mirror of
https://github.com/erlef/setup-beam.git
synced 2026-07-23 07:06:07 +00:00
Act on CodeQL's suggestions for tightening security / improving performance (#338)
* Act on CodeQL's actions/missing-workflow-permissions https://codeql.github.com/codeql-query-help/actions/actions-missing-workflow-permissions/ * Be more specific in the matched regex And don't match a group if we don't need to match one * Make it slightly faster since we know what after -otp- I create a const because both expressions are looking for the same thing
This commit is contained in:
committed by
GitHub
parent
889e64e95a
commit
65066e38a0
+4
-3
@@ -193,10 +193,11 @@ function requestedVersionFor(tool, version, originListing, mirrors) {
|
||||
}
|
||||
|
||||
async function getElixirVersion(exSpec0, otpVersion0) {
|
||||
const otpVersion = otpVersion0.match(/^([^-]+-)?(.+)$/)[2]
|
||||
const otpVersion = otpVersion0.match(/^(?:OTP-)?(.+)$/)[1]
|
||||
let otpVersionMajor = otpVersion.match(/^([^.]+).*$/)[1]
|
||||
|
||||
const userSuppliedOtp = exSpec0.match(/-otp-(\d+)/)?.[1] ?? null
|
||||
const otpSuffix = /-otp-(\d+)/
|
||||
const userSuppliedOtp = exSpec0.match(otpSuffix)?.[1] ?? null
|
||||
|
||||
if (userSuppliedOtp && isVersion(userSuppliedOtp)) {
|
||||
otpVersionMajor = userSuppliedOtp
|
||||
@@ -204,7 +205,7 @@ async function getElixirVersion(exSpec0, otpVersion0) {
|
||||
|
||||
const [otpVersionsForElixirMap, elixirVersions, originListing, hexMirrors] =
|
||||
await getElixirVersions()
|
||||
const spec = exSpec0.replace(/-otp-.*$/, '')
|
||||
const spec = exSpec0.replace(otpSuffix, '')
|
||||
const versions = elixirVersions
|
||||
const elixirVersionFromSpec = getVersionFromSpec(spec, versions)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user