mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
* feat: Add dependency cooldown for npm packages Strip recently-published package versions from npm registry metadata responses so npm's resolver naturally falls back to older versions. Overrides the Accept header to force full packument responses (which include the "time" field needed for publish-date checks). Reports cooldown blocks only when all versions are stripped (remaining == 0), matching npm's --min-release-age behavior for silent fallback. * fix: Report oldest version in cooldown block (shortest wait) When all versions are blocked by cooldown, report the oldest version since it exits the cooldown window first — giving the user the shortest wait time instead of the longest. * fix: Handle resp.Body.Close error return for errcheck linter * test: Add dependency cooldown assertions to template config tests * fix: config template for dependency cooldown * fix: Prevent npm from caching cooldown-stripped metadata responses * fix: Restore body on ReadAll failure and log Close errors in response modifier * fix: Close response body before replacing to prevent connection leak * fix: Correct daysLeft ceiling math and update ContentLength on error recovery * fix: Clear Status on status code change and update ContentLength in modifier error path * refactor: address review comments on dependency cooldown PR - Make NpmCooldownHandler and constructor package-private - Pass cooldown days as parameter instead of reading config internally - Convert standalone functions to methods on npmCooldownHandler - Set Accept-Encoding: identity to prevent gzip responses breaking JSON parsing - Return 503 with descriptive message when upstream body read fails * fix: log errors in stripCooldownVersions instead of swallowing them * fix: Config preserve fallback defaults * fix: Code review fixes * fix: correct cooldown tip to show wait time instead of incorrect trusted_packages advice * fix: prevent integer overflow in cooldown duration calculation with large days values * refactor: deduplicate CooldownBlock into internal/models, fix misleading variable names - Move CooldownBlock struct to internal/models to eliminate duplication between proxy/interceptors and internal/ui packages - Simplify proxy_flow.go by using direct assignment instead of field copy - Rename latestStripped/latestDate to oldestVer/oldestDate for clarity * fix: Dependency Cooldown Check Encapsulation (#207) * fix: Encapsulate cooldown check * feat: Add --skip-dependency-cooldown override * fix: Code review fixes --------- Co-authored-by: Abhisek Datta <abhisek.datta@gmail.com>
76 lines
3.7 KiB
Go
76 lines
3.7 KiB
Go
package config
|
|
|
|
import (
|
|
"fmt"
|
|
|
|
"github.com/spf13/cobra"
|
|
)
|
|
|
|
var skipDependencyCooldown bool
|
|
|
|
// sandboxAllowRaw holds the raw --sandbox-allow flag values before parsing.
|
|
var sandboxAllowRaw []string
|
|
|
|
// ApplyCobraFlags applies the cobra flags to the command.
|
|
// These flags are local concern of the config package. This helper function is used
|
|
// to bind them to the Cobra. The default values are taken from the global configuration,
|
|
// allowing for overriding the configuration at runtime.
|
|
func ApplyCobraFlags(cmd *cobra.Command) {
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.Config.Transitive, "transitive",
|
|
globalConfig.Config.Transitive, "Resolve transitive dependencies")
|
|
cmd.PersistentFlags().IntVar(&globalConfig.Config.TransitiveDepth, "transitive-depth",
|
|
globalConfig.Config.TransitiveDepth, "Maximum depth of transitive dependencies to resolve")
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.Config.IncludeDevDependencies, "include-dev-dependencies",
|
|
globalConfig.Config.IncludeDevDependencies, "Include dev dependencies in the dependency graph (slows down resolution)")
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.DryRun, "dry-run",
|
|
globalConfig.DryRun, "Dry run skips execution of package manager")
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.Config.Paranoid, "paranoid",
|
|
globalConfig.Config.Paranoid, "Enable high-security defaults (treat suspicious as malicious)")
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.Config.SkipEventLogging, "skip-event-log",
|
|
globalConfig.Config.SkipEventLogging, "Skip event logging")
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.Config.ExperimentalProxyMode, "experimental-proxy-mode",
|
|
globalConfig.Config.ExperimentalProxyMode, "Use experimental proxy-based interception (EXPERIMENTAL)")
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.Config.ProxyMode, "proxy-mode",
|
|
globalConfig.Config.ProxyMode, "Use proxy based interception")
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.Config.Sandbox.Enabled, "sandbox",
|
|
globalConfig.Config.Sandbox.Enabled, "Enable sandbox mode to isolate package manager processes (EXPERIMENTAL)")
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.Config.Sandbox.EnforceAlways, "sandbox-enforce",
|
|
globalConfig.Config.Sandbox.EnforceAlways, "Apply sandbox to all commands, not just install commands (requires --sandbox)")
|
|
cmd.PersistentFlags().StringVar(&globalConfig.SandboxProfileOverride, "sandbox-profile",
|
|
globalConfig.SandboxProfileOverride, "Override sandbox policy profile (built-in name or path to custom YAML)")
|
|
cmd.PersistentFlags().StringArrayVar(&sandboxAllowRaw, "sandbox-allow",
|
|
nil, "Add runtime sandbox allow rule (type=value). Types: read, write, exec, net-connect, net-bind")
|
|
|
|
cmd.PersistentFlags().BoolVar(&skipDependencyCooldown, "skip-dependency-cooldown",
|
|
false, "Skip dependency cooldown enforcement")
|
|
|
|
// Hide the experimental proxy mode flag but keep it for backward compatibility
|
|
_ = cmd.PersistentFlags().MarkHidden("experimental-proxy-mode")
|
|
}
|
|
|
|
// FinalizeDependencyCooldownOverride disables dependency cooldown in the global
|
|
// config when --skip-dependency-cooldown is set. Must be called after cobra
|
|
// flag parsing is complete.
|
|
func FinalizeDependencyCooldownOverride() {
|
|
if skipDependencyCooldown {
|
|
globalConfig.Config.DependencyCooldown.Enabled = false
|
|
}
|
|
}
|
|
|
|
// FinalizeSandboxAllowOverrides parses the raw --sandbox-allow flag values
|
|
// and stores the validated overrides in the global config. This must be called
|
|
// after cobra flag parsing is complete (e.g., in PersistentPreRun).
|
|
func FinalizeSandboxAllowOverrides() error {
|
|
if len(sandboxAllowRaw) == 0 {
|
|
return nil
|
|
}
|
|
|
|
overrides, err := parseSandboxAllowOverrides(sandboxAllowRaw)
|
|
if err != nil {
|
|
return fmt.Errorf("failed to parse --sandbox-allow flags: %w", err)
|
|
}
|
|
|
|
globalConfig.SandboxAllowOverrides = overrides
|
|
return nil
|
|
}
|