mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
* Add comprehensive event logging system with OS-specific location and rotation Features: - Event logging for security-relevant events (malware detection, installations) - OS-specific default log locations (~/.pmg/logs/ on macOS/Linux, %LOCALAPPDATA%\pmg\logs\ on Windows) - Automatic 7-day log rotation with daily log files (YYYYMMDD-pmg.log format) - Support for custom log files via --log flag - Thread-safe JSON logging with zero external dependencies Implementation: - New internal/eventlog package with comprehensive logging functionality - Integration with guard.go to log malware detections and blocks - Integration with main.go for initialization and cleanup - Log file naming: YYYYMMDD-pmg.log (e.g., 20251216-pmg.log) - Fail-safe design - PMG continues if logging fails Event Types: - malware_blocked: Malicious package blocked from installation - malware_confirmed: User proceeded with flagged package - install_allowed: Clean package installation allowed - install_started: Package manager command initiated - error: Error events Testing: - Comprehensive test suite with 6 passing tests - Verified with real malware detection (e.g., @postman/tunnel-agent) - Works with all package managers (npm, pip, etc.) Technical Details: - Thread-safe with mutex protection - JSON format for easy parsing - Automatic cleanup of logs >7 days old - Background cleanup goroutine - Uses only Go standard library (encoding/json, os, path/filepath, sync, time) * Add update command support and improve event logging robustness Features: - Add support for npm/pnpm/bun/yarn update/upgrade/ci commands - These commands now scan packages for malware before updating - Closes security gap where update commands bypassed PMG protection Improvements: - Make event logging more defensive (graceful failure when not initialized) - Add nil check for packageManager in guard to prevent test failures - Add comprehensive tests for update commands Testing: - All 33+ unit tests passing - Integration tests verified with real malware detection - Tested with npm update, npm ci, npm upgrade, pnpm update, yarn upgrade Files changed: - packagemanager/npm.go: Added update/upgrade/ci to InstallCommands - packagemanager/npm_test.go: Added 4 new test cases for update commands - guard/guard.go: Added nil check for packageManager - internal/eventlog/eventlog.go: Made logging more defensive * Address review feedback: use log.Warnf instead of silently failing Replace silent error handling in cleanupOldLogs with log.Warnf to avoid completely swallowing errors when reading log directory. Fixes reviewer feedback from abhisek. * Remove update/upgrade command support, keep logging improvements - Remove update/upgrade/ci commands from InstallCommands for npm, pnpm, bun, yarn - Remove special handling for update/upgrade/ci commands in ParseCommand - Remove update command test cases and restore original test - Preserve logging improvements (nil check in guard.go, defensive check in eventlog.go) All tests passing.