Files
Pranay Prakash e2ef3568a5 CI script improvements (#1826)
* CI script improvements

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* address codex feedback: harden remaining workflows

- add allowlist regex in prepare-workbench-path to block path traversal
- move matrix/input values to env vars across e2e-vercel-prod,
  benchmarks (local/postgres/vercel), and the reusable community-world
  workflows
- validate app-name/world-id/world-package inputs in the reusable
  community-world workflows
- pipe getCommunityWorldsMatrix script output through jq -c to prevent
  \$GITHUB_OUTPUT injection

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-21 23:00:27 -07:00

40 lines
1.4 KiB
YAML

name: 'Prepare Workbench Path'
description: 'Resolve a workbench path, staging tarball-based Next.js workbenches when needed.'
inputs:
app-name:
description: 'Workbench app name from test matrix'
required: true
outputs:
workbench_app_path:
description: 'Resolved absolute path to the workbench used by tests'
value: ${{ steps.prepare.outputs.workbench_app_path }}
runs:
using: 'composite'
steps:
- id: prepare
shell: bash
env:
APP_NAME: ${{ inputs.app-name }}
run: |
if [[ ! "$APP_NAME" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]]; then
echo "Invalid app-name: $APP_NAME" >&2
exit 1
fi
if [[ "$APP_NAME" == "nextjs-turbopack" || "$APP_NAME" == "nextjs-webpack" ]]; then
STAGE_LOG="$(mktemp)"
node scripts/stage-workbench-with-tarballs.mjs "workbench/$APP_NAME" | tee "$STAGE_LOG"
WORKBENCH_APP_PATH="$(sed -n 's/^Staged workbench: //p' "$STAGE_LOG" | tail -n 1)"
if [ -z "$WORKBENCH_APP_PATH" ]; then
echo "Failed to parse staged workbench path from stage-workbench-with-tarballs output"
exit 1
fi
else
./scripts/resolve-symlinks.sh "workbench/$APP_NAME"
WORKBENCH_APP_PATH="$GITHUB_WORKSPACE/workbench/$APP_NAME"
fi
echo "workbench_app_path=$WORKBENCH_APP_PATH" >> "$GITHUB_OUTPUT"