mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
feat: emit cloud events for dependency cooldown and host observations (#243)
* feat: emit cloud events for dependency cooldown and host observations (#237) Wire cooldown blocks and proxy host observations through the cloud sync pipeline so they appear as telemetry in Control Tower. - Cooldown blocks emit PACKAGE_DECISION with COOLDOWN_BLOCKED action and PmgDependencyCooldown context (publish date, cooldown days, days since publish, days remaining) - Proxy host observations emit HOST_OBSERVATION with PmgHostObservation (hostname, method) - Session summary now includes cooldown_blocked_count - Updated buf API dependency for new proto schema Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * format file * fix: add explicit eventlog mapping for EventTypeDependencyCooldown Follow the existing pattern where every audit event type has an explicit case in mapEventType and a corresponding constant in the eventlog package. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * Apply suggestion from @devin-ai-integration[bot] Co-authored-by: devin-ai-integration[bot] <158243242+devin-ai-integration[bot]@users.noreply.github.com> Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> --------- Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: Abhisek Datta <abhisek.datta@gmail.com> Co-authored-by: devin-ai-integration[bot] <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
devin-ai-integration[bot] <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Abhisek Datta
devin-ai-integration[bot] <158243242+devin-ai-integration[bot]@users.noreply.github.com>
parent
b671192598
commit
19d735cdd2
@@ -5,6 +5,7 @@ import (
|
||||
|
||||
controltowerv1 "buf.build/gen/go/safedep/api/protocolbuffers/go/safedep/messages/controltower/v1"
|
||||
"google.golang.org/protobuf/types/known/durationpb"
|
||||
"google.golang.org/protobuf/types/known/timestamppb"
|
||||
)
|
||||
|
||||
func (s *cloudSink) translateToPmgEvents(event AuditEvent) []*controltowerv1.PmgEvent {
|
||||
@@ -18,6 +19,10 @@ func (s *cloudSink) translateToPmgEvents(event AuditEvent) []*controltowerv1.Pmg
|
||||
// not a per-package event. It is emitted as part of EventTypeSessionComplete when
|
||||
// the session's insecureBypassed counter is > 0.
|
||||
return nil
|
||||
case EventTypeDependencyCooldown:
|
||||
return []*controltowerv1.PmgEvent{newCooldownBlockedEvent(event)}
|
||||
case EventTypeProxyHostObserved:
|
||||
return []*controltowerv1.PmgEvent{newHostObservationEvent(event)}
|
||||
case EventTypeSandboxOverride:
|
||||
return []*controltowerv1.PmgEvent{newSandboxOverrideEvent(event)}
|
||||
case EventTypeError:
|
||||
@@ -84,6 +89,37 @@ func newErrorEvent(event AuditEvent) *controltowerv1.PmgEvent {
|
||||
return e
|
||||
}
|
||||
|
||||
func newCooldownBlockedEvent(event AuditEvent) *controltowerv1.PmgEvent {
|
||||
decision := &controltowerv1.PmgPackageDecision{}
|
||||
decision.SetPackageVersion(event.PackageVersion)
|
||||
decision.SetAction(controltowerv1.PmgPackageAction_PMG_PACKAGE_ACTION_COOLDOWN_BLOCKED)
|
||||
|
||||
cooldown := &controltowerv1.PmgDependencyCooldown{}
|
||||
if !event.PublishDate.IsZero() {
|
||||
cooldown.SetPublishDate(timestamppb.New(event.PublishDate))
|
||||
}
|
||||
cooldown.SetCooldownDays(uint32(event.CooldownDays))
|
||||
cooldown.SetDaysSincePublish(uint32(event.DaysAgo))
|
||||
cooldown.SetDaysRemaining(uint32(event.DaysLeft))
|
||||
decision.SetCooldown(cooldown)
|
||||
|
||||
e := &controltowerv1.PmgEvent{}
|
||||
e.SetEventType(controltowerv1.PmgEventType_PMG_EVENT_TYPE_PACKAGE_DECISION)
|
||||
e.SetPackageDecision(decision)
|
||||
return e
|
||||
}
|
||||
|
||||
func newHostObservationEvent(event AuditEvent) *controltowerv1.PmgEvent {
|
||||
obs := &controltowerv1.PmgHostObservation{}
|
||||
obs.SetHostname(event.Hostname)
|
||||
obs.SetMethod(event.Method)
|
||||
|
||||
e := &controltowerv1.PmgEvent{}
|
||||
e.SetEventType(controltowerv1.PmgEventType_PMG_EVENT_TYPE_HOST_OBSERVATION)
|
||||
e.SetHostObservation(obs)
|
||||
return e
|
||||
}
|
||||
|
||||
func newSessionSummaryEvent(data *SessionData) *controltowerv1.PmgEvent {
|
||||
summary := &controltowerv1.PmgSessionSummary{}
|
||||
summary.SetPackageManager(mapPackageManager(data.PackageManager))
|
||||
@@ -93,6 +129,7 @@ func newSessionSummaryEvent(data *SessionData) *controltowerv1.PmgEvent {
|
||||
summary.SetBlockedCount(data.BlockedCount)
|
||||
summary.SetConfirmedCount(data.ConfirmedCount)
|
||||
summary.SetTrustedSkipped(data.TrustedSkipped)
|
||||
summary.SetCooldownBlockedCount(data.CooldownBlockedCount)
|
||||
summary.SetDuration(durationpb.New(data.Duration))
|
||||
summary.SetSandboxEnabled(data.SandboxEnabled)
|
||||
summary.SetParanoidMode(data.ParanoidMode)
|
||||
|
||||
Reference in New Issue
Block a user