You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
v3.4.0 installs NPM plugins from the consumer workspace, then imports
them from the Find action. The install succeeds, but Node can't resolve
the package from `dist/pluginManager/pluginNpmLoader.js`.
This happened in [the alt text plugin
workflow](https://github.com/github/accessibility-scanner-alt-text-plugin/actions/runs/30406827436)
after switching to the new package object in #62.
This installs the package beside the loader module with an explicit npm
prefix. In the action that's `dist/pluginManager/node_modules`, so the
bare ESM import finds it without using `GITHUB_WORKSPACE`. Keeping the
install out of the Find action root also avoids npm re-resolving the
action's own dependencies.
The allowlist, version pinning, `--ignore-scripts`, `--no-save`,
`--no-package-lock`, duplicate handling, and warnings are unchanged.
I tested the exact input from #62:
```yaml
scans: |
["axe", {"name": "alt-text-scan", "package": "@github/accessibility-scanner-alt-text-plugin", "version": "1.1.0"}]
```
In a clean scanner copy with a separate consumer cwd, the published
1.1.0 package loaded from the compiled action. A local page produced
both the plugin's `placeholder-alt-text` finding and Axe's `button-name`
finding. The Find action's dependency versions were unchanged after the
install.
Also ran all 82 action tests, lint, format check, and the Find build. I
updated the scanner docs that still showed plugin 1.0.0 or described
`scans` as strings only.
This needs a scanner v3.4.1 after merge. The plugin stays on v1.1.0,
then its workflow pin can move from the v3.4.0 commit to the v3.4.1
commit.
Copy file name to clipboardExpand all lines: PLUGINS.md
+2-1Lines changed: 2 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -46,6 +46,7 @@ jobs:
46
46
## Loading plugins from NPM packages
47
47
48
48
In addition to local plugins under `./.github/scanner-plugins`, the scanner can install and load plugins published as NPM packages. This avoids having to vendor a plugin's source into your repo.
49
+
NPM package loading requires scanner v3.4.1 or later.
49
50
50
51
To use an NPM plugin, pass an object (instead of a plain string) in the `scans` input with the following fields:
See the [plugin README](https://github.com/github/accessibility-scanner-alt-text-plugin#getting-started) for the current release version, full rule list, and setup instructions.
description: 'Stringified JSON array of scans to perform. If not provided, only Axe will be performed'
67
+
description: "Stringified JSON array of scans to perform. Core engines and local plugins use string names. Allowlisted NPM plugins use an object with 'name', 'package', and optional 'version'. If not provided, only Axe will be performed"
68
68
required: false
69
69
dry_run:
70
70
description: 'When true, scan and log the issues that would be filed without opening, closing, reopening, or assigning any issues, and without writing to the cache.'
0 commit comments