Piping find to xargs is dangerous as xargs will interpret any characters
defined in $IFS (Input Field Separator), usually <space><tab><newline>,
as separators in its input. This might lead to unintented operations
on files if any of the input to xargs containts any of the characters
defined in $IFS, most often this happens if a file contains a space in
its name. The safest way to execute a find | xargs is to force find to
separate its output with null characters and tell xargs to read null
characters as the delimiter AND also tell xargs to put the argument to
the command its supposed to run in quotation marks:
`find ... -print0 | xargs -I {} -0 rm -rf "{}"`
When running with GNU find you most likely also want to add
--no-run-if-empty or -r for short:
`find ... -print0 | xargs -I {} -0 --no-run-if-empty rm -rf "{}"`
This stops the invocation of xargs if there is no input on stdin, this
is however not portable and will break on BSD/macOS, the portability is
not a concern in this case though as the find | xargs happens in docker.
As you can see this gets unwieldly fast and despite using every
precaution, it's still not safe. When xargs is run with -0 to treat null
characters as the delimiter for its input and a file has a null
character in its name, xargs will treat the null character in the file
name as a delimiter and xargs will exhibit the same behaviour as it did
with spaces in file names.
Ahhh, isn't Unix wonderful? Loose APIs defined as untyped strings...
There is a salvation though! Most find xargs pipes are unnecessary and
can be replaced with built in functionality in find, the -exec flag.
Now, -exec comes in 2 flavours, one that is terminated with \; (the most
commonly used) and one terminated with \+ (the one most people actually
want to use). \; spawns a new invocation per found entry, thus creating
some process creation overhead. \+ instead concatenates the found
entries as arguments to the program we want to run, resulting in less
overhead and usually a faster execution.
Since find is smart enough to be aware of what constitutes an entry
(i.e it doesn't treat the entries as just a bunch of random strings to
read from stdin) it makes the whole invocation of the program, rm in
this case, safe even if it contains characters defines in $IFS or null
characters.
And with this overly elaborate commit message I bring you this 1 line
change.
* 'master' of github.com:backstage/backstage: (118 commits)
cli: Fix handling of dynamic imports in esm.js files
minor typo in migration
chore(deps): bump archiver from 5.1.0 to 5.2.0
dockerfile: mention build-image command
Apply suggestions from code review
update backend Dockerfile to use config example and fix comment
docs: add full docker deployment docs
chore: fix code review
chore: fixing syntax
docs: fixing custom implementations of utitiy apis
a small start to the integrations section of the config
TechDocs: Add changeset about Docker permission fix
Updated unit tests for the new UI
TechDocs: Pass user and group ID when invoking docker container
Replace logging erro and return undefined for a throw new Error
@types/react 16 not 17
Use a more strict type for `variant` of cards
docs(TechDocs): Add more context with AWS docs hyperlinks
Added missing dep on @types/react
Removed unused import
...
* Fix client reference
* Fix CatalogClient reference in create-app too
* Move catalog-client dep to create-app
* Add catalog-client dep again..
* Use RequestOptions
* tsc
* Backwards compatible scaffolder
* Fix test
* Avoid importing core
* Use request options
* Increase code coverage
* Type those variables
* use the second mock
* Trying to make tests work on Github too
* Get clean yarn from master
* Only add authorization header if token exists
* Use request options
* Forward authorization header token
* Refactor to use context argument
* Allow the registration of optional locations via the catalog-client
* Make EntityRefLink a React.forwardRef in order to use it as root component in other components like ListItem
* Rework the user flow of the catalog-import plugin
* Update the create-app template
* Add luxon and remove moment
* Port moment to luxon
* Add change set
* Split the step label and content to be able to refactor the stepper from vertical to horizontal in the future
* Fix tsc, prettier and import issues
* Update .changeset/strange-olives-unite.md
Co-authored-by: Himanshu Mishra <himanshu@orkohunter.net>
* Update plugins/auth-backend/src/identity/TokenFactory.ts
Co-authored-by: Himanshu Mishra <himanshu@orkohunter.net>
* Change from minor to patch
* Update DatabaseKeyStore.ts
* feat: added a test for running a simple cypress server
* Add luxon and remove moment
* Port from moment to Luxon
* Add changeset
* Fixes following CR
* Rebased and reinstalled yarn.lock
* Changed to fromSQL
* Fix prettier formatting
* chore: reworking the lock file for the cypress deps
* chore: adding cypress.config
* chore: reworking some more examples
* chore: added some more simple stuff for e2e tests with cypress
* chore: reworking again
* chore: making cypress nice
* chore: added a sample test that works
* chore: reworking tests to use he cypress github-action instead
* chore: reconfigure Cypress run
* chore: don't install - we have deps
* chore: dump video recordings too
* chore: slimming down install script a little
* chore: make pretty
* chore: fixing syntax
* chore: fixing syntax again
* Align card elements with list
* Align card elements with List
* Add changeset
* Removed unused import
* chore: archive video footage with the correct path
* chore: fix lint warnings
* chore: fix prettier again
* chore: move files around for ease
* Added pattern for component name
* Add changeset
* stash: push to stash
* Return AboutCard title to group name
* Refactor children to use shared function
* TechDocs: Add visbility to migrate away from basic setup
* bugfix: [3310] Favoriting a component resets interface to your owned components
update changeset
remove unused import
fix changeset message
fix vale errors?
* Create utc DateTime object directly
* integration: update the gitlab config mandatory fields to match reality
* Resolve review comments
* Remove shadowed variables
* generateEntityDefinitions should return a PartialEntity
* Update roadmap with Backstage Community Sessions
* Make sure that SidebarItems are also active when on sub route
* Add whitespace around variable
* Add changeset
* Add word to dictionary
* Smater duration display
* Add changeset
* chore(deps-dev): bump @graphql-codegen/typescript from 1.18.1 to 1.20.2
Bumps [@graphql-codegen/typescript](https://github.com/dotansimha/graphql-code-generator/tree/HEAD/packages/plugins/typescript/typescript) from 1.18.1 to 1.20.2.
- [Release notes](https://github.com/dotansimha/graphql-code-generator/releases)
- [Changelog](https://github.com/dotansimha/graphql-code-generator/blob/master/packages/plugins/typescript/typescript/CHANGELOG.md)
- [Commits](https://github.com/dotansimha/graphql-code-generator/commits/@graphql-codegen/typescript@1.20.2/packages/plugins/typescript/typescript)
Signed-off-by: dependabot[bot] <support@github.com>
* chore: reworking folder structure to move cypress outside of the project
* chore: updating workflow to point at the right folder now
* chore: fixing cypress build
* microsite: Fix color contrast for pre tags
* Add package name to lockfile.ts error
* Create new-mangos-tap.md
* Changed changeset bump to be patch
* Pass registered Logger in ServiceBuilderImpl to requestLoggingHandler
`requestLoggingHandler` takes an optional `logger` parameter that it can use
to log incoming requests. The `ServiceBuilderImpl` was not passing on this logger, if
set, to `requestLoggingHandler` middleware
* Add indices on columns referring location(id)
* Add changeset
* Catch catalog errors
* Add changeset
* Fixed parseUrl to output catalogPaths beginning with '/'
* Add configurable OAuth 2.0 scopes
- Add oauth2 config for optional scopes
- Document oauth2 config keys
- Add OAuth2 to demo app list of identity providers
* incorrectly added callbackUrl
* chore: added a simple readme to run some simple tests against a backstage instance
* chore(deps): bump @svgr/plugin-jsx from 5.4.0 to 5.5.0
Bumps [@svgr/plugin-jsx](https://github.com/gregberge/svgr) from 5.4.0 to 5.5.0.
- [Release notes](https://github.com/gregberge/svgr/releases)
- [Changelog](https://github.com/gregberge/svgr/blob/main/CHANGELOG.md)
- [Commits](https://github.com/gregberge/svgr/compare/v5.4.0...v5.5.0)
Signed-off-by: dependabot[bot] <support@github.com>
* chore(deps): bump @types/cors from 2.8.6 to 2.8.9
Bumps [@types/cors](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/cors) from 2.8.6 to 2.8.9.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/cors)
Signed-off-by: dependabot[bot] <support@github.com>
* fix: removing test e2e-test tsconfig.json file
* TechDocs: Preparers will take and return an etag for cache invalidation
* TechDocs: Implement etag based caching for url preparer
Signed-off-by: Himanshu Mishra <himanshu@orkohunter.net>
* TechDocs: Implement etag based caching for git preparer
Signed-off-by: Himanshu Mishra <himanshu@orkohunter.net>
* TechDocs: Warn when using legacy git preparer and dir preparer in backstage.io/techdocs-ref
Context: https://github.com/backstage/backstage/issues/4409
* TechDocs: Update tests for proper url preparer caching
* TechDocs: Deduplicate git clone for cache check
Signed-off-by: Himanshu Mishra <himanshu@orkohunter.net>
* TechDocs: Add changesets for deprecation and proper caching
* TechDocs: Implement caching for dir preparer
* Update the changesets
* scaffolder-backend: remove auth-backend dependency
* catalog-client: rename ApiContext to CatalogRequestOptions + avoid export
* refactor existing usage of ApiContext
* techdocs: don't swallow errors other than NotModifiedError
* catalog-import: removed bonus code
* techdocs: meaningful logs when readTree starts
* Flatten the options of the CatalogImportPage
* inline optional id token auth headers
* Define relationship to software catalog and loose coupling by convention.
* Clarify intentions around bulk vs. incremental index management.
* Break apart backend plugins & clarify indexer/plugin relationship.
* update changeset bump levels
* [Search] documentation update (#4459)
* delete link to issue as it is closed
* replace usage of easy as its very subjective
* Update docs/features/search/architecture.md
Co-authored-by: Adam Harvey <adam.harvey@dxc.com>
* prettier....:
Co-authored-by: Adam Harvey <adam.harvey@dxc.com>
* Own it.
* scaffolder: include backstage identity token in requests
* review feedback tweaks
* docs/apis: update to use named plugin var
* sentry: update plugin instance export name
* clear other field when toggling reason
* changeset
* fix(pagerduty): use the luxon date library
* Don't pass default as a scope to OIDC providers
* docs(TechDocs): Add GitHub Actions CI example with AWS S3
* tech-radar: migrated to new composability API
* cost-insights: migrate to new composability API
* Changeset
* Fix line endings
* Prettier
* Remove unnecessary scopes from OIDC defaultApi
* Bump plugin-auth-backend to a minor change,
add documentation for fixing it
* Fix md syntax error
* Fix Vale spelling error
* Remove defaultScopes from OIDC api
* [ImgBot] Optimize images
/plugins/catalog-import/docs/catalog-import-screenshot.png -- 613.39kb -> 356.48kb (41.88%)
Signed-off-by: ImgBotApp <ImgBotHelp@gmail.com>
* github/workflows: use lax config checks
* Use commented-out example value for scope
* feat(pagerduty): add changeset
* Apply suggestions from code review
Co-authored-by: Rémi Doreau <32459935+ayshiff@users.noreply.github.com>
* feat(catalog): add entity links card component
* update entity links changeset
* Fix prettier
* chore(deps-dev): bump @types/http-proxy from 1.17.4 to 1.17.5
Bumps [@types/http-proxy](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/http-proxy) from 1.17.4 to 1.17.5.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/http-proxy)
Signed-off-by: dependabot[bot] <support@github.com>
* Revert "Merge pull request #3953 from ayshiff/feature/techdocs-aws-sdkv3"
This reverts commit 1c7771871e, reversing
changes made to 65d5c8e6fe.
* Revert "Merge pull request #4035 from ayshiff/feature/catalog-backend-aws-sdk-v3"
This reverts commit 1df9134648, reversing
changes made to d45a510069.
* Add changeset
* feat: support custom app icons
* backend-common: implement UrlReader.search for the other providers too
* Remove changeset
* docs(TechDocs): Improvements to the CI example
Signed-off-by: Himanshu Mishra <himanshu@orkohunter.net>
* fix(catalog): entity links incorrect wrapping
* Remove unused functions and luxon
* Removed old imports
* Fix broken links in documentation (#4418)
* Update IdentityApi.md
* Update docs/reference/utility-apis/IdentityApi.md
* Update docs/reference/utility-apis/IdentityApi.md
* ran yarn docgen
* Use JS Date instead of Datetime
* Add line
* Prettier fix
* Move parseDate function
* Version Packages
* chore: fix the create-app version
* Limit the props that are forwarded to the Link component in the EntityRefLink
* Use routed tabs to link to every settings page
* fix up yarn after release
* chore: add lockfile to words
* catalog-info: add links
* Export Select component from core
I saw the Select component on storybook and went
to use it but it seems it's not exported. Any chance
it could be exported?
* bug: filepath can be returned as undefined from `git-url-parse` let's default to empty
* chore: might as well do this for all parsing
* chore: changeset
* Add changeset for fixing requestLoggingHandler
* chore(deps-dev): bump @storybook/addon-actions from 6.1.11 to 6.1.17
Bumps [@storybook/addon-actions](https://github.com/storybookjs/storybook/tree/HEAD/addons/actions) from 6.1.11 to 6.1.17.
- [Release notes](https://github.com/storybookjs/storybook/releases)
- [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md)
- [Commits](https://github.com/storybookjs/storybook/commits/v6.1.17/addons/actions)
Signed-off-by: dependabot[bot] <support@github.com>
* Port AboutCard
* Fix tests
* Revert EntityPage changes
* docs: Merge auth glossary with main glossary
* Remove the "Move repository" menu entry from the catalog page, as it's just a placeholder
It will be easy to bring it back later, but for now it just confuses users that it's not doing anything. It's also hard to remove for integrators.
* make the template cards conform to mui standard
Co-authored-by: Erik Larsson <erik.larsson@schibsted.com>
Co-authored-by: Dominik Henneke <dominik.henneke@sda-se.com>
Co-authored-by: Nils Streijffert <nstreijffert@spotify.com>
Co-authored-by: Nils Streijffert <nils.streijffert@gmail.com>
Co-authored-by: Himanshu Mishra <himanshu@orkohunter.net>
Co-authored-by: blam <ben@blam.sh>
Co-authored-by: Nir Gazit <nir.gzt@gmail.com>
Co-authored-by: Adam Harvey <adam.harvey@dxc.com>
Co-authored-by: NHI TRAN <nhid@ntran.io>
Co-authored-by: Fredrik Adelöw <freben@gmail.com>
Co-authored-by: Oliver Sand <oliver.sand@sda-se.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Debajyoti Halder <rondebajyoti@gmail.com>
Co-authored-by: Patrik Oldsberg <poldsberg@gmail.com>
Co-authored-by: Gowind <petrovgovind@gmail.com>
Co-authored-by: Alan Crosswell <alan@columbia.edu>
Co-authored-by: Eric Peterson <ericpeterson@spotify.com>
Co-authored-by: Emma Indal <emma.indahl@gmail.com>
Co-authored-by: Ryan Vazquez <ryanv@spotify.com>
Co-authored-by: Ryan Vazquez <ryanmvazquez@gmail.com>
Co-authored-by: Remi <remi.d45@gmail.com>
Co-authored-by: Ryan Manny <rmanny@apptio.com>
Co-authored-by: ImgBotApp <ImgBotHelp@gmail.com>
Co-authored-by: Rémi Doreau <32459935+ayshiff@users.noreply.github.com>
Co-authored-by: Andrew Thauer <6507159+andrewthauer@users.noreply.github.com>
Co-authored-by: Joel Low <joel@joelsplace.sg>
Co-authored-by: Eric Peterson <iamEAP@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Iain Billett <iain@roadie.io>