mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
* feat: Add separate package manager and resolver * fix: Npm dependency resolver * feat: Add analyzer for malysis query * feat: Add package manager guard as the orchestrator * feat: Add PMG to orchestrate installation * Add concurrent scan execution * Introduce package manager interaction abstraction * feat: Add UI port for guard * Remove refactored source files * Update README * fix: CI script for multi-arch build * ci: goreleaser CI fix * fix: npm command parser to extract package names * feat: Introduce global config primitive * fix: Close results channel for clean goroutine exit * ci: Add container image releaser * test: Improve test for npm resolver * refactor: Analyzer to generalise * Improve UI with additional info * fix: Goreleaser config * fix: npm resolver bug * fix: Fail when command exec workflow fails * fix: Bug with transitive dependency resolution * fix: Synchronize common data update in dependency resolver * chore: Improve log handling * docs: Update README * fix: UI text wrapping * fix: UI handling bugs * feat: Use concurrent dependency resolver
48 lines
891 B
Go
48 lines
891 B
Go
package analyzer
|
|
|
|
import (
|
|
"context"
|
|
|
|
packagev1 "buf.build/gen/go/safedep/api/protocolbuffers/go/safedep/messages/package/v1"
|
|
)
|
|
|
|
// A base interface for all analyzers
|
|
type Analyzer interface {
|
|
Name() string
|
|
}
|
|
|
|
type Action int
|
|
|
|
const (
|
|
ActionUnknown Action = iota
|
|
ActionAllow
|
|
ActionConfirm
|
|
ActionBlock
|
|
)
|
|
|
|
type PackageVersionAnalysisResult struct {
|
|
PackageVersion *packagev1.PackageVersion
|
|
|
|
// Analyser specific analysis ID
|
|
AnalysisID string
|
|
|
|
// Reference URL for the analysis
|
|
ReferenceURL string
|
|
|
|
// The action to take as recommended by the analyzer
|
|
Action Action
|
|
|
|
// Summary of the analysis
|
|
Summary string
|
|
|
|
// Analyzer specific data
|
|
Data any
|
|
}
|
|
|
|
// Contract for implementing package version specific analyzers
|
|
type PackageVersionAnalyzer interface {
|
|
Analyzer
|
|
|
|
Analyze(ctx context.Context, packageVersion *packagev1.PackageVersion) (*PackageVersionAnalysisResult, error)
|
|
}
|