feat(cooldown): add dependency_cooldown.skip list (per-control exemption) (#328)

Let dependency cooldown respect an explicit skip list so first-party /
internal packages that must be installed the moment they are published
(e.g. to sanity-test a freshly released version) are not held back by the
cooldown window.

Per review, this is a per-control skip list — NOT a second definition of
"trusted package". There remains a single top-level `trusted_packages`
(which waives malware analysis); `dependency_cooldown.skip` waives ONLY
the cooldown wait, so a fast-tracked package is still malware-scanned.

Matching:
- a PURL without a version skips cooldown for all versions of the package
  (package-level) — the metadata passes through unmodified;
- a PURL with a version skips cooldown for that version only — that
  version is preserved during stripping while other recent versions are
  still held.

- config: DependencyCooldownConfig.Skip + CooldownSkip()/CooldownSkipInfo.
- npm/pypi interceptors: bypass on package-level skip; thread per-version
  exemptions into the cooldown stripper so pinned versions survive.
- docs + config template; unit tests for the matcher (package/version
  level, precedence, mismatches) and the skip-vs-trusted independence.

Signed-off-by: dmdhrumilmistry <56185972+dmdhrumilmistry@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
dmdhrumilmistry
2026-06-15 19:44:55 +05:30
committed by GitHub
co-authored by Claude Opus 4.8
parent 26d5c0ad71
commit 61230fbcd7
11 changed files with 372 additions and 49 deletions
+7 -3
View File
@@ -29,7 +29,7 @@ func newPypiCooldownHandler(statsCollector *AnalysisStatsCollector) *pypiCooldow
// then registers a response modifier that strips files for versions within the cooldown window.
// If the client does not support PEP 691 (pip < 22.3), cooldown is skipped to avoid
// returning a content type the client cannot parse.
func (h *pypiCooldownHandler) HandleMetadataRequest(ctx *proxy.RequestContext, packageName string, cooldownDays int, pinnedVersion string) (*proxy.InterceptorResponse, error) {
func (h *pypiCooldownHandler) HandleMetadataRequest(ctx *proxy.RequestContext, packageName string, cooldownDays int, pinnedVersion string, exemptVersions map[string]bool) (*proxy.InterceptorResponse, error) {
log.Debugf("[%s] Cooldown: registering metadata modifier for %s", ctx.RequestID, packageName)
originalAccept := ctx.Headers.Get("Accept")
@@ -62,7 +62,7 @@ func (h *pypiCooldownHandler) HandleMetadataRequest(ctx *proxy.RequestContext, p
log.Debugf("[%s] Cooldown: parsed %d versions for %s", ctx.RequestID, len(dates), packageName)
strippedBody, stripped, remaining := h.stripCooldownFiles(body, dates, cooldownDays)
strippedBody, stripped, remaining := h.stripCooldownFiles(body, dates, cooldownDays, exemptVersions)
if stripped > 0 {
log.Infof("[%s] Cooldown: stripped %d version(s) from %s metadata (%d days, %d eligible remain)",
ctx.RequestID, stripped, packageName, cooldownDays, remaining)
@@ -133,9 +133,13 @@ func (h *pypiCooldownHandler) parsePEP691Files(body []byte) (map[string]time.Tim
// stripCooldownFiles removes all file entries for versions within the cooldown window
// from a PEP 691 JSON body. Returns the modified body, number of versions stripped,
// and number of versions remaining.
func (h *pypiCooldownHandler) stripCooldownFiles(body []byte, dates map[string]time.Time, cooldownDays int) ([]byte, int, int) {
func (h *pypiCooldownHandler) stripCooldownFiles(body []byte, dates map[string]time.Time, cooldownDays int, exemptVersions map[string]bool) ([]byte, int, int) {
tooNew := make(map[string]bool)
for version, uploadDate := range dates {
// Version-pinned skip entries are never stripped, even inside the window.
if exemptVersions[version] {
continue
}
if within, _, _ := cooldownIsWithinWindow(uploadDate, cooldownDays); within {
tooNew[version] = true
}