mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
feat(cooldown): add dependency_cooldown.skip list (per-control exemption) (#328)
Let dependency cooldown respect an explicit skip list so first-party / internal packages that must be installed the moment they are published (e.g. to sanity-test a freshly released version) are not held back by the cooldown window. Per review, this is a per-control skip list — NOT a second definition of "trusted package". There remains a single top-level `trusted_packages` (which waives malware analysis); `dependency_cooldown.skip` waives ONLY the cooldown wait, so a fast-tracked package is still malware-scanned. Matching: - a PURL without a version skips cooldown for all versions of the package (package-level) — the metadata passes through unmodified; - a PURL with a version skips cooldown for that version only — that version is preserved during stripping while other recent versions are still held. - config: DependencyCooldownConfig.Skip + CooldownSkip()/CooldownSkipInfo. - npm/pypi interceptors: bypass on package-level skip; thread per-version exemptions into the cooldown stripper so pinned versions survive. - docs + config template; unit tests for the matcher (package/version level, precedence, mismatches) and the skip-vs-trusted independence. Signed-off-by: dmdhrumilmistry <56185972+dmdhrumilmistry@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
26d5c0ad71
commit
61230fbcd7
@@ -33,7 +33,7 @@ func newNpmCooldownHandler(statsCollector *AnalysisStatsCollector) *npmCooldownH
|
||||
// HandleMetadataRequest overrides the Accept header to force the registry to return
|
||||
// a full packument (which includes publish dates in the "time" field), then registers
|
||||
// a response modifier that strips versions within the cooldown window.
|
||||
func (h *npmCooldownHandler) HandleMetadataRequest(ctx *proxy.RequestContext, packageName string, cooldownDays int, pinnedVersion string) (*proxy.InterceptorResponse, error) {
|
||||
func (h *npmCooldownHandler) HandleMetadataRequest(ctx *proxy.RequestContext, packageName string, cooldownDays int, pinnedVersion string, exemptVersions map[string]bool) (*proxy.InterceptorResponse, error) {
|
||||
log.Debugf("[%s] Cooldown: registering metadata modifier for %s", ctx.RequestID, packageName)
|
||||
|
||||
// Force full packument so the response always contains the "time" field.
|
||||
@@ -62,7 +62,7 @@ func (h *npmCooldownHandler) HandleMetadataRequest(ctx *proxy.RequestContext, pa
|
||||
|
||||
log.Debugf("[%s] Cooldown: parsed %d publish dates for %s", ctx.RequestID, len(dates), packageName)
|
||||
|
||||
strippedBody, stripped, remaining := h.stripCooldownVersions(body, dates, cooldownDays)
|
||||
strippedBody, stripped, remaining := h.stripCooldownVersions(body, dates, cooldownDays, exemptVersions)
|
||||
if stripped > 0 {
|
||||
log.Infof("[%s] Cooldown: stripped %d version(s) from %s metadata (%d days, %d eligible remain)",
|
||||
ctx.RequestID, stripped, packageName, cooldownDays, remaining)
|
||||
@@ -123,9 +123,13 @@ func (h *npmCooldownHandler) parseMetadataTime(body []byte) (map[string]time.Tim
|
||||
|
||||
// stripCooldownVersions removes versions published within the cooldown window from the
|
||||
// NPM metadata response. It strips entries from "versions", "time", and updates "dist-tags".
|
||||
func (h *npmCooldownHandler) stripCooldownVersions(body []byte, dates map[string]time.Time, cooldownDays int) ([]byte, int, int) {
|
||||
func (h *npmCooldownHandler) stripCooldownVersions(body []byte, dates map[string]time.Time, cooldownDays int, exemptVersions map[string]bool) ([]byte, int, int) {
|
||||
tooNew := make(map[string]bool)
|
||||
for version, publishDate := range dates {
|
||||
// Version-pinned skip entries are never stripped, even inside the window.
|
||||
if exemptVersions[version] {
|
||||
continue
|
||||
}
|
||||
if withinCooldown, _, _ := cooldownIsWithinWindow(publishDate, cooldownDays); withinCooldown {
|
||||
tooNew[version] = true
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user