feat: emit cloud events for dependency cooldown and host observations (#243)

* feat: emit cloud events for dependency cooldown and host observations (#237)

Wire cooldown blocks and proxy host observations through the cloud sync
pipeline so they appear as telemetry in Control Tower.

- Cooldown blocks emit PACKAGE_DECISION with COOLDOWN_BLOCKED action and
  PmgDependencyCooldown context (publish date, cooldown days, days since
  publish, days remaining)
- Proxy host observations emit HOST_OBSERVATION with PmgHostObservation
  (hostname, method)
- Session summary now includes cooldown_blocked_count
- Updated buf API dependency for new proto schema

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* format file

* fix: add explicit eventlog mapping for EventTypeDependencyCooldown

Follow the existing pattern where every audit event type has an explicit
case in mapEventType and a corresponding constant in the eventlog package.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Apply suggestion from @devin-ai-integration[bot]

Co-authored-by: devin-ai-integration[bot] <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com>

---------

Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Abhisek Datta <abhisek.datta@gmail.com>
Co-authored-by: devin-ai-integration[bot] <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
Sahil Bansal
2026-05-08 10:01:25 +05:30
committed by GitHub
co-authored by Claude Opus 4.6 devin-ai-integration[bot] <158243242+devin-ai-integration[bot]@users.noreply.github.com> Abhisek Datta devin-ai-integration[bot] <158243242+devin-ai-integration[bot]@users.noreply.github.com>
parent b671192598
commit 19d735cdd2
12 changed files with 218 additions and 67 deletions
+21 -13
View File
@@ -8,19 +8,20 @@ import (
// SessionData carries aggregate session statistics for session-complete events.
type SessionData struct {
PackageManager string
FlowType FlowType
Outcome Outcome
TotalAnalyzed uint32
AllowedCount uint32
BlockedCount uint32
ConfirmedCount uint32
TrustedSkipped uint32
InsecureBypassed uint32
Duration time.Duration
SandboxEnabled bool
ParanoidMode bool
TransitiveEnabled bool
PackageManager string
FlowType FlowType
Outcome Outcome
TotalAnalyzed uint32
AllowedCount uint32
BlockedCount uint32
ConfirmedCount uint32
TrustedSkipped uint32
InsecureBypassed uint32
CooldownBlockedCount uint32
Duration time.Duration
SandboxEnabled bool
ParanoidMode bool
TransitiveEnabled bool
}
// FlowType identifies how PMG intercepted the package installation.
@@ -54,6 +55,7 @@ const (
EventTypeDependencyResolved EventType = "dependency_resolved"
EventTypeInstallInsecureBypass EventType = "install_insecure_bypass"
EventTypeProxyHostObserved EventType = "proxy_host_observed"
EventTypeDependencyCooldown EventType = "dependency_cooldown"
EventTypeSandboxOverride EventType = "sandbox_override"
EventTypeError EventType = "error"
EventTypeSessionComplete EventType = "session_complete"
@@ -91,6 +93,12 @@ type AuditEvent struct {
Method string
Reason string
// Cooldown context
PublishDate time.Time
CooldownDays int
DaysAgo int
DaysLeft int
// Error context
Error error