$FLUTTER_PUB_CACHE_PATH" \
172+
-g "$FLUTTER_GIT_SOURCE" \
173+
"$FLUTTER_CHANNEL"
120174
121175
- name: Cache Flutter
122176
id: cache-flutter

‎setup.sh‎

Lines changed: 22 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -44,9 +44,29 @@ download_archive() {
4444
archive_url="$MANIFEST_BASE_URL/$1"
4545
archive_name=$(basename "$1")
4646
archive_local="$RUNNER_TEMP/$archive_name"
47+
expected_sha256="$3"
48+
49+
compute_sha256() {
50+
if check_command sha256sum; then
51+
sha256sum "$1" | awk '{print $1}'
52+
elif check_command shasum; then
53+
shasum -a 256 "$1" | awk '{print $1}'
54+
fi
55+
}
4756

4857
curl --connect-timeout 15 --retry 5 "$archive_url" >"$archive_local"
4958

59+
if [ -z "$expected_sha256" ] || [ "$expected_sha256" = "null" ]; then
60+
echo "Warning: no sha256 in manifest for $archive_name, skipping integrity check"
61+
else
62+
actual_sha256=$(compute_sha256 "$archive_local")
63+
if [ -z "$actual_sha256" ]; then
64+
echo "Warning: no sha256 tool found, skipping integrity check"
65+
elif [ "$actual_sha256" != "$expected_sha256" ]; then
66+
echo "Warning: checksum mismatch for $archive_name: expected $expected_sha256, got $actual_sha256"
67+
fi
68+
fi
69+
5070
mkdir -p "$2"
5171

5272
case "$archive_name" in
@@ -231,7 +251,8 @@ if [ ! -x "$CACHE_PATH/flutter/bin/flutter" ]; then
231251
fi
232252
else
233253
archive_url=$(echo "$VERSION_MANIFEST" | jq -r '.archive')
234-
download_archive "$archive_url" "$CACHE_PATH"
254+
archive_sha256=$(echo "$VERSION_MANIFEST" | jq -r '.sha256')
255+
download_archive "$archive_url" "$CACHE_PATH" "$archive_sha256"
235256
fi
236257
fi
237258

0 commit comments

Comments
 (0)