Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Validate checksum metadata value types
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: a800a031-600e-4d28-b23e-be309555d38d
  • Loading branch information
brunoborges committed Jul 29, 2026
commit eb35a583586bb1b895a835a3515a907885cae955
19 changes: 19 additions & 0 deletions __tests__/checksum.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,25 @@ describe('verifyChecksum', () => {
);
});

it.each([undefined, null, 123])(
'reports a malformed digest when the value is %p',
async value => {
const checksum = {
algorithm: 'sha256',
value
} as unknown as ChecksumMetadata;

await expect(
verifyChecksum('/missing/archive', checksum, {
distribution: 'Test',
version: '17'
})
).rejects.toThrow(
'Malformed sha256 checksum metadata: expected a 64-character hexadecimal digest.'
);
}
);

it('rejects unsupported algorithms without leaking source query parameters', async () => {
const checksum = {
algorithm: 'md5',
Expand Down
14 changes: 11 additions & 3 deletions dist/setup/index.js
Original file line number Diff line number Diff line change
Expand Up @@ -129431,7 +129431,9 @@ function sanitizedSource(source) {
}
function normalizeExpectedDigest(checksum) {
const algorithm = checksum.algorithm;
const digest = checksum.value.trim().toLowerCase();
const digest = typeof checksum.value === 'string'
? checksum.value.trim().toLowerCase()
: '';
const expectedLength = algorithm === 'sha256' ? 64 : algorithm === 'sha512' ? 128 : 0;
if (expectedLength === 0) {
throw new Error(`Unsupported checksum algorithm '${String(algorithm)}'${sanitizedSource(checksum.source)}. Supported algorithms are sha256 and sha512.`);
Expand Down Expand Up @@ -129515,11 +129517,17 @@ class JavaBase {
return archivePath;
}
catch (error) {
let cleanupError;
let cleanupFailed = false;
try {
await external_fs_namespaceObject.promises.rm(archivePath, { force: true });
}
catch (cleanupError) {
throw new Error(`${error.message} Failed to remove the downloaded archive after verification failure: ${cleanupError.message}`, { cause: cleanupError });
catch (caughtCleanupError) {
cleanupError = caughtCleanupError;
cleanupFailed = true;
}
if (cleanupFailed) {
throw new Error(`${error.message} Failed to remove the downloaded archive after verification failure: ${cleanupError.message}`, { cause: error });
}
throw error;
}
Expand Down
5 changes: 4 additions & 1 deletion src/checksum.ts
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,10 @@ function sanitizedSource(source: string | undefined): string {

function normalizeExpectedDigest(checksum: ChecksumMetadata): string {
const algorithm = checksum.algorithm;
const digest = checksum.value.trim().toLowerCase();
const digest =
typeof checksum.value === 'string'
? checksum.value.trim().toLowerCase()
: '';
const expectedLength =
algorithm === 'sha256' ? 64 : algorithm === 'sha512' ? 128 : 0;

Expand Down
Loading