Abhisek Datta and GitHub
19e04b71b4
fix: Enable HTTP/2 for proxy upstream with connection tuning ( #183 )
...
* fix: Enable HTTP/2 for proxy upstream with connection tuning
* fix: Handle HTTP/2 upstream translating to HTTP/1.1 downstream
* fix: Remove go tool golangci-lint as per docs
* fix: Code review fixes
* fix: Code review fixes
2026-03-11 14:40:27 +05:30
Abhisek Datta and GitHub
e31a11e8e2
docs: Update README ( #182 )
...
* docs: Update README
* docs: Update README
2026-03-11 11:04:05 +05:30
Abhisek Datta and GitHub
2d1926388c
fix: Handle goproxy scheme handling bug ( #181 )
...
* fix: Handle goproxy scheme handling bug
* fix: Code review fixes
2026-03-10 10:35:28 +05:30
Abhisek Datta and GitHub
f8fcdf6929
chore: Rotate PH analytics public token ( #180 )
2026-03-10 08:47:18 +05:30
Abhisek Datta and GitHub
0588e66131
fix: Tune pypi sandbox profile ( #178 )
2026-03-06 17:47:04 +05:30
Abhisek Datta and GitHub
2bb5dd3778
fix: Allow explicit override over deny patterns ( #177 )
...
* fix: Allow explicit override over deny patterns
* test: Non-glob expansion for overrides is expected
2026-03-06 10:10:15 +05:30
Abhisek Datta and GitHub
8cba52201c
feat: Add config support for UI verbosity level ( #175 )
...
* feat: Add config support for UI verbosity level
* docs: Add verbosity info in UI doc
2026-03-04 13:32:34 +05:30
Abhisek Datta and GitHub
0c09988776
fix: Interactive pty identification for proxy mode ( #174 )
2026-03-04 06:56:06 +00:00
601ba315c2
ci: Add GHA for issue triage ( #171 )
...
* ci: Add GHA for issue triage
* Update .github/workflows/issue-triage.yml
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* Update .github/workflows/issue-triage.yml
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-02-20 07:12:39 +00:00
Abhisek Datta and GitHub
91aa4547c4
feat: Show sandbox info in PMG setup info command ( #170 )
2026-02-20 11:59:29 +05:30
Abhisek Datta and GitHub
6074080219
feat: Add support for sandbox allow override ( #165 )
...
* feat: Add support for sandbox allow override
* fix: Main should fail on arg processing error
* fix: Remove redundant policy conflict check
2026-02-16 13:58:08 +05:30
d3cb15a3ea
docs: Update README ( #163 )
...
* docs: Update README
* docs: Misc fixes
* Update README.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* Update README.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-02-16 13:35:58 +05:30
Abhisek Datta and GitHub
3778d4d1f3
fix: Sandbox Allow network bind for npx ( #151 )
...
* feat: Add support for network bind
* chore: Add comments for bwrap sandbox
2026-02-04 15:32:47 +05:30
Abhisek Datta and GitHub
b5696f989f
chore: Proxy mode without experimental tag ( #147 )
...
* chore: Proxy mode without experimental tag
* fix: Update proxy mode docs
* fix: Code review fixes
2026-02-02 12:58:28 +05:30
4600ab0245
fix: Sandbox policy tuning for tmp write access ( #145 )
...
* fix: Sandbox policy tuning for tmp write access
* fix: Remove numbers from test
* Update sandbox/profiles/pnpm-restrictive.yml
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: Sandbox E2E test to consider Linux bubblewrap tmpfs mount
* Update sandbox/profiles/pnpm-restrictive.yml
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: Migrate deny rules from pnpm to npm policy
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
2026-02-01 15:20:17 +05:30
Abhisek Datta and GitHub
be63fdd6ea
fix: Remove Emoji from Setup ( #142 )
...
* fix: Remove emoji from setup
* fix: Update README demo
2026-01-27 20:08:23 +05:30
Abhisek Datta and GitHub
36ac3e3384
feat: Add post-exec reporting support ( #134 )
...
* feat: Add post install reporting support
* fix: UI report handling
* fix: Duplicate reporting
* fix: Show warning on insecure bypass
* fix: Proxy event log insecure skip installation
* fix: Proxy event log insecure skip installation
* fix: Common definition for infer outcome
2026-01-27 17:50:26 +05:30
aa5c528a9d
docs: Update README ( #133 )
...
* docs: Update README
* docs: Update README
* docs: Update README
* docs: Update README
* docs: Update README
* Apply suggestion from @Sahilb315
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
2026-01-21 20:29:15 +05:30
edfdd543e0
chore: README update demo and Error Fix ( #126 )
...
* docs: Update README with demo gif
* fix: Proxy remove dependency on interaction
* fix: Update demo gif width
* Update docs/demo/pmg-intro.tape
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: PMG demo
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-01-18 16:00:37 +05:30
Abhisek Datta and GitHub
6a3821d44a
chore: Improve console error experience ( #124 )
...
* chore: Improve console error experience
* fix: Use standard error code and handle verbosity
2026-01-17 14:05:01 +05:30
Abhisek Datta and GitHub
80a1747e3e
feat: Add support for Linux Sandbox using Bubblewrap ( #120 )
...
* feat: Add support for bubblewrap sandbox
* fix: Glob pattern expansion limit for linux
* fix: Bug in glob pattern expansion for bwrap
* fix: README on trust
* fix: Multiple bubblewrap translator fix
* test: Add E2E for linux sandbox
* fix: Refactor bwrap sandbox to use common dangerous files
* fix: Path test case
* fix: Non-existent path handling bug
* refactor: Misc cleanup
* fix: Avoid bind mount for non-existentent deny protection
* fix: Off by one bug in path depth handling
* ci: Disable AppArmor on GHA runner
* fix: Disable apparmor userns restrictions
2026-01-15 20:12:12 +05:30
b97a4c2ee5
docs: Add trust doc ( #118 )
...
* docs: Add trust doc
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-01-14 15:02:08 +05:30
Abhisek Datta and GitHub
cf12914ab3
ci: Add support for build provenance ( #116 )
...
* ci: Add support for build provenance
* fix: Fix provenance job
2026-01-14 11:45:54 +05:30
2e1f5b1a36
feat: Add support for policy inheritence ( #113 )
...
* feat: Add support for policy inheritence
* fix: Linter fixes
* Update docs/sandbox.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: Handle boolean inheritence
* ci: Add linter
* Update sandbox/policy_test.go
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: Linter fixes
* fix: Linter fixes
* fix: Sandbox rule regex format
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-01-14 10:50:39 +05:30
9693428171
feat: Experimental Sandbox Support ( #101 )
...
* feat: Sandbox implementation with seatbelt
* refactor: Remove concept of PM_CACHE
* fix: Misc fixes
* refactor: Sandbox for separation of boundaries
* fix: Apply API
* fix: Add support for sandbox cleanup
* test: Add variable interpolation test
* fix: Misc cleanup fixes
* chore: Cleanup sandbox registry
* chore: Cleanup sandbox policy
* chore: Cleanup sandbox
* fix: Misc cleanup fixes
* fix: Remove violation mode
* fix: Update config template
* chore: Go mod cleanup
* fix: Handle the case when package manager policy is explicitly disabled
* fix: Sandbox executor
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* test: Remove unused var
* test: Add test for seatbelt sandbox driver
* fix: Sandbox profile loader from file should use path for caching
* test: Add policy test
* feat: Add support for config templates
* fix: Seatbelt translator handle glob
* fix: Merge conflicts
* fix: Fix sandbox policy generator for MacOS min permissions
* fix: Sandbox path handling bugs
* fix: Deny read to dangerous directories
* fix: Deny read to dangerous directories
* add sandbox e2e (#112 )
* fix: Sandbox E2E test
* fix: Code review fixes
* fix: Code review fixes
* doc: Add sandbox debugging guide
* doc: Update sandbox doc
* docs: Add sandbox usage doc
* fix: Use better error for sandbox without policy
* fix: Add sandbox for npx
* fix: Enable PTY for npm
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
2026-01-13 14:52:02 +05:30
Abhisek Datta and GitHub
c0122898ca
feat: Add support for setup-info command ( #108 )
...
* feat: Add support for setup-info command
* fix: Code review fixes
* fix: Add event log info
2026-01-11 19:25:13 +05:30
Abhisek Datta and GitHub
a373b5b243
docs: Add doc for trusted packages and proxy mode ( #102 )
2026-01-09 13:56:48 +00:00
Abhisek Datta and GitHub
1684e25cc9
fix: Use separate event for trusted package allowed ( #98 )
2026-01-08 01:03:31 +05:30
Abhisek Datta and GitHub
0603df8c25
docs: Update README ( #97 )
...
* docs: Update README
* docs: Update README
2026-01-07 18:54:18 +00:00
Abhisek Datta and GitHub
1c319eba0e
fix: Proxy flow should respect trusted packages ( #96 )
...
* fix: Handle trusted packages in proxy flow
* perf: Pre-parse trusted PURLs
* fix: Code review fixes
* fix: Remove unused config
2026-01-08 00:15:02 +05:30
779deeb23d
feat: Add Support for Proxy Based Npm Interceptor ( #87 )
...
* feat: Add experimental proxy based npm interceptor
* refactor: Analysis cache
* ci: Add E2E for npm proxy
* fix: Handle dry-run in proxy flow
* fix: Handle special case for scope package name
* fix: Misc fixes
* fix: Code review fixes
* fix: Code review fixes
* refactor: Reusable code into base registry interceptor
* Pause npm process during user confirmation (#90 )
* pause npm process when prompting user for confirmation
* disable progress bar
* fix logging and close chan on return
* update use of deprecated field
* refactor: Separation of concerns for handling process state
* fix: Safe permission for cert file
* fix: Handle nil check for interaction hook
* fix: Add test for base registry
* Fix goreleaser for windows build (#93 )
* introduce platform specific process control
* rename common.go to common_flow.go
* feat: Add support for pause resume on windows
* fix: Code review fixes
* test: Add confirmation handler tests
---------
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
2026-01-07 13:22:08 +05:30
20c854e473
feat: Config Persistence & API ( #83 )
...
* introduce a persistent config
* add tests and refactor config creation
* update config handling and add support for removing config
* add support to skip suspicious pkgs marked as trusted
* add support for config dir Env & unexport functions
* small fixes
* add assert for dir
* fix tests
* fix shell source line & trusted pkgs parsing
* fix flag inconsistency
* update config to read on each invocation and create if does not exist
* fix flags value being overridden
* remove redundant func call
* modify trusted pkg check to be config bound
* modify RemoveConfig to rm files & not dir. add tests for paths.go
* add versions for package for e2e
* modify tests to reset config
* fix: Simplify config persistence
* fix: Misc comments
* fix: Misc fix
* fix: Do not overwrite config file if exists
* fix: Do not overwrite config file if exists
* fix: Config cobra command should override and not replace
* fix: Create dir before writing config template
* fix: Create dir before writing config template
* fix: Misc refactoring
* test: Add test for is trusted package version
* Update cmd/setup/setup.go
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* Update config/config.go
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: Remove unused constant in config
* fix: Resolve conflict with event logger
* docs: Add doc for eventlogger.Logger interface
* test: Add E2E for config file creation
* fix: Code review fixes
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Sahilb315 <bansalsahil315@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-01-01 12:33:52 +05:30
Abhisek Datta and GitHub
21eb05373f
feat: Add Support for Proxy with Interceptor ( #77 )
2025-12-10 08:34:28 +05:30
Abhisek Datta and GitHub
47fc5252ba
fix: Add pip3 shell alias ( #76 )
2025-12-04 09:49:43 +05:30
Abhisek Datta and GitHub
2493fb4dc6
chore: Better user friendly error messages ( #64 )
2025-08-21 18:26:05 +05:30
4031219375
fix: Show error messages on fatal failures #32 ( #34 )
...
* fix: Show error messages on fatal failures #32
* test: Add E2E test
* test: fix E2E scripts
* test: fix E2E scripts
* fix: Race condition in concurrent analyzer
* fix: update formatting to ensure docs URL is clickable
Signed-off-by: Sahil Bansal <bansalsahil315@gmail.com >
* fix: E2E test
---------
Signed-off-by: Sahil Bansal <bansalsahil315@gmail.com >
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
2025-05-17 21:54:47 +05:30
Abhisek Datta and GitHub
b85f77cfbc
feat: Add support for active scanning in paranoid mode ( #31 )
...
* feat: Add support for active scanning in paranoid mode
* docs: Fix README
2025-05-16 19:38:06 +05:30
Abhisek Datta and GitHub
7c9681ef00
Multiple Misc Updates ( #23 )
...
* docs: Update README
* docs: Add badges
2025-05-15 21:34:41 +05:30
Abhisek Datta and GitHub
5022d64ce4
chore: Improve UX ( #22 )
2025-05-15 18:03:46 +05:30
Abhisek Datta and GitHub
cfde1d7632
ci: Add CodeQL and OpenSSF Scorecard action ( #21 )
2025-05-15 16:59:13 +05:30
Abhisek Datta and GitHub
e86b6ef056
feat: Refactor PMG to Maintain Separation of Concerns and Clean Architecture ( #19 )
...
* feat: Add separate package manager and resolver
* fix: Npm dependency resolver
* feat: Add analyzer for malysis query
* feat: Add package manager guard as the orchestrator
* feat: Add PMG to orchestrate installation
* Add concurrent scan execution
* Introduce package manager interaction abstraction
* feat: Add UI port for guard
* Remove refactored source files
* Update README
* fix: CI script for multi-arch build
* ci: goreleaser CI fix
* fix: npm command parser to extract package names
* feat: Introduce global config primitive
* fix: Close results channel for clean goroutine exit
* ci: Add container image releaser
* test: Improve test for npm resolver
* refactor: Analyzer to generalise
* Improve UI with additional info
* fix: Goreleaser config
* fix: npm resolver bug
* fix: Fail when command exec workflow fails
* fix: Bug with transitive dependency resolution
* fix: Synchronize common data update in dependency resolver
* chore: Improve log handling
* docs: Update README
* fix: UI text wrapping
* fix: UI handling bugs
* feat: Use concurrent dependency resolver
2025-05-15 16:50:59 +05:30
Abhisek Datta and GitHub
ec010c7d6b
Merge pull request #1 from safedep/feat/npm-support
...
project initialisation & added npm cmd support
2025-04-29 09:06:05 +05:30
Abhisek Datta and GitHub
1d45698137
Update README.md
...
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
2025-03-20 08:00:09 +05:30
Abhisek Datta and GitHub
c22c97b257
Initial commit
2025-03-20 07:59:48 +05:30