diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..7e5fe2c --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,78 @@ + +# Contributing Guide + +You can contribute to `pmg` and help make it better. Apart from bug fixes, +features, we particularly value contributions in the form of: + +- Documentation improvements +- Bug reports +- Using `pmg` in your projects and providing feedback + +## How to contribute + +1. Fork the repository +2. Add your changes +3. Submit a pull request + +## How to report a bug + +Create a new issue and add the label "bug". + +## How to suggest a new feature + +Create a new issue and add the label "enhancement". + +## Development workflow + +When contributing changes to repository, follow these steps: + +1. Ensure tests are passing +2. Ensure you write test cases for new code +3. `Signed-off-by` line is required in commit message (use `-s` flag while committing) + +## Developer Setup + +### Requirements + +- Go 1.24+ +- Git +- Make + +### Getting Started + +1. Clone your fork: + ```bash + git clone https://github.com/YOUR_USERNAME/pmg.git + cd pmg + ``` + +2. Install dependencies: + ```bash + go mod tidy + ``` + +3. Build the project: + ```bash + make all + ``` + +### Development Workflow + +1. Create a branch: + ```bash + git checkout -b feature/your-feature + ``` + +2. Make your changes and test: + ```bash + make test + ``` + +3. Commit with sign-off: + ```bash + git commit -s -m "feat: add new feature" + ``` + +4. Push and create PR: + ```bash + git push origin feature/your-feature diff --git a/MAINTAINERS.txt b/MAINTAINERS.txt new file mode 100644 index 0000000..83db181 --- /dev/null +++ b/MAINTAINERS.txt @@ -0,0 +1,17 @@ +pmg is built and maintained by SafeDep with the help of the community. +https://safedep.io + +Abhisek Datta + Email: abhisek@safedep.io + GitHub username: @abhisek + Affiliation: SafeDep + +Sahil Bansal + Email: sahil.bansal@safedep.io + Github username: @Sahilb315 + Affiliation: SafeDep + +Omkar Phansopkar + Email: omkar.phansopkar@safedep.io + GitHub username: @OmkarPh + Affiliation: SafeDep diff --git a/Makefile b/Makefile index 2b42a2b..5375016 100644 --- a/Makefile +++ b/Makefile @@ -14,3 +14,6 @@ create_bin: clean: rm -rf $(BIN_DIR) + +test: + go test ./... diff --git a/README.md b/README.md index 2feb3f4..467e55a 100644 --- a/README.md +++ b/README.md @@ -5,13 +5,22 @@ PMG is a security-focused wrapper for package managers that helps detect and pre ## 📑 Table of Contents +- [Features](#features) - [Supported Ecosystems](#supported-ecosystems) - [Installation](#installation) - [Prerequisites](#prerequisites) -- [Environment Variables](#environment-variables) +- [Configuration](#configuration) - [Usage](#usage) + - [NPM Packages](#npm-packages) + - [PNPM Packages](#pnpm-packages) + - [Common Flags](#common-flags) - [Contributing](#contributing) +## Features +- 🚫 Malware detection and prevention +- 🌲 Deep dependency analysis +- ⚡ Fast and efficient package verification +- 🔄 Seamless integration with existing package managers ## Supported Ecosystems Currently, PMG supports the following package ecosystems: @@ -19,6 +28,7 @@ Currently, PMG supports the following package ecosystems: | Ecosystem | Status | Command | |-----------|--------|---------| | NPM | ✅ Active | `pmg npm install ` | +| PNPM | ✅ Active | `pmg pnpm add ` | | PyPI | 🚧 Planned | Coming soon | | Go | 🚧 Planned | Coming soon | @@ -35,29 +45,51 @@ go install github.com/safedep/pmg@latest - Go 1.24 - SafeDep API credentials (SAFEDEP_API_KEY and SAFEDEP_TENANT_ID) -## Environment Variables +## Configuration -- `SAFEDEP_API_KEY`: Your SafeDep API key -- `SAFEDEP_TENANT_ID`: Your SafeDep tenant ID +### Environment Variables -Visit https://docs.safedep.io/cloud/quickstart for instructions on obtaining your API Key and Tenant ID. +| Variable | Description | Required | +|----------|-------------|----------| +| `SAFEDEP_API_KEY` | Your SafeDep API key | Yes | +| `SAFEDEP_TENANT_ID` | Your SafeDep tenant ID | Yes | + +Get your API credentials by visiting [SafeDep Quickstart Guide](https://docs.safedep.io/cloud/quickstart). ## Usage -### Scanning NPM packages +### Security in Action + +#### Malicious Package Detection +![pmg scan malicious package](./docs/assets/pmg-malicious-pkg.png) + +#### Bulk Package Analysis +![pmg scan & install multiple package](./docs/assets/pmg-scan-multiple-pkgs.png) + +### NPM Packages +Install a package: ```bash pmg npm install ``` -OR +Alternative commands: ```bash -pmg npm i +pmg npm i # Short form +pmg npm add # Alternative syntax ``` -OR + +### PNPM Packages +Install a package: ```bash -pmg npm add +pmg pnpm add +``` + +### Common Flags +All standard package manager flags are supported: +```bash +pmg npm install --save-dev # Install as dev dependency +pmg pnpm add -D # Install as dev dependency ``` ## Contributing - -Please feel free to submit a Pull Request. +Refer to [CONTRIBUTING.md](CONTRIBUTING.md) diff --git a/docs/assets/pmg-malicious-pkg.png b/docs/assets/pmg-malicious-pkg.png new file mode 100644 index 0000000..2597df4 Binary files /dev/null and b/docs/assets/pmg-malicious-pkg.png differ diff --git a/docs/assets/pmg-scan-multiple-pkgs.png b/docs/assets/pmg-scan-multiple-pkgs.png new file mode 100644 index 0000000..d624c76 Binary files /dev/null and b/docs/assets/pmg-scan-multiple-pkgs.png differ diff --git a/pkg/common/utils/utils_test.go b/pkg/common/utils/utils_test.go index c3e1048..a9fd538 100644 --- a/pkg/common/utils/utils_test.go +++ b/pkg/common/utils/utils_test.go @@ -200,7 +200,7 @@ func TestRemoveMarkdown(t *testing.T) { {"Just plain text", "Just plain text"}, // Complex mixed - {"### Title\nSome **bold** text and a [link](http://url.com).", "Title\nSome bold text and a link."}, + {"### Title\nSome **bold** text and a [link](http://url.com).", "Title Some bold text and a link."}, } for _, tt := range tests {