refactor(scripts): migrate JavaScript tools to TypeScript (#121005)

* refactor(scripts): migrate JavaScript tools to TypeScript

* fix(ci): keep changed-scope preflight zero-install

* fix(ci): preserve zero-install script owners

* fix(ci): complete script migration follow-through

* fix(release): keep stable closeout zero-install

* fix(scripts): preserve standalone execution boundaries

* fix(scripts): repair standalone loader boundaries

* fix(scripts): normalize gateway observation ids

* fix(scripts): keep Docker packager standalone

* test(scripts): preserve rebase cleanup helpers

* test(sessions): use tracked temp directory
This commit is contained in:
Peter Steinberger
2026-08-09 07:21:35 -07:00
committed by GitHub
parent 2433fa213c
commit c70aee247e
937 changed files with 48087 additions and 50044 deletions
@@ -39,6 +39,16 @@ const securitySensitiveFiles = [
},
];
/**
* @typedef {{
* body?: string,
* created_at?: string,
* html_url?: string,
* user?: { login?: string },
* }} GuardComment
* @typedef {{ login: string, source: string }} GuardActorCandidate
*/
export function securitySensitiveFileDefinitions() {
return securitySensitiveFiles.map((entry) => ({ ...entry }));
}
@@ -84,6 +94,14 @@ function* securitySensitiveOverrideCandidates({ comments, expectedSha, newerThan
}
}
/**
* @param {{
* comments: GuardComment[],
* expectedSha: string | null,
* isSecurityMember: (login: string) => boolean,
* newerThan?: string,
* }} options
*/
export function findSecuritySensitiveOverrideCommand({
comments,
expectedSha,
@@ -102,6 +120,14 @@ export function findSecuritySensitiveOverrideCommand({
return null;
}
/**
* @param {{
* comments: GuardComment[],
* expectedSha: string | null,
* isSecurityMember: (login: string) => Promise<boolean>,
* newerThan?: string,
* }} input
*/
export async function findSecuritySensitiveOverrideCommandAsync(input) {
for (const candidate of securitySensitiveOverrideCandidates(input)) {
if (await input.isSecurityMember(candidate.login)) {
@@ -304,6 +330,12 @@ export function securitySensitiveGuardTrustedActorCandidates({
return guardTrustedActorCandidates({ pullRequest, event, currentHeadSha });
}
/**
* @param {{
* candidates: GuardActorCandidate[],
* isSecuritySensitiveApprover: (login: string) => Promise<string | null>,
* }} options
*/
export async function findTrustedSecuritySensitiveGuardActor({
candidates,
isSecuritySensitiveApprover,