feat: release 2.7.0-rc2
This commit is contained in:
@@ -17,6 +17,10 @@ export type WorkspaceManifest = {
|
||||
};
|
||||
|
||||
export type BuildSpec = {
|
||||
/** Absent means the legacy BuildKit Dockerfile builder. */
|
||||
builder?: "buildkit" | "buildpacks";
|
||||
/** GitHub release CNB package, optionally pinned with #sha256=<hex>. */
|
||||
buildpackUri?: string;
|
||||
architecture: BuildArchitecture;
|
||||
image: string;
|
||||
context: string;
|
||||
@@ -65,6 +69,32 @@ export function isSha256Digest(value: unknown): value is Sha256Digest {
|
||||
return typeof value === "string" && /^sha256:[a-f0-9]{64}$/.test(value);
|
||||
}
|
||||
|
||||
export function validateBuildpackUri(value: unknown): asserts value is string {
|
||||
if (typeof value !== "string" || value.length > 4096 || /[\s\\]/.test(value))
|
||||
throw new Error("Invalid buildpack URI");
|
||||
let url: URL;
|
||||
try {
|
||||
url = new URL(value);
|
||||
} catch {
|
||||
throw new Error("Invalid buildpack URI");
|
||||
}
|
||||
if (
|
||||
url.protocol !== "https:" ||
|
||||
url.hostname !== "github.com" ||
|
||||
url.port ||
|
||||
url.username ||
|
||||
url.password ||
|
||||
url.search ||
|
||||
!/^\/[A-Za-z0-9_.-]+\/[A-Za-z0-9_.-]+\/releases\/download\/[^/]+\/[^/]+\.cnb$/.test(
|
||||
url.pathname,
|
||||
) ||
|
||||
(url.hash && !/^#sha256=[a-f0-9]{64}$/.test(url.hash))
|
||||
)
|
||||
throw new Error(
|
||||
"Buildpack URI must be an HTTPS GitHub release .cnb URL (optional #sha256=<hex>)",
|
||||
);
|
||||
}
|
||||
|
||||
export function assertSha256Digest(
|
||||
value: unknown,
|
||||
): asserts value is Sha256Digest {
|
||||
|
||||
Reference in New Issue
Block a user