mirror of
https://github.com/astral-sh/setup-uv.git
synced 2026-08-25 19:43:50 +00:00
Reject paths in .tool-versions (#1007)
## Summary - reject path-like uv versions from `.tool-versions` - reject path-like Python versions from `.tool-versions` - document the restriction and cover Unix and Windows paths in tests ## Testing - `npm ci --ignore-scripts` - `npm run all` Refs: pi-session 019ff4bb-8b7c-7c4b-8bdf-7c188dfa2e3f
This commit is contained in:
@@ -113,6 +113,20 @@ describe("getUvVersionFromToolVersions", () => {
|
||||
);
|
||||
});
|
||||
|
||||
it.each(["/my/python/exploit", "my/exploited/uv", "C:\\exploited\\uv"])(
|
||||
"should warn and return undefined for path %s",
|
||||
async (version) => {
|
||||
mockReadFileSync.mockReturnValue(`uv ${version}`);
|
||||
|
||||
const result = await getVersionFromToolVersions(".tool-versions");
|
||||
|
||||
expect(result).toBeUndefined();
|
||||
expect(mockWarning).toHaveBeenCalledWith(
|
||||
`The uv version ${version} in .tool-versions is not supported. Paths are not allowed.`,
|
||||
);
|
||||
},
|
||||
);
|
||||
|
||||
it("should handle file path with .tool-versions extension", async () => {
|
||||
const fileContent = "uv 0.1.0";
|
||||
mockReadFileSync.mockReturnValue(fileContent);
|
||||
@@ -170,19 +184,23 @@ describe("getPythonVersionFromToolVersions", () => {
|
||||
);
|
||||
});
|
||||
|
||||
it.each(["ref:main", "path:~/src/python", "system"])(
|
||||
"should warn and return undefined for %s",
|
||||
async (version) => {
|
||||
mockReadFileSync.mockReturnValue(`python ${version}`);
|
||||
it.each([
|
||||
"ref:main",
|
||||
"path:~/src/python",
|
||||
"system",
|
||||
"/my/python/exploit",
|
||||
"my/exploited/python",
|
||||
"C:\\exploited\\python",
|
||||
])("should warn and return undefined for %s", async (version) => {
|
||||
mockReadFileSync.mockReturnValue(`python ${version}`);
|
||||
|
||||
const result = await getPythonVersionFromToolVersions(".tool-versions");
|
||||
const result = await getPythonVersionFromToolVersions(".tool-versions");
|
||||
|
||||
expect(result).toBeUndefined();
|
||||
expect(mockWarning).toHaveBeenCalledWith(
|
||||
`The Python version ${version} in .tool-versions is not supported. The Python entry will be ignored.`,
|
||||
);
|
||||
},
|
||||
);
|
||||
expect(result).toBeUndefined();
|
||||
expect(mockWarning).toHaveBeenCalledWith(
|
||||
`The Python version ${version} in .tool-versions is not supported. The Python entry will be ignored.`,
|
||||
);
|
||||
});
|
||||
|
||||
it("should return undefined for non-.tool-versions files", async () => {
|
||||
const result = await getPythonVersionFromToolVersions(".python-version");
|
||||
|
||||
Reference in New Issue
Block a user