mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
Adds pmg proxy command group for running a long-lived MITM proxy that intercepts all package manager traffic without requiring PMG shims or wrappers. Targets CI/CD pipelines where env vars can be set globally. - pmg proxy start: starts proxy with npm+pypi interceptors, writes state file (pid/addr/ca-cert-path), auto-blocks suspicious packages - pmg proxy stop: sends SIGTERM to the running proxy - pmg proxy env: emits HTTP_PROXY/HTTPS_PROXY/SSL_CERT_FILE etc. as shell exports, or writes directly to $GITHUB_ENV with --gha - pmg proxy status: shows running/stopped status GHA usage: pmg proxy start & pmg proxy env --gha # populates env for all subsequent steps npm install # intercepted automatically, no wrapper needed Also adds .github/workflows/persistent-proxy-e2e.yml to validate the persistent proxy mode end-to-end in CI.
41 lines
948 B
Go
41 lines
948 B
Go
package proxy
|
|
|
|
import (
|
|
"fmt"
|
|
"os"
|
|
|
|
"github.com/safedep/pmg/config"
|
|
"github.com/safedep/pmg/internal/proxystate"
|
|
"github.com/spf13/cobra"
|
|
)
|
|
|
|
func newStatusCommand() *cobra.Command {
|
|
return &cobra.Command{
|
|
Use: "status",
|
|
Short: "Show the status of the persistent PMG proxy server",
|
|
RunE: runStatus,
|
|
}
|
|
}
|
|
|
|
func runStatus(_ *cobra.Command, _ []string) error {
|
|
cfg := config.Get()
|
|
statePath := proxystate.StatePath(cfg.ConfigDir())
|
|
|
|
state, err := proxystate.Read(statePath)
|
|
if err != nil {
|
|
if _, werr := fmt.Fprintln(os.Stdout, "PMG proxy: not running (no state file)"); werr != nil {
|
|
return werr
|
|
}
|
|
return nil
|
|
}
|
|
|
|
if state.IsRunning() {
|
|
_, err = fmt.Fprintf(os.Stdout, "PMG proxy: running (pid %d, addr %s, ca %s)\n",
|
|
state.PID, state.Addr, state.CACertPath)
|
|
} else {
|
|
_, err = fmt.Fprintf(os.Stdout, "PMG proxy: stopped (stale state for pid %d — run 'pmg proxy stop' to clean up)\n", state.PID)
|
|
}
|
|
|
|
return err
|
|
}
|