Skip to content

Only use mirrorToken in getManifest if it's provided#1548

Merged
HarithaVattikuti merged 2 commits into
actions:mainfrom
F-Secure-web:fix/only-use-mirror-token-for-manifest-if-set
Jun 9, 2026
Merged

Only use mirrorToken in getManifest if it's provided#1548
HarithaVattikuti merged 2 commits into
actions:mainfrom
F-Secure-web:fix/only-use-mirror-token-for-manifest-if-set

Conversation

@deiga

@deiga deiga commented May 11, 2026

Copy link
Copy Markdown
Contributor

Description:
When providing a mirror, but not a mirrorToken then getManifest will use the empty mirrorToken instead of any possible github token. This can lead to API Rate Limit exhaustion inadvertently.

The proposed fix is to only supply mirrorToken if it is actually set.

Related issue:
I couldn't find any directly related issues

Check list:

  • Mark if documentation changes are required.
  • Mark if tests were added or updated to cover the changes.

@deiga
deiga requested a review from a team as a code owner May 11, 2026 11:20
@noemiplatform

Copy link
Copy Markdown

no one should be allowed to make any changes

@priya-kinthali

Copy link
Copy Markdown
Contributor

Hi @deiga 👋
Thanks for this contribution! It looks like the dist/ folder hasn't been updated with your changes. Could you please run npm run build and commit the resulting changes to dist/? This ensures the action picks up your source code updates. Thanks!

Copilot AI review requested due to automatic review settings June 1, 2026 19:13
@deiga

deiga commented Jun 1, 2026

Copy link
Copy Markdown
Contributor Author

Doh! 🤦
@priya-kinthali thanks for letting me know :)

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

This PR adjusts how authentication tokens are selected when downloading Node distributions and fetching the node-versions manifest, preferring the mirror token only when it’s explicitly present.

Changes:

  • Update tc.downloadTool auth selection to use mirrorToken only when both mirror and mirrorToken are set.
  • Update tc.getManifestFromRepo auth selection similarly.
  • Regenerate/update the compiled dist/setup/index.js to reflect the source change.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated 2 comments.

File Description
src/distributions/official_builds/official_builds.ts Changes token selection logic for downloads and manifest fetches.
dist/setup/index.js Compiled output updated to match the source logic change.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/distributions/official_builds/official_builds.ts
Comment thread src/distributions/official_builds/official_builds.ts
deiga added 2 commits June 1, 2026 23:39
Signed-off-by: Timo Sand <timo.sand@f-secure.com>
Signed-off-by: Timo Sand <timo.sand@f-secure.com>
@deiga
deiga force-pushed the fix/only-use-mirror-token-for-manifest-if-set branch from f1a144b to bf9e4b9 Compare June 1, 2026 20:40
@HarithaVattikuti
HarithaVattikuti merged commit f4a67bb into actions:main Jun 9, 2026
228 of 231 checks passed
@deiga
deiga deleted the fix/only-use-mirror-token-for-manifest-if-set branch June 10, 2026 10:06
gowridurgad pushed a commit to gowridurgad/setup-node that referenced this pull request Jun 23, 2026
* Only use `mirrorToken` in `getManifest` if it's provided

Signed-off-by: Timo Sand <timo.sand@f-secure.com>

* `npm run build`

Signed-off-by: Timo Sand <timo.sand@f-secure.com>

---------

Signed-off-by: Timo Sand <timo.sand@f-secure.com>
gowridurgad pushed a commit to gowridurgad/setup-node that referenced this pull request Jun 29, 2026
* Only use `mirrorToken` in `getManifest` if it's provided

Signed-off-by: Timo Sand <timo.sand@f-secure.com>

* `npm run build`

Signed-off-by: Timo Sand <timo.sand@f-secure.com>

---------

Signed-off-by: Timo Sand <timo.sand@f-secure.com>
ajgon pushed a commit to deedee-ops/schemas that referenced this pull request Jul 14, 2026
#11)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/setup-node](https://github.com/actions/setup-node) | action | major | `v6.4.0` → `v7.0.0` |

---

### Release Notes

<details>
<summary>actions/setup-node (actions/setup-node)</summary>

### [`v7.0.0`](https://github.com/actions/setup-node/releases/tag/v7.0.0)

[Compare Source](actions/setup-node@v6.5.0...v7.0.0)

#### What's Changed

##### Enhancements:

- Add cache-primary-key and cache-matched-key as outputs by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1577](actions/setup-node#1577)
- Migrate to ESM and upgrade dependencies by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1574](actions/setup-node#1574)

##### Bug fixes:

- Remove dummy NODE\_AUTH\_TOKEN export by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1558](actions/setup-node#1558)
- Only use `mirrorToken` in `getManifest` if it's provided by [@&#8203;deiga](https://github.com/deiga) in [#&#8203;1548](actions/setup-node#1548)

##### Documentation updates:

- Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@&#8203;chiranjib-swain](https://github.com/chiranjib-swain) in [#&#8203;1536](actions/setup-node#1536)
- docs: Update restore-only cache documentation by [@&#8203;priya-kinthali](https://github.com/priya-kinthali) in [#&#8203;1550](actions/setup-node#1550)
- docs: Update caching recommendations to mitigate cache poisoning risks by [@&#8203;chiranjib-swain](https://github.com/chiranjib-swain) in [#&#8203;1567](actions/setup-node#1567)

##### Dependency update:

- Upgrade [@&#8203;actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@&#8203;jasongin](https://github.com/jasongin) in [#&#8203;1569](actions/setup-node#1569)

#### New Contributors

- [@&#8203;chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#&#8203;1536](actions/setup-node#1536)
- [@&#8203;deiga](https://github.com/deiga) made their first contribution in [#&#8203;1548](actions/setup-node#1548)
- [@&#8203;jasongin](https://github.com/jasongin) made their first contribution in [#&#8203;1569](actions/setup-node#1569)

**Full Changelog**: <actions/setup-node@v6...v7.0.0>

### [`v6.5.0`](https://github.com/actions/setup-node/releases/tag/v6.5.0)

[Compare Source](actions/setup-node@v6.4.0...v6.5.0)

#### What's Changed

- Update [@&#8203;actions/cache](https://github.com/actions/cache) to 5.1.0 and add security overrides for undici and fast-xml-parser by [@&#8203;HarithaVattikuti](https://github.com/HarithaVattikuti) in [#&#8203;1579](actions/setup-node#1579)

**Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0>

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Warsaw)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI2MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->

Reviewed-on: https://git.ajgon.casa/deedee/schemas/pulls/11
mergify Bot added a commit to ArcadeData/arcadedb that referenced this pull request Jul 19, 2026
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0.
Release notes

*Sourced from [actions/setup-node's releases](https://github.com/actions/setup-node/releases).*

> v7.0.0
> ------
>
> What's Changed
> --------------
>
> ### Enhancements:
>
> * Add cache-primary-key and cache-matched-key as outputs by [`@​gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1577](https://redirect.github.com/actions/setup-node/pull/1577)
> * Migrate to ESM and upgrade dependencies by [`@​gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1574](https://redirect.github.com/actions/setup-node/pull/1574)
>
> ### Bug fixes:
>
> * Remove dummy NODE\_AUTH\_TOKEN export by [`@​gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1558](https://redirect.github.com/actions/setup-node/pull/1558)
> * Only use `mirrorToken` in `getManifest` if it's provided by [`@​deiga`](https://github.com/deiga) in [actions/setup-node#1548](https://redirect.github.com/actions/setup-node/pull/1548)
>
> ### Documentation updates:
>
> * Add documentation for publishing to npm with Trusted Publisher (OIDC) by [`@​chiranjib-swain`](https://github.com/chiranjib-swain) in [actions/setup-node#1536](https://redirect.github.com/actions/setup-node/pull/1536)
> * docs: Update restore-only cache documentation by [`@​priya-kinthali`](https://github.com/priya-kinthali) in [actions/setup-node#1550](https://redirect.github.com/actions/setup-node/pull/1550)
> * docs: Update caching recommendations to mitigate cache poisoning risks by [`@​chiranjib-swain`](https://github.com/chiranjib-swain) in [actions/setup-node#1567](https://redirect.github.com/actions/setup-node/pull/1567)
>
> ### Dependency update:
>
> * Upgrade `@​actions/cache` to 5.1.0, log cache write denied by [`@​jasongin`](https://github.com/jasongin) in [actions/setup-node#1569](https://redirect.github.com/actions/setup-node/pull/1569)
>
> New Contributors
> ----------------
>
> * [`@​chiranjib-swain`](https://github.com/chiranjib-swain) made their first contribution in [actions/setup-node#1536](https://redirect.github.com/actions/setup-node/pull/1536)
> * [`@​deiga`](https://github.com/deiga) made their first contribution in [actions/setup-node#1548](https://redirect.github.com/actions/setup-node/pull/1548)
> * [`@​jasongin`](https://github.com/jasongin) made their first contribution in [actions/setup-node#1569](https://redirect.github.com/actions/setup-node/pull/1569)
>
> **Full Changelog**: <actions/setup-node@v6...v7.0.0>
>
> v6.5.0
> ------
>
> What's Changed
> --------------
>
> * Update `@​actions/cache` to 5.1.0 and add security overrides for undici and fast-xml-parser by [`@​HarithaVattikuti`](https://github.com/HarithaVattikuti) in [actions/setup-node#1579](https://redirect.github.com/actions/setup-node/pull/1579)
>
> **Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0>


Commits

* [`8207627`](actions/setup-node@8207627) Migrate to ESM and upgrade dependencies ([#1574](https://redirect.github.com/actions/setup-node/issues/1574))
* [`04be95c`](actions/setup-node@04be95c) Add cache-primary-key and cache-matched-key as outputs ([#1577](https://redirect.github.com/actions/setup-node/issues/1577))
* [`7c2c68d`](actions/setup-node@7c2c68d) docs: Update caching recommendations to mitigate cache poisoning risks ([#1567](https://redirect.github.com/actions/setup-node/issues/1567))
* [`6a61c03`](actions/setup-node@6a61c03) Merge pull request [#1569](https://redirect.github.com/actions/setup-node/issues/1569) from jasongin/update-actions-cache-5.1.0
* [`30eb73b`](actions/setup-node@30eb73b) Resolve high-severity audit issues
* [`4e1a87a`](actions/setup-node@4e1a87a) Update dist
* [`360237f`](actions/setup-node@360237f) Strict equality
* [`4f8aac5`](actions/setup-node@4f8aac5) Bump `@​actions/cache` to 5.1.0, log cache write denied
* [`f4a67bb`](actions/setup-node@f4a67bb) Only use `mirrorToken` in `getManifest` if it's provided ([#1548](https://redirect.github.com/actions/setup-node/issues/1548))
* [`0355742`](actions/setup-node@0355742) Remove dummy NODE\_AUTH\_TOKEN export ([#1558](https://redirect.github.com/actions/setup-node/issues/1558))
* Additional commits viewable in [compare view](actions/setup-node@48b55a0...8207627)
  
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility\_score?dependency-name=actions/setup-node&package-manager=github\_actions&previous-version=6.4.0&new-version=7.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
  
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
hypekostas pushed a commit to stellar/stellar-disbursement-platform-frontend that referenced this pull request Jul 20, 2026
…roup (#558)

Bumps the all-actions group with 1 update: [actions/setup-node](https://github.com/actions/setup-node).

Updates `actions/setup-node` from **6** to **7**

## Release notes

*Sourced from [actions/setup-node's releases](https://github.com/actions/setup-node/releases).*

> ## v7.0.0
>
> ## What's Changed
>
> ### Enhancements
> - Add `cache-primary-key` and `cache-matched-key` as outputs by [@gowridurgad](https://github.com/gowridurgad) in [actions/setup-node#1577](actions/setup-node#1577)
> - Migrate to ESM and upgrade dependencies by [@gowridurgad](https://github.com/gowridurgad) in [actions/setup-node#1574](actions/setup-node#1574)
>
> ### Bug fixes
> - Remove dummy `NODE_AUTH_TOKEN` export by [@gowridurgad](https://github.com/gowridurgad) in [actions/setup-node#1558](actions/setup-node#1558)
> - Only use `mirrorToken` in `getManifest` if it's provided by [@deiga](https://github.com/deiga) in [actions/setup-node#1548](actions/setup-node#1548)
>
> ### Documentation updates
> - Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@chiranjib-swain](https://github.com/chiranjib-swain) in [actions/setup-node#1536](actions/setup-node#1536)
> - Update restore-only cache documentation by [@priya-kinthali](https://github.com/priya-kinthali) in [actions/setup-node#1550](actions/setup-node#1550)
> - Update caching recommendations to mitigate cache poisoning risks by [@chiranjib-swain](https://github.com/chiranjib-swain) in [actions/setup-node#1567](actions/setup-node#1567)
>
> ### Dependency update
> - Upgrade `@actions/cache` to 5.1.0, log cache write denied by [@jasongin](https://github.com/jasongin) in [actions/setup-node#1569](actions/setup-node#1569)
>
> ### New Contributors
> - @chiranjib-swain (#1536)
> - @deiga (#1548)
> - @jasongin (#1569)
>
> **Full Changelog:** actions/setup-node@v6...v7.0.0
>
> ## v6.5.0
> - Update `@actions/cache` to 5.1.0 and add security overrides for `undici` and `fast-xml-parser`.
>
> **Full Changelog:** actions/setup-node@v6.4.0...v6.5.0
>
> ## v6.4.0
> - Upgrade `@actions` dependencies.
> - Update Node.js versions in `versions.yml` and bump package to v6.4.0.
>
> ## v6.3.0
> - Support parsing `devEngines` field.
>
> ... (remaining release notes truncated exactly as in the original)

## Commits

- `8207627` Migrate to ESM and upgrade dependencies (#1574)
- `04be95c` Add cache-primary-key and cache-matched-key as outputs (#1577)
- `7c2c68d` Update caching recommendations to mitigate cache poisoning risks (#1567)
- `6a61c03` Merge pull request #1569
- `30eb73b` Resolve high-severity audit issues
- `4e1a87a` Update dist
- `360237f` Strict equality
- `4f8aac5` Bump `@actions/cache` to 5.1.0
- `f4a67bb` Only use `mirrorToken` in `getManifest` if it's provided (#1548)
- `0355742` Remove dummy `NODE_AUTH_TOKEN` export (#1558)
- Additional commits viewable in the compare view.

---

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.

## Dependabot commands and options

- `@dependabot rebase`
- `@dependabot recreate`
- `@dependabot show <dependency name> ignore conditions`
- `@dependabot ignore <dependency name> major version`
- `@dependabot ignore <dependency name> minor version`
- `@dependabot ignore <dependency name>`
- `@dependabot unignore <dependency name>`
- `@dependabot unignore <dependency name> <ignore condition>`
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants