feat: release 2.7.0-rc2

This commit is contained in:
2026-10-06 15:31:51 +00:00 Unverified
parent cd9fb512cd
commit c8de9ddcba
42 changed files with 6127 additions and 593 deletions
+30
View File
@@ -17,6 +17,10 @@ export type WorkspaceManifest = {
};
export type BuildSpec = {
/** Absent means the legacy BuildKit Dockerfile builder. */
builder?: "buildkit" | "buildpacks";
/** GitHub release CNB package, optionally pinned with #sha256=<hex>. */
buildpackUri?: string;
architecture: BuildArchitecture;
image: string;
context: string;
@@ -65,6 +69,32 @@ export function isSha256Digest(value: unknown): value is Sha256Digest {
return typeof value === "string" && /^sha256:[a-f0-9]{64}$/.test(value);
}
export function validateBuildpackUri(value: unknown): asserts value is string {
if (typeof value !== "string" || value.length > 4096 || /[\s\\]/.test(value))
throw new Error("Invalid buildpack URI");
let url: URL;
try {
url = new URL(value);
} catch {
throw new Error("Invalid buildpack URI");
}
if (
url.protocol !== "https:" ||
url.hostname !== "github.com" ||
url.port ||
url.username ||
url.password ||
url.search ||
!/^\/[A-Za-z0-9_.-]+\/[A-Za-z0-9_.-]+\/releases\/download\/[^/]+\/[^/]+\.cnb$/.test(
url.pathname,
) ||
(url.hash && !/^#sha256=[a-f0-9]{64}$/.test(url.hash))
)
throw new Error(
"Buildpack URI must be an HTTPS GitHub release .cnb URL (optional #sha256=<hex>)",
);
}
export function assertSha256Digest(
value: unknown,
): asserts value is Sha256Digest {