Files
openclaw/scripts/lib/ghsa-patch-subprocess.mjs
tzy-17 828bcd8231 fix(scripts): bound GHSA patch GitHub lookups (#110756)
* fix(scripts): bound GHSA patch subprocesses

Co-authored-by: 唐梓夷0668001293 <tang.ziyi@xydigit.com>

* fix(scripts): satisfy GHSA runner control-flow lint

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-19 00:37:06 +01:00

23 lines
765 B
JavaScript

import { spawnSync } from "node:child_process";
// GHSA patch performs multiple sequential GitHub API reads and writes. Keep enough
// headroom for GitHub latency while preventing one stalled request from blocking
// the maintainer command indefinitely.
export const GHSA_COMMAND_TIMEOUT_MS = 60_000;
export function runGhCommand(args, params = {}) {
const spawnSyncImpl = params.spawnSyncImpl ?? spawnSync;
const proc = spawnSyncImpl("gh", args, {
encoding: "utf8",
killSignal: "SIGKILL",
timeout: params.timeoutMs ?? GHSA_COMMAND_TIMEOUT_MS,
});
if (proc.error) {
throw proc.error;
}
if (proc.status !== 0) {
throw new Error(proc.stderr.trim() || proc.stdout.trim() || `gh ${args.join(" ")} failed`);
}
return proc.stdout;
}