Commit Graph

24 Commits

Author SHA1 Message Date
ilammy 6bcb337df2 msvc-dev-cmd v1.3.0 v1.3.0 2020-06-14 20:57:29 +03:00
Alexei Lozovsky be0a358ece Look for vcbuildtools.bat of VS 2015 as well (#9)
"Visual C++" has its build tool batch files in a different place.
Let's look there as well if we have not found 2017 or 2019 stuff.

Thanks to ReactOS project for figuring this out.

Co-authored-by: Victor Perevertkin <victor.perevertkin@reactos.org>
2020-06-14 20:55:01 +03:00
Oleh Prypin 5a6b51d5ac Refactor to not use the helper script (#6)
Choose vcvarsall.bat within JS code, call CMD directly with a command instead of writing a temporary file.
2020-05-09 21:24:12 +03:00
ilammy 074eec8db2 msvc-dev-cmd v1.2.0 v1.2.0 2020-04-30 21:28:00 +03:00
ilammy 9269bb4baf Bump transitive dependency versions
Resolve CVE-2020-7598 in minimis -- one of our transitive dependencies.
2020-04-30 21:23:23 +03:00
Nicolas Jarnoux ef0a58bd96 Enable other editions of msvc (#4)
I'll probably use self hosted runners in a project and the Community
version of Visual Studio will be installed on those. This enables the
script to check for Community and Professional editions in addition
to the Entreprise one offered by GitHub.

The modification generates a kinda search map ordered by version then
by edition. It generates the batch script that runs vcvarsall.bat
on the fly given that search map.
2020-04-26 23:54:04 +03:00
ilammy 52e66840de Prepare for next release 2020-03-19 09:03:19 +02:00
ilammy b5113e7e9d msvc-dev-cmd v1.1.0 v1.1.0 2020-03-19 08:51:27 +02:00
ilammy ddf4cb029f Fail audit on moderate and above vulnerabilities
Set the threshold to "moderate" and above. Currently msvc-dev-cmd has
an issue in transitive dev-dependency "minimist" [1] via somewhat long
chain of dependencies:

  - eslint > file-entry-cache > flat-cache > write > mkdirp > minimist
  - eslint > mkdirp > minimist

In order for this to be resolved all these packages need to do something
about their pinned versions. I don't want to sit there with a red build
because of some possible low-severity prototype pollution in dev
dependency. Anything higher -- okay, I'll look at at, and apply a fix
if necessary. (Maybe we should not audit dev dependencies at all...)

This particular vulnerability can be exploited by an attacker who can
submit a pull request and do "something bad"™ to Actions runners
executing jobs for this repository. However, since it's a dev
dependency, nothing will happen to our users. So we can safely ignore
this advisory.

[1]: https://npmjs.com/advisories/1179
2020-03-19 08:41:04 +02:00
ilammy 26cb400781 Run "npm audit" for release branch too
I'd like to be notified about weird vulnerabilities in JavaScript
libraries for the release branch as well. It's double important
since the release branch ships particular pinned version of *all*
dependencies.
2020-03-19 08:34:02 +02:00
Sean Kelly 075328686b Add VisualStudioVersion variable to exports (#3)
This variable seems to be necessary for some build tools like colcon:

https://colcon.readthedocs.io/en/released/
2020-03-19 08:24:49 +02:00
ilammy e6cca73138 Refresh dependencies
"npm audit" started whining about moderate denial of service
vulnerability in a dependency of dependency of dependency
(eslint > espree > acorn). This is not really serious because
we use "eslint" only for development. However, red builds are not good
so bump the pinned version in package.lock. (Released versions are not
affected because they do not include eslint.)
2020-03-12 12:54:03 +02:00
ilammy 1eed9c1215 msvc-dev-cmd v1.0.1 v1.0.1 2020-02-13 23:51:26 +02:00
ilammy aa189b6b13 Refresh dependencies
It's not like we need any new features, but let's bump the versions
because we are in JavaScript land.

Also, run "npm audit" regularly, just in case a serious vulnerability
is discovered.
2020-02-12 00:19:19 +02:00
ilammy 164e882247 Integration test for release version
Make sure that the released version is also fine. Run this test every
time a push is made into the release branch as well as on schedule.
2020-02-12 00:00:24 +02:00
ilammy a71277ef87 Use cmd.exe as shell
It works well and we don't need PowerShell which has weird notion of
default executable search path.
2020-02-12 00:00:24 +02:00
ilammy 987899132c Run test job at 06:00 every day
Well, it seems the environment is changing so we'd better run the tests
reguarly to see whether something breaks in a timely manner.

GitHub Actions also don't offer other Windows environments now, only
windows-latest is available. Reduce test matrix to only that.
2020-02-11 23:27:51 +02:00
ilammy 233eac407f msvc-dev-cmd v1.0.0 v1.0.0 2019-10-02 01:10:16 +03:00
ilammy 89d8017608 Fix eslint warnings 2019-10-02 01:09:14 +03:00
ilammy 5e81beaeab Correct badge in README 2019-10-02 00:59:07 +03:00
ilammy d33b04e19c Verify configured environment
Try compiling some C code, If it works then we're probably fine.
I don't even try to verify cross-compilation because I don't need it.
It should work, but that's not my problem right now.
2019-10-02 00:53:54 +03:00
ilammy cc105e3302 Initial batch file hack
Again, this is a squashed commit with around three hours of attempts
to write something working. See comments in the file for more details.
I'm too lazy to document this stuff properly.
2019-10-02 00:52:30 +03:00
ilammy 103b2da063 Remove garbage from README 2019-10-01 22:28:19 +03:00
ilammy 3fdf9b2e34 Initial action stub
Now that I know how to write some simple action, let's make a stub
more complete. For example, I already know what inputs I would like
to handle for this action.
2019-10-01 22:15:47 +03:00