The Global Block List shipped earlier but was never added to the README.
It applies to both the Community and Enterprise tiers, so it is listed
under Community (Free), which the Enterprise list already inherits.
The bundle was previously built against a stale node_modules
(@actions/cache 4.0.3) instead of the lockfile version (4.1.0), so the
committed dist did not match a clean-install build and build-check
failed.
Bump the TLS and bravo agent downloads to agent-ebpf v1.8.14 and update
the corresponding SHA256 checksums. Non-TLS, macOS, and Windows agents
are unchanged.
The post step exited early for all self-hosted runners, so an agent
deployed by the pre-step via deploy-on-self-hosted-vm never received the
job-end signal (post_event.json) and never flushed process and file
events. On ephemeral VMs such as AWS CodeBuild-hosted runners the VM is
destroyed right after the job, losing those events.
Record in GITHUB_STATE when the pre-step installs the agent on the VM
and run the same Linux cleanup as GitHub-hosted in that case. Persistent
self-hosted runners with a pre-installed agent keep the early exit.
CodeBuild-hosted runner VMs are ephemeral, so the persistent self-hosted
agent mode does not fit: its machine-scoped config carries no run_id or
one_time_key (process and file events are not attributed to the run) and
the post step exits without flushing events before the VM is destroyed.
Detect CODEBUILD_RUNNER_TYPE=GITHUB and route to the per-run bravo agent,
which reports run-scoped insights and flushes on job end.
On AWS CodeBuild-hosted runners the Actions runner executes as root and
the USER environment variable is not set, so the self-hosted install
path ran 'sudo chown -R undefined /home/agent' and agent installation
failed silently. Resolve the user via os.userInfo() when USER is unset,
and skip the chown instead of failing when no user can be determined.
handleLinuxCleanup and handleMacosCleanup also did an unconditional writeFileSync
to a path inside the agent dir, throwing ENOENT when Pre-step crashed before
installing the agent (proven by integration test on synthetic-reject branch).
Mirror the same dir-existence check that handleWindowsCleanup already has.
- Replace @actions/http-client socketTimeout with fetch + AbortSignal.timeout(3s)
on monitor, tls-inspect, policy fetch, policy-store fetch, and addSummary,
so DNS + TCP connect + TLS are bounded (was unbounded, causing ~2-4 min hangs)
- Add unhandledRejection guard in setup.ts and cleanup.ts so Node 22+ does not
silently kill the step on background async errors from third-party deps
- Skip Windows post-step cleanup when agent dir is missing (Pre-step crashed
before install), instead of throwing ENOENT on post_event.json
- Bump @types/node to ^24, typescript to ^5, ts-jest to ^29.4 to match node24
runtime and enable AbortSignal.timeout typings
Drop the parenthetical detail from UBUNTU_SLIM_MESSAGE so the user-facing
log is concise, and regenerate dist/ so the action can run from this
branch without a separate build step.
ubuntu-slim runners (Hosted Compute Agent Docker containers) are
GitHub-hosted but lack the standard USER environment variable set
on full VM-based runners. This causes chownForFolder to fail with
'chown: invalid user: undefined'.
Instead of patching chownForFolder, detect ubuntu-slim early
informative message, matching the existing patterns for isDocker(),
isARCRunner(), and other unsupported runner types.
Fixes#627
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>