diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml
index cd4058f..700f28e 100644
--- a/.github/workflows/ci.yml
+++ b/.github/workflows/ci.yml
@@ -13,17 +13,18 @@ jobs:
strategy:
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
+ go-version: ['1.25']
runs-on: ${{ matrix.os }}
steps:
- - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
+ - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- name: Set up Go
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
+ uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
- go-version-file: go.mod
+ go-version: ${{ matrix.go-version }}
- name: Build
run: go build -v ./...
@@ -34,14 +35,14 @@ jobs:
lint:
runs-on: ubuntu-latest
steps:
- - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
+ - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- name: Set up Go
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
+ uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
- go-version-file: go.mod
+ go-version: '1.25'
- name: golangci-lint
run: go tool golangci-lint run ./...
diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml
index 1c4eb1e..93b0a1e 100644
--- a/.github/workflows/publish.yml
+++ b/.github/workflows/publish.yml
@@ -18,23 +18,14 @@ jobs:
permissions:
packages: write
contents: read
- id-token: write
steps:
- name: Check out the repo
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
+ uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
with:
persist-credentials: false
- - name: Set up QEMU
- uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0
- with:
- platforms: linux/amd64,linux/arm64
-
- - name: Set up Docker Buildx
- uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
-
- name: Log in to the Container registry
- uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f
+ uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee
with:
registry: ghcr.io
username: ${{ github.actor }}
@@ -42,57 +33,14 @@ jobs:
- name: Extract metadata (tags, labels) for Docker
id: meta
- uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302
+ uses: docker/metadata-action@80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9
with:
images: ghcr.io/${{ github.repository }}
- - uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
-
- name: Build and push Docker image
- id: build
- uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a
+ uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf
with:
context: .
- platforms: linux/amd64,linux/arm64
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
- provenance: mode=max
- sbom: true
-
- - name: Sign image by digest
- env:
- DIGEST: ${{ steps.build.outputs.digest }}
- IMAGE: ghcr.io/${{ github.repository }}
- run: |
- set -euo pipefail
- [[ "$DIGEST" =~ ^sha256:[0-9a-f]{64}$ ]]
- cosign sign --yes "${IMAGE}@${DIGEST}"
-
- - name: Verify BuildKit attestations and extract SPDX predicates
- env:
- DIGEST: ${{ steps.build.outputs.digest }}
- IMAGE: ghcr.io/${{ github.repository }}
- run: |
- set -euo pipefail
- reference="${IMAGE}@${DIGEST}"
- docker buildx imagetools inspect "$reference" --format '{{ json .Provenance }}' > provenance.json
- docker buildx imagetools inspect "$reference" --format '{{ json .SBOM }}' > sbom.json
-
- for platform in linux/amd64 linux/arm64; do
- jq -e --arg p "$platform" '.[$p].SLSA | type == "object" and length > 0' \
- provenance.json >/dev/null
- jq -e --arg p "$platform" '.[$p].SPDX' sbom.json > "sbom-${platform//\//-}.spdx.json"
- done
-
- - name: Attest platform SBOMs by digest
- env:
- DIGEST: ${{ steps.build.outputs.digest }}
- IMAGE: ghcr.io/${{ github.repository }}
- run: |
- set -euo pipefail
- [[ "$DIGEST" =~ ^sha256:[0-9a-f]{64}$ ]]
- reference="${IMAGE}@${DIGEST}"
- for predicate in sbom-linux-amd64.spdx.json sbom-linux-arm64.spdx.json; do
- cosign attest --yes --type spdxjson --predicate "$predicate" "$reference"
- done
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index 5d32181..f7833fb 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -14,7 +14,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
+ - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 0
persist-credentials: false
@@ -22,12 +22,12 @@ jobs:
- uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
- name: Set up Go
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
+ uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
go-version-file: go.mod
cache: false
- - uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
+ - uses: goreleaser/goreleaser-action@5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89 # v7.2.2
with:
version: "~> v2"
args: release --clean
diff --git a/.github/workflows/swagger.yml b/.github/workflows/swagger.yml
index 38c42c3..f947c7e 100644
--- a/.github/workflows/swagger.yml
+++ b/.github/workflows/swagger.yml
@@ -12,14 +12,14 @@ jobs:
swagger:
runs-on: ubuntu-latest
steps:
- - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
+ - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- name: Set up Go
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
+ uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
- go-version-file: go.mod
+ go-version: '1.25'
- name: Install swag
run: go install github.com/swaggo/swag/cmd/swag@latest
diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml
index ac587dd..cce6e4f 100644
--- a/.github/workflows/zizmor.yml
+++ b/.github/workflows/zizmor.yml
@@ -21,9 +21,9 @@ jobs:
security-events: write
steps:
- name: Checkout
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
+ uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- name: Run zizmor
- uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2
+ uses: zizmorcore/zizmor-action@192e21d79ab29983730a13d1382995c2307fbcaa # v0.5.7
diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md
index 68a6acf..88ad1cb 100644
--- a/CONTRIBUTING.md
+++ b/CONTRIBUTING.md
@@ -39,7 +39,7 @@ proxy/
│ │ └── queries.go # CRUD operations
│ ├── storage/ # Artifact file storage
│ │ ├── storage.go # Storage interface
-│ │ └── blob.go # gocloud.dev/blob backends (file, S3, Azure)
+│ │ └── filesystem.go # Local filesystem impl
│ ├── upstream/ # Upstream registry clients
│ │ ├── fetcher.go # HTTP artifact fetching
│ │ └── resolver.go # Download URL resolution
@@ -72,7 +72,7 @@ Key types:
### `internal/storage`
-Artifact file storage abstraction backed by `gocloud.dev/blob`. Supports local filesystem (`file://`), S3 (`s3://`), and Azure (`azblob://`) URLs.
+Artifact file storage abstraction. Currently implements local filesystem storage. Designed to allow future backends (S3, GCS).
Interface:
```go
diff --git a/Dockerfile b/Dockerfile
index 9a64c5a..7b2795c 100644
--- a/Dockerfile
+++ b/Dockerfile
@@ -1,4 +1,4 @@
-FROM --platform=$BUILDPLATFORM golang:1.26.6-alpine AS builder
+FROM golang:1.26.4-alpine AS builder
WORKDIR /src
@@ -12,9 +12,8 @@ RUN go mod download
# Copy source code
COPY . .
-# Build the binary for the target platform
-ARG TARGETARCH
-RUN CGO_ENABLED=0 GOOS=linux GOARCH=${TARGETARCH} go build -ldflags="-s -w" -o /proxy ./cmd/proxy
+# Build the binary
+RUN CGO_ENABLED=0 GOOS=linux go build -ldflags="-s -w" -o /proxy ./cmd/proxy
FROM alpine:3.24.1
diff --git a/README.md b/README.md
index 320a737..4609b66 100644
--- a/README.md
+++ b/README.md
@@ -362,39 +362,6 @@ Or pull images directly:
docker pull localhost:8080/library/nginx:latest
```
-### Helm
-
-Configure each HTTP chart repository with a name, then add the matching proxy
-URL to Helm:
-
-```yaml
-upstream:
- helm:
- bitnami: "https://charts.bitnami.com/bitnami"
-```
-
-```bash
-helm repo add bitnami http://localhost:8080/helm/bitnami
-helm repo update
-helm pull bitnami/nginx
-```
-
-The proxy caches `index.yaml` using the normal metadata-cache settings and
-caches chart archives after verifying their SHA-256 digest from the index.
-
-For charts stored in an OCI registry, configure a named OCI upstream and add
-the reserved `upstream/{name}` prefix to the chart reference:
-
-```yaml
-upstream:
- oci:
- ghcr: "https://ghcr.io"
-```
-
-```bash
-helm pull oci://localhost:8080/upstream/ghcr/owner/charts/mychart --version 1.0.0 --plain-http
-```
-
### Debian / APT
Configure APT to use the proxy in `/etc/apt/sources.list.d/proxy.list`:
@@ -409,13 +376,6 @@ Replace your existing sources.list entries, then:
sudo apt update
```
-The upstream defaults to `http://deb.debian.org/debian`. To proxy a different APT repository (e.g. Ubuntu), set `upstream.debian` in the config file or `PROXY_UPSTREAM_DEBIAN` in the environment:
-
-```yaml
-upstream:
- debian: "http://archive.ubuntu.com/ubuntu"
-```
-
### RPM / Yum / DNF
Configure yum/dnf to use the proxy in `/etc/yum.repos.d/proxy.repo`:
@@ -456,7 +416,6 @@ The proxy can be configured via:
-database-url string PostgreSQL connection URL
-log-level string Log level: debug, info, warn, error (default "info")
-log-format string Log format: text, json (default "text")
--access-log string Path to the JSONL access log
-version Print version and exit
```
@@ -472,7 +431,6 @@ PROXY_DATABASE_PATH=./cache/proxy.db
PROXY_DATABASE_URL=postgres://user:pass@localhost/proxy?sslmode=disable
PROXY_LOG_LEVEL=info
PROXY_LOG_FORMAT=text
-PROXY_ACCESS_LOG_PATH=/var/log/proxy/access.jsonl
```
### Configuration File
@@ -493,9 +451,6 @@ log:
level: "info"
format: "text"
-access_log:
- path: "/var/log/proxy/access.jsonl" # Optional JSONL activity log
-
# Optional: override upstream URLs
upstream:
npm: "https://registry.npmjs.org"
@@ -669,7 +624,6 @@ Recently cached:
| `GET /conda/*` | Conda/Anaconda protocol |
| `GET /cran/*` | CRAN (R) protocol |
| `GET /julia/*` | Julia Pkg server protocol |
-| `GET /helm/{repository}/*` | HTTP Helm chart repository protocol |
| `GET /v2/*` | OCI/Docker registry protocol |
| `GET /debian/*` | Debian/APT repository protocol |
| `GET /rpm/*` | RPM/Yum repository protocol |
@@ -883,8 +837,6 @@ The proxy exposes Prometheus metrics at `GET /metrics`. All metric names are pre
| Metric | Type | Labels | Description |
|--------|------|--------|-------------|
-| `proxy_requests_total` | counter | `ecosystem`, `status` | Proxy responses by package ecosystem and HTTP status |
-| `proxy_request_duration_seconds` | histogram | `ecosystem`, `status` | Proxy request duration |
| `proxy_cache_hits_total` | counter | `ecosystem` | Cache hits |
| `proxy_cache_misses_total` | counter | `ecosystem` | Cache misses |
| `proxy_cache_size_bytes` | gauge | | Total size of cached artifacts |
@@ -1065,7 +1017,7 @@ The proxy will recreate the database on next start.
Requirements:
-- Go (the project version is declared in `go.mod`)
+- Go 1.25 or later
```bash
git clone https://github.com/git-pkgs/proxy.git
diff --git a/cmd/proxy/main.go b/cmd/proxy/main.go
index c5549ad..15a71c0 100644
--- a/cmd/proxy/main.go
+++ b/cmd/proxy/main.go
@@ -40,8 +40,6 @@
// Log level: debug, info, warn, error (default "info")
// -log-format string
// Log format: text, json (default "text")
-// -access-log string
-// Path to the JSONL access log (disabled by default)
//
// Stats Flags:
//
@@ -74,7 +72,6 @@
// PROXY_DATABASE_URL - PostgreSQL connection URL
// PROXY_LOG_LEVEL - Log level
// PROXY_LOG_FORMAT - Log format
-// PROXY_ACCESS_LOG_PATH - JSONL access log path
// PROXY_UPSTREAM_MAVEN - Maven repository upstream URL
// PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL - Gradle Plugin Portal upstream URL
// PROXY_GRADLE_BUILD_CACHE_READ_ONLY - Disable Gradle PUT uploads
@@ -187,7 +184,6 @@ func runServe() {
databaseURL := fs.String("database-url", "", "PostgreSQL connection URL")
logLevel := fs.String("log-level", "", "Log level: debug, info, warn, error")
logFormat := fs.String("log-format", "", "Log format: text, json")
- accessLogPath := fs.String("access-log", "", "Path to the JSONL access log")
version := fs.Bool("version", false, "Print version and exit")
fs.Usage = func() {
@@ -205,7 +201,6 @@ func runServe() {
fmt.Fprintf(os.Stderr, " PROXY_DATABASE_URL PostgreSQL connection URL\n")
fmt.Fprintf(os.Stderr, " PROXY_LOG_LEVEL Log level\n")
fmt.Fprintf(os.Stderr, " PROXY_LOG_FORMAT Log format\n")
- fmt.Fprintf(os.Stderr, " PROXY_ACCESS_LOG_PATH JSONL access log path\n")
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_MAVEN Maven repository upstream URL\n")
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL Gradle Plugin Portal upstream URL\n")
fmt.Fprintf(os.Stderr, " PROXY_GRADLE_BUILD_CACHE_READ_ONLY Disable Gradle PUT uploads\n")
@@ -261,9 +256,6 @@ func runServe() {
if *logFormat != "" {
cfg.Log.Format = *logFormat
}
- if *accessLogPath != "" {
- cfg.AccessLog.Path = *accessLogPath
- }
// Validate configuration
if err := cfg.Validate(); err != nil {
@@ -275,10 +267,7 @@ func runServe() {
logger := setupLogger(cfg.Log.Level, cfg.Log.Format)
// Create and start server
- srv, err := server.New(cfg, logger, server.BuildInfo{
- Version: Version,
- Commit: Commit,
- })
+ srv, err := server.New(cfg, logger)
if err != nil {
logger.Error("failed to create server", "error", err)
os.Exit(1)
diff --git a/config.example.yaml b/config.example.yaml
index 1df95b3..62b4105 100644
--- a/config.example.yaml
+++ b/config.example.yaml
@@ -9,11 +9,6 @@ listen: ":8080"
# so users know what to point their package manager at.
base_url: "http://localhost:8080"
-# Timeout for individual upstream HTTP requests made by protocol handlers
-# (metadata fetches, pass-through file requests). Uses Go duration syntax.
-# Set to "0" to disable the timeout. Default: "30s".
-# http_timeout: "30s"
-
# Public URL where the web UI is reached. Defaults to base_url when unset.
# Set this separately when the UI is served on a different hostname than the
# package endpoints — for example, the UI on a public domain behind auth while
@@ -78,10 +73,6 @@ log:
# Log format: "text" or "json"
format: "text"
-# JSONL access log. Leave path empty to disable it.
-access_log:
- path: ""
-
# Upstream registry URLs and authentication
upstream:
# npm registry URL
@@ -99,21 +90,8 @@ upstream:
# Cargo crate download URL
cargo_download: "https://static.crates.io/crates"
- # Debian/APT repository URL (used by /debian endpoint)
- debian: "http://deb.debian.org/debian"
-
- # Named HTTP Helm chart repositories (used by /helm/{name}/)
- # helm:
- # bitnami: "https://charts.bitnami.com/bitnami"
-
- # Named OCI registries. Use the upstream/{name}/ repository prefix, e.g.
- # oci://proxy.example.com/upstream/ghcr/owner/chart.
- # oci:
- # ghcr: "https://ghcr.io"
-
# Authentication for upstream registries
- # Keys are absolute URL scopes. Scheme, host, effective port, and path
- # segment boundaries must match; the longest matching scope wins.
+ # Keys are URL prefixes matched against request URLs.
# Values can reference environment variables using ${VAR_NAME} syntax.
#
# Supported auth types:
@@ -185,8 +163,7 @@ cooldown:
# npm: "7d"
# cargo: "0"
- # Per-package overrides (keyed by PURL). Keys are normalized, so npm scopes
- # may use either @scope or the canonical %40scope form.
+ # Per-package overrides (keyed by PURL)
# packages:
# "pkg:npm/lodash": "0"
# "pkg:npm/@babel/core": "14d"
diff --git a/docs/architecture.md b/docs/architecture.md
index 6d9bfda..f04d548 100644
--- a/docs/architecture.md
+++ b/docs/architecture.md
@@ -240,8 +240,6 @@ Fetches artifacts from upstream registries.
- Exponential backoff retry on 429 (rate limit) and 5xx errors
- Returns streaming reader (doesn't load into memory)
- Configurable user-agent
-- Shares an authentication-aware transport with metadata requests so URL-scoped credentials apply consistently
-- Discovers and caches scoped OCI Bearer tokens from registry challenges
**Resolver:**
- Determines download URL for a package/version
@@ -353,7 +351,6 @@ Eviction can be implemented as:
- Fresh data - new versions visible immediately
- Metadata is small, upstream fetch is fast
- Set `cache_metadata: true` or use the mirror command to enable metadata caching for offline use via the `metadata_cache` table
-- OCI manifests are the exception: they are cached automatically so previously fetched images remain pullable when the registry or token service is unavailable
**Why stream artifacts?**
- Memory efficient - don't load large files into RAM
diff --git a/docs/configuration.md b/docs/configuration.md
index 3b8b935..f220279 100644
--- a/docs/configuration.md
+++ b/docs/configuration.md
@@ -108,30 +108,6 @@ log:
| `log.level` | `PROXY_LOG_LEVEL` | `-log-level` | `debug`, `info`, `warn`, `error` |
| `log.format` | `PROXY_LOG_FORMAT` | `-log-format` | `text`, `json` |
-## Access Log
-
-The optional access log records client requests and each HTTP exchange with an upstream registry. It is always written as JSONL, with one JSON object per line. Records for the same client request share a `request_id`.
-
-```yaml
-access_log:
- path: "/var/log/proxy/access.jsonl"
-```
-
-| Config | Environment | Flag | Description |
-|--------|-------------|------|-------------|
-| `access_log.path` | `PROXY_ACCESS_LOG_PATH` | `-access-log` | File to append JSONL records to; empty disables the log |
-
-The parent directory must exist and be writable when the proxy starts. A newly created log file is readable and writable only by the proxy process owner.
-
-A request that receives a rate limit response from an upstream can produce records like these:
-
-```json
-{"time":"2026-08-16T12:00:00Z","event":"upstream","request_id":"host/example-000001","method":"GET","url":"https://registry.example/packages/example","status_code":429,"duration_ms":42}
-{"time":"2026-08-16T12:00:00Z","event":"request","request_id":"host/example-000001","method":"GET","path":"/npm/example","status_code":502,"duration_ms":43,"remote_addr":"192.0.2.10:41234"}
-```
-
-Upstream retries and OCI authentication calls are separate `upstream` records, so the log preserves every status returned over the wire. Network failures have an `error` field and no `status_code`. URL credentials, query strings, and fragments are omitted from both upstream URLs and client paths.
-
## Upstream Registries
Override default upstream registry URLs:
@@ -143,33 +119,11 @@ upstream:
gradle_plugin_portal: "https://plugins.gradle.org/m2"
cargo: "https://index.crates.io"
cargo_download: "https://static.crates.io/crates"
-
- # Named HTTP Helm chart repositories, served at /helm/{name}/.
- helm:
- bitnami: "https://charts.bitnami.com/bitnami"
-
- # Named OCI registries. Select one with the repository prefix
- # upstream/{name}/, e.g. oci://proxy.example.com/upstream/ghcr/owner/chart.
- oci:
- ghcr: "https://ghcr.io"
```
-Helm HTTP repositories are read-only. The proxy fetches and rewrites each
-repository's `index.yaml` so chart archives are downloaded through the proxy.
-Chart archives are retained only when their SHA-256 digest matches the digest
-listed in the index. Relative and absolute chart URLs are both supported.
-
-Named OCI registries preserve the existing unprefixed Docker Hub mirror. A
-reference such as `oci://proxy.example.com/upstream/ghcr/owner/chart` is sent
-to the registry configured as `ghcr` with `owner/chart` as its repository.
-When the proxy uses plain HTTP (for example `localhost:8080`), pass
-`--plain-http` to Helm OCI commands.
-
## Authentication
-Configure authentication for private upstream registries. The same authentication-aware client is used for metadata and artifact downloads, and credentials can reference environment variables using `${VAR_NAME}` syntax.
-
-OCI registries that return a Bearer challenge from a `/v2/{repository}/…` endpoint are handled automatically. The proxy discovers the token realm from `WWW-Authenticate`, applies any configured credentials for the token URL, and reuses the scoped token until shortly before it expires.
+Configure authentication for private upstream registries. Auth is matched by URL prefix, and credentials can reference environment variables using `${VAR_NAME}` syntax.
### Bearer Token
@@ -218,7 +172,7 @@ upstream:
### URL Matching
-Auth keys must be absolute URLs. Matching compares the scheme, host, effective port, and path-segment prefix, preventing credentials for `registry.example.com` from being sent to a lookalike host such as `registry.example.com.evil.test`. The longest matching scope wins, so you can configure different credentials for different paths:
+Auth configs are matched by URL prefix. The longest matching prefix wins, so you can configure different credentials for different paths:
```yaml
upstream:
@@ -280,8 +234,6 @@ cooldown:
Durations support days (`7d`), hours (`48h`), and minutes (`30m`). Set to `0` to disable.
-Package PURL keys are normalized to canonical form before matching, so `pkg:npm/@babel/core` and `pkg:npm/%40babel/core` are equivalent, as are `pkg:pypi/Django` and `pkg:pypi/django`. If both forms configure the same package, the canonical entry wins.
-
Resolution order: package override, then ecosystem override, then global default. This lets you set a conservative default while exempting trusted packages.
Currently supported for npm, PyPI, pub.dev, Composer, Cargo, NuGet, Conda, RubyGems, and Hex. These ecosystems include publish timestamps in their metadata.
@@ -292,8 +244,6 @@ Note: Hex cooldown requires disabling registry signature verification since the
By default the proxy fetches metadata fresh from upstream on every request. Enable `cache_metadata` to store metadata responses in the database and storage backend for offline fallback. When upstream is unreachable, the proxy serves the last cached copy. ETag-based revalidation avoids re-downloading unchanged metadata.
-OCI manifests are always cached because cached image blobs cannot be pulled without their manifests. Digest-addressed manifests are immutable and served directly from cache. Tag-addressed manifests follow `metadata_ttl`, revalidate when stale, and fall back to the last cached response when the registry is unavailable.
-
```yaml
cache_metadata: true
```
@@ -326,18 +276,6 @@ metadata_max_size: "100MB" # default
Or via environment variable: `PROXY_METADATA_MAX_SIZE=250MB`.
-## Upstream HTTP timeout
-
-Protocol handlers use a shared HTTP client for upstream requests such as metadata fetches and pass-through file downloads. `http_timeout` sets that client's per-request timeout. Raise it if slow upstreams or large metadata responses cause `context deadline exceeded` errors.
-
-```yaml
-http_timeout: "30s" # default
-```
-
-Or via environment variable: `PROXY_HTTP_TIMEOUT=2m`.
-
-Set to `"0"` to disable the timeout entirely (requests then rely only on the server's write timeout).
-
## Mirror API
The `/api/mirror` endpoints are disabled by default. Enable them to allow starting mirror jobs via HTTP:
diff --git a/go.mod b/go.mod
index d95ee13..9576fda 100644
--- a/go.mod
+++ b/go.mod
@@ -1,79 +1,72 @@
module github.com/git-pkgs/proxy
-go 1.26.0
-
-toolchain go1.26.6
+go 1.25.6
require (
github.com/BurntSushi/toml v1.6.0
github.com/CycloneDX/cyclonedx-go v0.11.0
- github.com/git-pkgs/archives v0.5.1
+ github.com/git-pkgs/archives v0.3.0
github.com/git-pkgs/cooldown v0.1.1
- github.com/git-pkgs/enrichment v0.6.5
- github.com/git-pkgs/integrity v0.1.1
- github.com/git-pkgs/magic v0.2.0
- github.com/git-pkgs/purl v0.1.17
- github.com/git-pkgs/registries v0.8.1
- github.com/git-pkgs/spdx v0.3.1
- github.com/git-pkgs/vers v0.3.1
- github.com/git-pkgs/vulns v0.2.2
- github.com/go-chi/chi/v5 v5.3.1
+ github.com/git-pkgs/enrichment v0.4.1
+ github.com/git-pkgs/purl v0.1.13
+ github.com/git-pkgs/registries v0.6.2
+ github.com/git-pkgs/spdx v0.1.4
+ github.com/git-pkgs/vers v0.2.6
+ github.com/git-pkgs/vulns v0.1.6
+ github.com/go-chi/chi/v5 v5.3.0
github.com/jmoiron/sqlx v1.4.0
github.com/lib/pq v1.12.3
- github.com/prometheus/client_golang v1.24.1
+ github.com/prometheus/client_golang v1.23.2
github.com/prometheus/client_model v0.6.2
github.com/spdx/tools-golang v0.5.7
github.com/swaggo/swag v1.16.6
gocloud.dev v0.46.0
- golang.org/x/sync v0.22.0
- google.golang.org/protobuf v1.36.12
+ golang.org/x/sync v0.21.0
+ google.golang.org/protobuf v1.36.11
gopkg.in/yaml.v3 v3.0.1
- modernc.org/sqlite v1.56.0
+ modernc.org/sqlite v1.53.0
)
require (
- 4d63.com/gocheckcompilerdirectives v1.4.0 // indirect
+ 4d63.com/gocheckcompilerdirectives v1.3.0 // indirect
4d63.com/gochecknoglobals v0.2.2 // indirect
- charm.land/lipgloss/v2 v2.0.6 // indirect
- cloud.google.com/go/auth v0.21.0 // indirect
+ cloud.google.com/go/auth v0.18.2 // indirect
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
cloud.google.com/go/compute/metadata v0.9.0 // indirect
codeberg.org/chavacava/garif v0.2.0 // indirect
codeberg.org/polyfloyd/go-errorlint v1.9.0 // indirect
dev.gaijin.team/go/exhaustruct/v4 v4.0.0 // indirect
- dev.gaijin.team/go/exhaustruct/v5 v5.0.3 // indirect
- dev.gaijin.team/go/golib v0.8.1 // indirect
+ dev.gaijin.team/go/golib v0.6.0 // indirect
github.com/4meepo/tagalign v1.4.3 // indirect
- github.com/Abirdcfly/dupword v0.1.8 // indirect
+ github.com/Abirdcfly/dupword v0.1.7 // indirect
github.com/AdminBenni/iota-mixing v1.0.0 // indirect
- github.com/AlwxSin/noinlineerr v1.0.6 // indirect
- github.com/Antonboom/errname v1.1.2 // indirect
- github.com/Antonboom/nilnil v1.1.2 // indirect
+ github.com/AlwxSin/noinlineerr v1.0.5 // indirect
+ github.com/Antonboom/errname v1.1.1 // indirect
+ github.com/Antonboom/nilnil v1.1.1 // indirect
github.com/Antonboom/testifylint v1.6.4 // indirect
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0 // indirect
github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1 // indirect
github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2 // indirect
github.com/Azure/azure-sdk-for-go/sdk/storage/azblob v1.6.4 // indirect
github.com/AzureAD/microsoft-authentication-library-for-go v1.7.0 // indirect
- github.com/ClickHouse/clickhouse-go-linter v1.2.1 // indirect
github.com/Djarvur/go-err113 v0.1.1 // indirect
github.com/KyleBanks/depth v1.2.1 // indirect
- github.com/Masterminds/semver/v3 v3.5.0 // indirect
- github.com/MirrexOne/unqueryvet v1.5.4 // indirect
+ github.com/Masterminds/semver/v3 v3.4.0 // indirect
+ github.com/MirrexOne/unqueryvet v1.5.3 // indirect
github.com/OpenPeeDeeP/depguard/v2 v2.2.1 // indirect
github.com/PuerkitoBio/purell v1.1.1 // indirect
github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 // indirect
- github.com/alecthomas/chroma/v2 v2.27.0 // indirect
+ github.com/alecthomas/chroma/v2 v2.23.1 // indirect
github.com/alecthomas/go-check-sumtype v0.3.1 // indirect
github.com/alexkohler/nakedret/v2 v2.0.6 // indirect
- github.com/alexkohler/prealloc v1.1.0 // indirect
+ github.com/alexkohler/prealloc v1.0.2 // indirect
github.com/alfatraining/structtag v1.0.0 // indirect
github.com/alingse/asasalint v0.0.11 // indirect
github.com/alingse/nilnesserr v0.2.0 // indirect
github.com/anchore/go-struct-converter v0.1.0 // indirect
github.com/apapsch/go-jsonmerge/v2 v2.0.0 // indirect
- github.com/ashanbrown/forbidigo/v2 v2.3.1 // indirect
- github.com/ashanbrown/makezero/v2 v2.2.1 // indirect
+ github.com/ashanbrown/forbidigo/v2 v2.3.0 // indirect
+ github.com/ashanbrown/makezero/v2 v2.1.0 // indirect
github.com/aws/aws-sdk-go-v2 v1.41.9 // indirect
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.11 // indirect
github.com/aws/aws-sdk-go-v2/config v1.32.20 // indirect
@@ -93,49 +86,48 @@ require (
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.36.2 // indirect
github.com/aws/aws-sdk-go-v2/service/sts v1.42.3 // indirect
github.com/aws/smithy-go v1.26.0 // indirect
+ github.com/aymanbagabas/go-osc52/v2 v2.0.1 // indirect
github.com/beorn7/perks v1.0.1 // indirect
github.com/bkielbasa/cyclop v1.2.3 // indirect
github.com/blizzy78/varnamelen v0.8.0 // indirect
github.com/bombsimon/wsl/v4 v4.7.0 // indirect
- github.com/bombsimon/wsl/v5 v5.9.0 // indirect
+ github.com/bombsimon/wsl/v5 v5.6.0 // indirect
github.com/breml/bidichk v0.3.3 // indirect
github.com/breml/errchkjson v0.4.1 // indirect
- github.com/butuzov/ireturn v0.4.1 // indirect
- github.com/butuzov/mirror v1.3.3 // indirect
+ github.com/butuzov/ireturn v0.4.0 // indirect
+ github.com/butuzov/mirror v1.3.0 // indirect
github.com/catenacyber/perfsprint v0.10.1 // indirect
github.com/ccojocar/zxcvbn-go v1.0.4 // indirect
github.com/cenk/backoff v2.2.1+incompatible // indirect
github.com/cespare/xxhash/v2 v2.3.0 // indirect
github.com/charithe/durationcheck v0.0.11 // indirect
- github.com/charmbracelet/colorprofile v0.4.3 // indirect
- github.com/charmbracelet/ultraviolet v0.0.0-20260811164956-006e29f97886 // indirect
- github.com/charmbracelet/x/ansi v0.11.8 // indirect
- github.com/charmbracelet/x/term v0.2.2 // indirect
- github.com/charmbracelet/x/termios v0.1.1 // indirect
- github.com/charmbracelet/x/windows v0.2.2 // indirect
+ github.com/charmbracelet/colorprofile v0.2.3-0.20250311203215-f60798e515dc // indirect
+ github.com/charmbracelet/lipgloss v1.1.0 // indirect
+ github.com/charmbracelet/x/ansi v0.10.1 // indirect
+ github.com/charmbracelet/x/cellbuf v0.0.13-0.20250311204145-2c3ea96c31dd // indirect
+ github.com/charmbracelet/x/term v0.2.1 // indirect
github.com/ckaznocha/intrange v0.3.1 // indirect
- github.com/clipperhouse/displaywidth v0.11.0 // indirect
- github.com/clipperhouse/uax29/v2 v2.7.0 // indirect
github.com/cpuguy83/go-md2man/v2 v2.0.6 // indirect
github.com/curioswitch/go-reassign v0.3.0 // indirect
github.com/daixiang0/gci v0.13.7 // indirect
github.com/dave/dst v0.27.3 // indirect
+ github.com/davecgh/go-spew v1.1.1 // indirect
github.com/denis-tingaikin/go-header v0.5.0 // indirect
- github.com/dlclark/regexp2/v2 v2.2.1 // indirect
+ github.com/dlclark/regexp2 v1.11.5 // indirect
github.com/dustin/go-humanize v1.0.1 // indirect
- github.com/ecosyste-ms/ecosystems-go v0.4.0 // indirect
+ github.com/ecosyste-ms/ecosystems-go v0.2.0 // indirect
github.com/ettle/strcase v0.2.0 // indirect
github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a // indirect
- github.com/fatih/color v1.19.0 // indirect
+ github.com/fatih/color v1.18.0 // indirect
github.com/fatih/structtag v1.2.0 // indirect
- github.com/firefart/nonamedreturns v1.0.8 // indirect
+ github.com/firefart/nonamedreturns v1.0.6 // indirect
github.com/fsnotify/fsnotify v1.9.0 // indirect
github.com/fzipp/gocyclo v0.6.0 // indirect
- github.com/ghostiam/protogetter v0.3.21 // indirect
+ github.com/ghostiam/protogetter v0.3.20 // indirect
github.com/git-pkgs/packageurl-go v0.3.1 // indirect
github.com/git-pkgs/pom v0.1.5 // indirect
github.com/github/go-spdx/v2 v2.7.0 // indirect
- github.com/go-critic/go-critic v0.14.4 // indirect
+ github.com/go-critic/go-critic v0.14.3 // indirect
github.com/go-logr/logr v1.4.3 // indirect
github.com/go-logr/stdr v1.2.2 // indirect
github.com/go-openapi/jsonpointer v0.19.5 // indirect
@@ -156,108 +148,107 @@ require (
github.com/gofrs/flock v0.13.0 // indirect
github.com/golang-jwt/jwt/v5 v5.3.1 // indirect
github.com/golangci/asciicheck v0.5.0 // indirect
- github.com/golangci/dupl v0.0.0-20260401084720-c99c5cf5c202 // indirect
+ github.com/golangci/dupl v0.0.0-20250308024227-f665c8d69b32 // indirect
github.com/golangci/go-printf-func-name v0.1.1 // indirect
- github.com/golangci/gofmt v0.0.0-20260820135601-e84e05053792 // indirect
- github.com/golangci/golangci-lint/v2 v2.13.1 // indirect
+ github.com/golangci/gofmt v0.0.0-20250106114630-d62b90e6713d // indirect
+ github.com/golangci/golangci-lint/v2 v2.10.1 // indirect
github.com/golangci/golines v0.15.0 // indirect
github.com/golangci/misspell v0.8.0 // indirect
github.com/golangci/plugin-module-register v0.1.2 // indirect
github.com/golangci/revgrep v0.8.0 // indirect
- github.com/golangci/rowserrcheck v0.0.0-20260419091836-c5f79b8a11ba // indirect
github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e // indirect
github.com/golangci/unconvert v0.0.0-20250410112200-a129a6e6413e // indirect
github.com/google/go-cmp v0.7.0 // indirect
github.com/google/s2a-go v0.1.9 // indirect
github.com/google/uuid v1.6.0 // indirect
github.com/google/wire v0.7.0 // indirect
- github.com/googleapis/enterprise-certificate-proxy v0.3.18 // indirect
- github.com/googleapis/gax-go/v2 v2.23.0 // indirect
+ github.com/googleapis/enterprise-certificate-proxy v0.3.14 // indirect
+ github.com/googleapis/gax-go/v2 v2.19.0 // indirect
github.com/gordonklaus/ineffassign v0.2.0 // indirect
github.com/gostaticanalysis/analysisutil v0.7.1 // indirect
github.com/gostaticanalysis/comment v1.5.0 // indirect
github.com/gostaticanalysis/forcetypeassert v0.2.0 // indirect
github.com/gostaticanalysis/nilerr v0.1.2 // indirect
github.com/hashicorp/go-immutable-radix/v2 v2.1.0 // indirect
- github.com/hashicorp/go-version v1.9.0 // indirect
+ github.com/hashicorp/go-version v1.8.0 // indirect
github.com/hashicorp/golang-lru/v2 v2.0.7 // indirect
github.com/hashicorp/hcl v1.0.0 // indirect
github.com/hexops/gotextdiff v1.0.3 // indirect
github.com/inconshreveable/mousetrap v1.1.0 // indirect
- github.com/jgautheron/goconst v1.11.0 // indirect
+ github.com/jgautheron/goconst v1.8.2 // indirect
+ github.com/jingyugao/rowserrcheck v1.1.1 // indirect
github.com/jjti/go-spancheck v0.6.5 // indirect
github.com/josharian/intern v1.0.0 // indirect
github.com/julz/importas v0.2.0 // indirect
github.com/karamaru-alpha/copyloopvar v1.2.2 // indirect
- github.com/kisielk/errcheck v1.20.0 // indirect
+ github.com/kisielk/errcheck v1.9.0 // indirect
github.com/kkHAIKE/contextcheck v1.1.6 // indirect
github.com/kulti/thelper v0.7.1 // indirect
github.com/kunwardeep/paralleltest v1.0.15 // indirect
github.com/kylelemons/godebug v1.1.0 // indirect
github.com/lasiar/canonicalheader v1.1.2 // indirect
github.com/ldez/exptostd v0.4.5 // indirect
- github.com/ldez/gomoddirectives v0.9.0 // indirect
+ github.com/ldez/gomoddirectives v0.8.0 // indirect
github.com/ldez/grignotin v0.10.1 // indirect
github.com/ldez/structtags v0.6.1 // indirect
github.com/ldez/tagliatelle v0.7.2 // indirect
github.com/ldez/usetesting v0.5.0 // indirect
github.com/leonklingele/grouper v1.1.2 // indirect
- github.com/lucasb-eyer/go-colorful v1.4.1 // indirect
+ github.com/lucasb-eyer/go-colorful v1.2.0 // indirect
github.com/macabu/inamedparam v0.2.0 // indirect
github.com/magiconair/properties v1.8.6 // indirect
github.com/mailru/easyjson v0.7.7 // indirect
github.com/manuelarte/embeddedstructfieldcheck v0.4.0 // indirect
- github.com/manuelarte/funcorder v0.6.0 // indirect
+ github.com/manuelarte/funcorder v0.5.0 // indirect
github.com/maratori/testableexamples v1.0.1 // indirect
github.com/maratori/testpackage v1.1.2 // indirect
github.com/matoous/godox v1.1.0 // indirect
- github.com/mattn/go-colorable v0.1.15 // indirect
- github.com/mattn/go-isatty v0.0.24 // indirect
- github.com/mattn/go-runewidth v0.0.24 // indirect
- github.com/mgechev/revive v1.15.0 // indirect
+ github.com/mattn/go-colorable v0.1.14 // indirect
+ github.com/mattn/go-isatty v0.0.20 // indirect
+ github.com/mattn/go-runewidth v0.0.16 // indirect
+ github.com/mgechev/revive v1.14.0 // indirect
github.com/mitchellh/go-homedir v1.1.0 // indirect
github.com/mitchellh/mapstructure v1.5.0 // indirect
github.com/moricho/tparallel v0.3.2 // indirect
- github.com/muesli/cancelreader v0.2.2 // indirect
+ github.com/muesli/termenv v0.16.0 // indirect
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
github.com/nakabonne/nestif v0.3.1 // indirect
github.com/ncruces/go-strftime v1.0.0 // indirect
github.com/nishanths/exhaustive v0.12.0 // indirect
github.com/nishanths/predeclared v0.2.2 // indirect
- github.com/nunnatsa/ginkgolinter v0.24.0 // indirect
- github.com/oapi-codegen/nullable v1.2.0 // indirect
- github.com/oapi-codegen/runtime v1.6.0 // indirect
+ github.com/nunnatsa/ginkgolinter v0.23.0 // indirect
+ github.com/oapi-codegen/runtime v1.4.1 // indirect
github.com/package-url/packageurl-go v0.1.6 // indirect
github.com/pandatix/go-cvss v0.6.2 // indirect
github.com/pelletier/go-toml v1.9.5 // indirect
- github.com/pelletier/go-toml/v2 v2.4.3 // indirect
+ github.com/pelletier/go-toml/v2 v2.2.4 // indirect
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
- github.com/prometheus/common v0.70.1 // indirect
- github.com/prometheus/procfs v0.21.1 // indirect
+ github.com/pmezard/go-difflib v1.0.0 // indirect
+ github.com/prometheus/common v0.67.5 // indirect
+ github.com/prometheus/procfs v0.20.1 // indirect
github.com/quasilyte/go-ruleguard v0.4.5 // indirect
github.com/quasilyte/go-ruleguard/dsl v0.3.23 // indirect
github.com/quasilyte/gogrep v0.5.0 // indirect
github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727 // indirect
github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567 // indirect
- github.com/raeperd/recvcheck v0.3.0 // indirect
+ github.com/raeperd/recvcheck v0.2.0 // indirect
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
github.com/rivo/uniseg v0.4.7 // indirect
- github.com/rogpeppe/go-internal v1.16.0 // indirect
+ github.com/rogpeppe/go-internal v1.14.1 // indirect
github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529 // indirect
github.com/rubyist/circuitbreaker v2.2.1+incompatible // indirect
github.com/russross/blackfriday/v2 v2.1.0 // indirect
github.com/ryancurrah/gomodguard v1.4.1 // indirect
- github.com/ryancurrah/gomodguard/v2 v2.1.3 // indirect
- github.com/ryanrolds/sqlclosecheck v0.6.0 // indirect
+ github.com/ryanrolds/sqlclosecheck v0.5.1 // indirect
github.com/sanposhiho/wastedassign/v2 v2.1.0 // indirect
- github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 // indirect
+ github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 // indirect
github.com/sashamelentyev/interfacebloat v1.1.0 // indirect
github.com/sashamelentyev/usestdlibvars v1.29.0 // indirect
- github.com/securego/gosec/v2 v2.28.0 // indirect
- github.com/sirupsen/logrus v1.10.1 // indirect
+ github.com/securego/gosec/v2 v2.23.0 // indirect
+ github.com/sirupsen/logrus v1.9.4 // indirect
github.com/sivchari/containedctx v1.0.3 // indirect
- github.com/sonatard/noctx v0.5.1 // indirect
- github.com/sourcegraph/go-diff v0.8.0 // indirect
+ github.com/sonatard/noctx v0.4.0 // indirect
+ github.com/sourcegraph/go-diff v0.7.0 // indirect
github.com/spf13/afero v1.15.0 // indirect
github.com/spf13/cast v1.5.0 // indirect
github.com/spf13/cobra v1.10.2 // indirect
@@ -266,20 +257,20 @@ require (
github.com/spf13/viper v1.12.0 // indirect
github.com/ssgreg/nlreturn/v2 v2.2.1 // indirect
github.com/stbenjam/no-sprintf-host-port v0.3.1 // indirect
- github.com/stretchr/objx v0.5.3 // indirect
- github.com/stretchr/testify v1.12.1 // indirect
+ github.com/stretchr/objx v0.5.2 // indirect
+ github.com/stretchr/testify v1.11.1 // indirect
github.com/subosito/gotenv v1.4.1 // indirect
- github.com/tetafro/godot v1.5.6 // indirect
- github.com/timakin/bodyclose v0.0.0-20260129054331-73d1f95b84b4 // indirect
+ github.com/tetafro/godot v1.5.4 // indirect
+ github.com/timakin/bodyclose v0.0.0-20241222091800-1db5c5ca4d67 // indirect
github.com/timonwong/loggercheck v0.11.0 // indirect
github.com/tomarrell/wrapcheck/v2 v2.12.0 // indirect
github.com/tommy-muehle/go-mnd/v2 v2.5.1 // indirect
- github.com/ulikunitz/xz v0.5.16 // indirect
+ github.com/ulikunitz/xz v0.5.15 // indirect
github.com/ultraware/funlen v0.2.0 // indirect
github.com/ultraware/whitespace v0.2.0 // indirect
github.com/urfave/cli/v2 v2.3.0 // indirect
- github.com/uudashr/gocognit v1.2.1 // indirect
- github.com/uudashr/iface v1.5.0 // indirect
+ github.com/uudashr/gocognit v1.2.0 // indirect
+ github.com/uudashr/iface v1.4.1 // indirect
github.com/xen0n/gosmopolitan v1.3.0 // indirect
github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e // indirect
github.com/yagipy/maintidx v1.0.0 // indirect
@@ -287,9 +278,9 @@ require (
github.com/ykadowak/zerologlint v0.1.5 // indirect
gitlab.com/bosi/decorder v0.4.2 // indirect
go-simpler.org/musttag v0.14.0 // indirect
- go-simpler.org/sloglint v0.12.0 // indirect
+ go-simpler.org/sloglint v0.11.1 // indirect
go.augendre.info/arangolint v0.4.0 // indirect
- go.augendre.info/fatcontext v0.10.0 // indirect
+ go.augendre.info/fatcontext v0.9.0 // indirect
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
go.opentelemetry.io/otel v1.44.0 // indirect
go.opentelemetry.io/otel/metric v1.44.0 // indirect
@@ -298,29 +289,29 @@ require (
go.opentelemetry.io/otel/trace v1.44.0 // indirect
go.uber.org/multierr v1.11.0 // indirect
go.uber.org/zap v1.27.1 // indirect
- go.yaml.in/yaml/v2 v2.4.4 // indirect
- go.yaml.in/yaml/v3 v3.0.5 // indirect
- golang.org/x/crypto v0.55.0 // indirect
+ go.yaml.in/yaml/v2 v2.4.3 // indirect
+ go.yaml.in/yaml/v3 v3.0.4 // indirect
+ golang.org/x/crypto v0.53.0 // indirect
golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa // indirect
- golang.org/x/exp/typeparams v0.0.0-20260811152304-ee035b5b010f // indirect
- golang.org/x/mod v0.40.0 // indirect
- golang.org/x/net v0.58.0 // indirect
+ golang.org/x/exp/typeparams v0.0.0-20260209203927-2842357ff358 // indirect
+ golang.org/x/mod v0.36.0 // indirect
+ golang.org/x/net v0.56.0 // indirect
golang.org/x/oauth2 v0.36.0 // indirect
- golang.org/x/sys v0.47.0 // indirect
- golang.org/x/text v0.41.0 // indirect
- golang.org/x/tools v0.49.0 // indirect
+ golang.org/x/sys v0.46.0 // indirect
+ golang.org/x/text v0.38.0 // indirect
+ golang.org/x/tools v0.45.0 // indirect
golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
- google.golang.org/api v0.288.0 // indirect
- google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800 // indirect
- google.golang.org/grpc v1.82.1 // indirect
+ google.golang.org/api v0.272.0 // indirect
+ google.golang.org/genproto/googleapis/rpc v0.0.0-20260316180232-0b37fe3546d5 // indirect
+ google.golang.org/grpc v1.81.1 // indirect
gopkg.in/ini.v1 v1.67.0 // indirect
gopkg.in/yaml.v2 v2.4.0 // indirect
- honnef.co/go/tools v0.8.0 // indirect
- modernc.org/libc v1.74.4 // indirect
+ honnef.co/go/tools v0.7.0 // indirect
+ modernc.org/libc v1.73.4 // indirect
modernc.org/mathutil v1.7.1 // indirect
modernc.org/memory v1.11.0 // indirect
- mvdan.cc/gofumpt v0.11.0 // indirect
- mvdan.cc/unparam v0.0.0-20260818115549-3f964bcb5673 // indirect
+ mvdan.cc/gofumpt v0.9.2 // indirect
+ mvdan.cc/unparam v0.0.0-20251027182757-5beb8c8f8f15 // indirect
sigs.k8s.io/yaml v1.6.0 // indirect
)
diff --git a/go.sum b/go.sum
index e2fedc7..93bed13 100644
--- a/go.sum
+++ b/go.sum
@@ -1,15 +1,13 @@
-4d63.com/gocheckcompilerdirectives v1.4.0 h1:ZLq62rbGWVmQhiZ8kuNVIT/M09xCSTdJz9K3xOdT/CY=
-4d63.com/gocheckcompilerdirectives v1.4.0/go.mod h1:9ZOAiMOjqC/nRwci2fcUXVHUNLG/cH6r6rhUh+jTFtQ=
+4d63.com/gocheckcompilerdirectives v1.3.0 h1:Ew5y5CtcAAQeTVKUVFrE7EwHMrTO6BggtEj8BZSjZ3A=
+4d63.com/gocheckcompilerdirectives v1.3.0/go.mod h1:ofsJ4zx2QAuIP/NO/NAh1ig6R1Fb18/GI7RVMwz7kAY=
4d63.com/gochecknoglobals v0.2.2 h1:H1vdnwnMaZdQW/N+NrkT1SZMTBmcwHe9Vq8lJcYYTtU=
4d63.com/gochecknoglobals v0.2.2/go.mod h1:lLxwTQjL5eIesRbvnzIP3jZtG140FnTdz+AlMa+ogt0=
cel.dev/expr v0.25.1 h1:1KrZg61W6TWSxuNZ37Xy49ps13NUovb66QLprthtwi4=
cel.dev/expr v0.25.1/go.mod h1:hrXvqGP6G6gyx8UAHSHJ5RGk//1Oj5nXQ2NI02Nrsg4=
-charm.land/lipgloss/v2 v2.0.6 h1:EaGKeuA8FvF+v2BT5VmZd2LoYLaMZJXA5n34th8nCIQ=
-charm.land/lipgloss/v2 v2.0.6/go.mod h1:ipDDJNSGa1hlwDtSfW1s2/xR8Vdhbut4PXh2zEKZd0Q=
cloud.google.com/go v0.123.0 h1:2NAUJwPR47q+E35uaJeYoNhuNEM9kM8SjgRgdeOJUSE=
cloud.google.com/go v0.123.0/go.mod h1:xBoMV08QcqUGuPW65Qfm1o9Y4zKZBpGS+7bImXLTAZU=
-cloud.google.com/go/auth v0.21.0 h1:g/QwYfYb2Ai6HH8oomAOyBaIHLbscZ4+T/F/f5JZHkE=
-cloud.google.com/go/auth v0.21.0/go.mod h1:M9o2Oz+YI2jAfxewJgb1vyI3vceHF+eohmxyzmrl+9s=
+cloud.google.com/go/auth v0.18.2 h1:+Nbt5Ev0xEqxlNjd6c+yYUeosQ5TtEUaNcN/3FozlaM=
+cloud.google.com/go/auth v0.18.2/go.mod h1:xD+oY7gcahcu7G2SG2DsBerfFxgPAJz17zz2joOFF3M=
cloud.google.com/go/auth/oauth2adapt v0.2.8 h1:keo8NaayQZ6wimpNSmW5OPc283g65QNIiLpZnkHRbnc=
cloud.google.com/go/auth/oauth2adapt v0.2.8/go.mod h1:XQ9y31RkqZCcwJWNSx2Xvric3RrU88hAYYbjDWYDL+c=
cloud.google.com/go/compute/metadata v0.9.0 h1:pDUj4QMoPejqq20dK0Pg2N4yG9zIkYGdBtwLoEkH9Zs=
@@ -26,25 +24,23 @@ codeberg.org/polyfloyd/go-errorlint v1.9.0 h1:VkdEEmA1VBpH6ecQoMR4LdphVI3fA4RrCh
codeberg.org/polyfloyd/go-errorlint v1.9.0/go.mod h1:GPRRu2LzVijNn4YkrZYJfatQIdS+TrcK8rL5Xs24qw8=
dev.gaijin.team/go/exhaustruct/v4 v4.0.0 h1:873r7aNneqoBB3IaFIzhvt2RFYTuHgmMjoKfwODoI1Y=
dev.gaijin.team/go/exhaustruct/v4 v4.0.0/go.mod h1:aZ/k2o4Y05aMJtiux15x8iXaumE88YdiB0Ai4fXOzPI=
-dev.gaijin.team/go/exhaustruct/v5 v5.0.3 h1:yOeA7DNjlT8y4yfmN6nWWYYggA13N523YAj9/TXbuTM=
-dev.gaijin.team/go/exhaustruct/v5 v5.0.3/go.mod h1:KwtBsX8nHHH1YxhxkpiBq6bfsmw5WnazWpNvJPHgY9Y=
-dev.gaijin.team/go/golib v0.8.1 h1:JYju4x9BSo+QD/AYeHULVDcvEhiFg8wOi6pT0IaZF5E=
-dev.gaijin.team/go/golib v0.8.1/go.mod h1:c5fu7t1RSGMxSQgcUYO1sODbzsYnOCXJLmHeNG1Eb+0=
+dev.gaijin.team/go/golib v0.6.0 h1:v6nnznFTs4bppib/NyU1PQxobwDHwCXXl15P7DV5Zgo=
+dev.gaijin.team/go/golib v0.6.0/go.mod h1:uY1mShx8Z/aNHWDyAkZTkX+uCi5PdX7KsG1eDQa2AVE=
filippo.io/edwards25519 v1.1.0/go.mod h1:BxyFTGdWcka3PhytdK4V28tE5sGfRvvvRV7EaN4VDT4=
filippo.io/edwards25519 v1.2.0 h1:crnVqOiS4jqYleHd9vaKZ+HKtHfllngJIiOpNpoJsjo=
filippo.io/edwards25519 v1.2.0/go.mod h1:xzAOLCNug/yB62zG1bQ8uziwrIqIuxhctzJT18Q77mc=
github.com/4meepo/tagalign v1.4.3 h1:Bnu7jGWwbfpAie2vyl63Zup5KuRv21olsPIha53BJr8=
github.com/4meepo/tagalign v1.4.3/go.mod h1:00WwRjiuSbrRJnSVeGWPLp2epS5Q/l4UEy0apLLS37c=
-github.com/Abirdcfly/dupword v0.1.8 h1:SrhcUuGsROBuChFxHALRYzyyPODWn9zwghmzPvD9Cd8=
-github.com/Abirdcfly/dupword v0.1.8/go.mod h1:XZrhVnI7YGpsTiWZANSQaBJ4QpL/Tq5vIEdKJJAs9WI=
+github.com/Abirdcfly/dupword v0.1.7 h1:2j8sInznrje4I0CMisSL6ipEBkeJUJAmK1/lfoNGWrQ=
+github.com/Abirdcfly/dupword v0.1.7/go.mod h1:K0DkBeOebJ4VyOICFdppB23Q0YMOgVafM0zYW0n9lF4=
github.com/AdminBenni/iota-mixing v1.0.0 h1:Os6lpjG2dp/AE5fYBPAA1zfa2qMdCAWwPMCgpwKq7wo=
github.com/AdminBenni/iota-mixing v1.0.0/go.mod h1:i4+tpAaB+qMVIV9OK3m4/DAynOd5bQFaOu+2AhtBCNY=
-github.com/AlwxSin/noinlineerr v1.0.6 h1:KAvuxunTe9QxvqrFB7nZTdb/7Wzas4AvifslTnG0Ld8=
-github.com/AlwxSin/noinlineerr v1.0.6/go.mod h1:+QgkkoYrMH7RHvcdxdlI7vYYEdgeoFOVjU9sUhw/rQc=
-github.com/Antonboom/errname v1.1.2 h1:dxwONZJua3VB8Xh/VaCjqAcqF645sWWv7xj26zy7tdQ=
-github.com/Antonboom/errname v1.1.2/go.mod h1:YeZIpgLMxT+SNkruGgYkLhzq/9vs3fsolTZegKaKDZI=
-github.com/Antonboom/nilnil v1.1.2 h1:aNlFuJhaEseXe4fHO3xbjXlSeEiQVYa2lEkWD2s2hAY=
-github.com/Antonboom/nilnil v1.1.2/go.mod h1:0ynwvphOLmAuMwTNDyBnDZmSwZoDpcFXmUHmzoHH2WA=
+github.com/AlwxSin/noinlineerr v1.0.5 h1:RUjt63wk1AYWTXtVXbSqemlbVTb23JOSRiNsshj7TbY=
+github.com/AlwxSin/noinlineerr v1.0.5/go.mod h1:+QgkkoYrMH7RHvcdxdlI7vYYEdgeoFOVjU9sUhw/rQc=
+github.com/Antonboom/errname v1.1.1 h1:bllB7mlIbTVzO9jmSWVWLjxTEbGBVQ1Ff/ClQgtPw9Q=
+github.com/Antonboom/errname v1.1.1/go.mod h1:gjhe24xoxXp0ScLtHzjiXp0Exi1RFLKJb0bVBtWKCWQ=
+github.com/Antonboom/nilnil v1.1.1 h1:9Mdr6BYd8WHCDngQnNVV0b554xyisFioEKi30sksufQ=
+github.com/Antonboom/nilnil v1.1.1/go.mod h1:yCyAmSw3doopbOWhJlVci+HuyNRuHJKIv6V2oYQa8II=
github.com/Antonboom/testifylint v1.6.4 h1:gs9fUEy+egzxkEbq9P4cpcMB6/G0DYdMeiFS87UiqmQ=
github.com/Antonboom/testifylint v1.6.4/go.mod h1:YO33FROXX2OoUfwjz8g+gUxQXio5i9qpVy7nXGbxDD4=
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0 h1:fou+2+WFTib47nS+nz/ozhEBnvU96bKHy6LjRsY4E28=
@@ -66,24 +62,22 @@ github.com/AzureAD/microsoft-authentication-library-for-go v1.7.0/go.mod h1:HKpQ
github.com/BurntSushi/toml v0.3.1/go.mod h1:xHWCNGjB5oqiDr8zfno3MHue2Ht5sIBksp03qcyfWMU=
github.com/BurntSushi/toml v1.6.0 h1:dRaEfpa2VI55EwlIW72hMRHdWouJeRF7TPYhI+AUQjk=
github.com/BurntSushi/toml v1.6.0/go.mod h1:ukJfTF/6rtPPRCnwkur4qwRxa8vTRFBF0uk2lLoLwho=
-github.com/ClickHouse/clickhouse-go-linter v1.2.1 h1:zGEKIyd5YL08ieWG/LOUmlau2DxbxPVOfAeo+4Jz3ck=
-github.com/ClickHouse/clickhouse-go-linter v1.2.1/go.mod h1:pLorS7ffPTfuUV9M0SJgfHA/h/WQPQUk2FWG9x74cQ4=
github.com/CycloneDX/cyclonedx-go v0.11.0 h1:GokP8FiRC+foiuwWhSSLpSD5H4hSWtGnR3wo7apkBFI=
github.com/CycloneDX/cyclonedx-go v0.11.0/go.mod h1:vUvbCXQsEm48OI6oOlanxstwNByXjCZ2wuleUlwGEO8=
github.com/Djarvur/go-err113 v0.1.1 h1:eHfopDqXRwAi+YmCUas75ZE0+hoBHJ2GQNLYRSxao4g=
github.com/Djarvur/go-err113 v0.1.1/go.mod h1:IaWJdYFLg76t2ihfflPZnM1LIQszWOsFDh2hhhAVF6k=
-github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.32.0 h1:rIkQfkCOVKc1OiRCNcSDD8ml5RJlZbH/Xsq7lbpynwc=
-github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.32.0/go.mod h1:RD2SsorTmYhF6HkTmDw7KmPYQk8OBYwTkuasChwv7R4=
+github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.31.0 h1:DHa2U07rk8syqvCge0QIGMCE1WxGj9njT44GH7zNJLQ=
+github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.31.0/go.mod h1:P4WPRUkOhJC13W//jWpyfJNDAIpvRbAUIYLX/4jtlE0=
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0 h1:UnDZ/zFfG1JhH/DqxIZYU/1CUAlTUScoXD/LcM2Ykk8=
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0/go.mod h1:IA1C1U7jO/ENqm/vhi7V9YYpBsp+IMyqNrEN94N7tVc=
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0 h1:0s6TxfCu2KHkkZPnBfsQ2y5qia0jl3MMrmBhu3nCOYk=
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0/go.mod h1:Mf6O40IAyB9zR/1J8nGDDPirZQQPbYJni8Yisy7NTMc=
github.com/KyleBanks/depth v1.2.1 h1:5h8fQADFrWtarTdtDudMmGsC7GPbOAu6RVB3ffsVFHc=
github.com/KyleBanks/depth v1.2.1/go.mod h1:jzSb9d0L43HxTQfT+oSA1EEp2q+ne2uh6XgeJcm8brE=
-github.com/Masterminds/semver/v3 v3.5.0 h1:kQceYJfbupGfZOKZQg0kou0DgAKhzDg2NZPAwZ/2OOE=
-github.com/Masterminds/semver/v3 v3.5.0/go.mod h1:4V+yj/TJE1HU9XfppCwVMZq3I84lprf4nC11bSS5beM=
-github.com/MirrexOne/unqueryvet v1.5.4 h1:38QOxShO7JmMWT+eCdDMbcUgGCOeJphVkzzRgyLJgsQ=
-github.com/MirrexOne/unqueryvet v1.5.4/go.mod h1:fs9Zq6eh1LRIhsDIsxf9PONVUjYdFHdtkHIgZdJnyPU=
+github.com/Masterminds/semver/v3 v3.4.0 h1:Zog+i5UMtVoCU8oKka5P7i9q9HgrJeGzI9SA1Xbatp0=
+github.com/Masterminds/semver/v3 v3.4.0/go.mod h1:4V+yj/TJE1HU9XfppCwVMZq3I84lprf4nC11bSS5beM=
+github.com/MirrexOne/unqueryvet v1.5.3 h1:LpT3rsH+IY3cQddWF9bg4C7jsbASdGnrOSofY8IPEiw=
+github.com/MirrexOne/unqueryvet v1.5.3/go.mod h1:fs9Zq6eh1LRIhsDIsxf9PONVUjYdFHdtkHIgZdJnyPU=
github.com/OpenPeeDeeP/depguard/v2 v2.2.1 h1:vckeWVESWp6Qog7UZSARNqfu/cZqvki8zsuj3piCMx4=
github.com/OpenPeeDeeP/depguard/v2 v2.2.1/go.mod h1:q4DKzC4UcVaAvcfd41CZh0PWpGgzrVxUYBlgKNGquUo=
github.com/PuerkitoBio/purell v1.1.1 h1:WEQqlqaGbrPkxLJWfBwQmfEAE1Z7ONdDLqrN38tNFfI=
@@ -93,16 +87,16 @@ github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578/go.mod h1:uGdko
github.com/RaveNoX/go-jsoncommentstrip v1.0.0/go.mod h1:78ihd09MekBnJnxpICcwzCMzGrKSKYe4AqU6PDYYpjk=
github.com/alecthomas/assert/v2 v2.11.0 h1:2Q9r3ki8+JYXvGsDyBXwH3LcJ+WK5D0gc5E8vS6K3D0=
github.com/alecthomas/assert/v2 v2.11.0/go.mod h1:Bze95FyfUr7x34QZrjL+XP+0qgp/zg8yS+TtBj1WA3k=
-github.com/alecthomas/chroma/v2 v2.27.0 h1:FodwmyOBgJULFYmDqibcp9pvfDLWdtPRh9v/r5BXYZs=
-github.com/alecthomas/chroma/v2 v2.27.0/go.mod h1:NjJ3ciIgrqBNeIkWZ4e46nseoLDslxU1LmfCoL+wcY8=
+github.com/alecthomas/chroma/v2 v2.23.1 h1:nv2AVZdTyClGbVQkIzlDm/rnhk1E9bU9nXwmZ/Vk/iY=
+github.com/alecthomas/chroma/v2 v2.23.1/go.mod h1:NqVhfBR0lte5Ouh3DcthuUCTUpDC9cxBOfyMbMQPs3o=
github.com/alecthomas/go-check-sumtype v0.3.1 h1:u9aUvbGINJxLVXiFvHUlPEaD7VDULsrxJb4Aq31NLkU=
github.com/alecthomas/go-check-sumtype v0.3.1/go.mod h1:A8TSiN3UPRw3laIgWEUOHHLPa6/r9MtoigdlP5h3K/E=
github.com/alecthomas/repr v0.5.2 h1:SU73FTI9D1P5UNtvseffFSGmdNci/O6RsqzeXJtP0Qs=
github.com/alecthomas/repr v0.5.2/go.mod h1:Fr0507jx4eOXV7AlPV6AVZLYrLIuIeSOWtW57eE/O/4=
github.com/alexkohler/nakedret/v2 v2.0.6 h1:ME3Qef1/KIKr3kWX3nti3hhgNxw6aqN5pZmQiFSsuzQ=
github.com/alexkohler/nakedret/v2 v2.0.6/go.mod h1:l3RKju/IzOMQHmsEvXwkqMDzHHvurNQfAgE1eVmT40Q=
-github.com/alexkohler/prealloc v1.1.0 h1:cKGRBqlXw5iyQGLYhrXrDlcHxugXpTq4tQ5c91wkf8M=
-github.com/alexkohler/prealloc v1.1.0/go.mod h1:fT39Jge3bQrfA7nPMDngUfvUbQGQeJyGQnR+913SCig=
+github.com/alexkohler/prealloc v1.0.2 h1:MPo8cIkGkZytq7WNH9UHv3DIX1mPz1RatPXnZb0zHWQ=
+github.com/alexkohler/prealloc v1.0.2/go.mod h1:fT39Jge3bQrfA7nPMDngUfvUbQGQeJyGQnR+913SCig=
github.com/alfatraining/structtag v1.0.0 h1:2qmcUqNcCoyVJ0up879K614L9PazjBSFruTB0GOFjCc=
github.com/alfatraining/structtag v1.0.0/go.mod h1:p3Xi5SwzTi+Ryj64DqjLWz7XurHxbGsq6y3ubePJPus=
github.com/alingse/asasalint v0.0.11 h1:SFwnQXJ49Kx/1GghOFz1XGqHYKp21Kq1nHad/0WQRnw=
@@ -113,10 +107,10 @@ github.com/anchore/go-struct-converter v0.1.0 h1:2rDRssAl6mgKBSLNiVCMADgZRhoqtw9
github.com/anchore/go-struct-converter v0.1.0/go.mod h1:rYqSE9HbjzpHTI74vwPvae4ZVYZd1lue2ta6xHPdblA=
github.com/apapsch/go-jsonmerge/v2 v2.0.0 h1:axGnT1gRIfimI7gJifB699GoE/oq+F2MU7Dml6nw9rQ=
github.com/apapsch/go-jsonmerge/v2 v2.0.0/go.mod h1:lvDnEdqiQrp0O42VQGgmlKpxL1AP2+08jFMw88y4klk=
-github.com/ashanbrown/forbidigo/v2 v2.3.1 h1:KAZijvQ7zeIBKbhikT4jCm0TLYXC4u78bTiLh/8JROI=
-github.com/ashanbrown/forbidigo/v2 v2.3.1/go.mod h1:2QDkLTzU6TV937eFROamXrW92M3paehdae4HCDCOZCM=
-github.com/ashanbrown/makezero/v2 v2.2.1 h1:A7uU8dgB1PA9aelTxHMfHIQ8Qev8AB3JLxJUBUsejqM=
-github.com/ashanbrown/makezero/v2 v2.2.1/go.mod h1:aEGT/9q3S8DHeE57C88z2a6xydvgx8J5hgXIGWgo0MY=
+github.com/ashanbrown/forbidigo/v2 v2.3.0 h1:OZZDOchCgsX5gvToVtEBoV2UWbFfI6RKQTir2UZzSxo=
+github.com/ashanbrown/forbidigo/v2 v2.3.0/go.mod h1:5p6VmsG5/1xx3E785W9fouMxIOkvY2rRV9nMdWadd6c=
+github.com/ashanbrown/makezero/v2 v2.1.0 h1:snuKYMbqosNokUKm+R6/+vOPs8yVAi46La7Ck6QYSaE=
+github.com/ashanbrown/makezero/v2 v2.1.0/go.mod h1:aEGT/9q3S8DHeE57C88z2a6xydvgx8J5hgXIGWgo0MY=
github.com/aws/aws-sdk-go-v2 v1.41.9 h1:/rYeyO2+HrMztAmxAq9++XJtFMqSIpSsNA0yDGALYq4=
github.com/aws/aws-sdk-go-v2 v1.41.9/go.mod h1:+HsoOEX80qAVUitj1A2DhCNTjmb3edVyuDypb6LNEeo=
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.11 h1:h5+3VT69KUBK24grGuuA5saDJTj2IIjLb9au668Fo5I=
@@ -155,6 +149,8 @@ github.com/aws/aws-sdk-go-v2/service/sts v1.42.3 h1:ErklX/7uhSbkAAeyQD/Y1OoQ9hO3
github.com/aws/aws-sdk-go-v2/service/sts v1.42.3/go.mod h1:ULe4HCzfKPiR6R3HEurE3b1upEkuk8AkMrOKtaOxKO8=
github.com/aws/smithy-go v1.26.0 h1:9ouqbi+NyKP7fV3Te7UElCwdAb6Y8uk7LGwPE5tVe/s=
github.com/aws/smithy-go v1.26.0/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc=
+github.com/aymanbagabas/go-osc52/v2 v2.0.1 h1:HwpRHbFMcZLEVr42D4p7XBqjyuxQH5SMiErDT4WkJ2k=
+github.com/aymanbagabas/go-osc52/v2 v2.0.1/go.mod h1:uYgXzlJ7ZpABp8OJ+exZzJJhRNQ2ASbcXHWsFqH8hp8=
github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM=
github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6rlkpw=
github.com/bkielbasa/cyclop v1.2.3 h1:faIVMIGDIANuGPWH031CZJTi2ymOQBULs9H21HSMa5w=
@@ -164,18 +160,18 @@ github.com/blizzy78/varnamelen v0.8.0/go.mod h1:V9TzQZ4fLJ1DSrjVDfl89H7aMnTvKkAp
github.com/bmatcuk/doublestar v1.1.1/go.mod h1:UD6OnuiIn0yFxxA2le/rnRU1G4RaI4UvFv1sNto9p6w=
github.com/bombsimon/wsl/v4 v4.7.0 h1:1Ilm9JBPRczjyUs6hvOPKvd7VL1Q++PL8M0SXBDf+jQ=
github.com/bombsimon/wsl/v4 v4.7.0/go.mod h1:uV/+6BkffuzSAVYD+yGyld1AChO7/EuLrCF/8xTiapg=
-github.com/bombsimon/wsl/v5 v5.9.0 h1:WCrgZ7RQnZO5oEwbVTlYgBdU3wL294kR1BSWV8vTfsU=
-github.com/bombsimon/wsl/v5 v5.9.0/go.mod h1:kjo4HiAV5FDkHC8/uzJq9mBffEEd6WT/nvN7DoMovDM=
+github.com/bombsimon/wsl/v5 v5.6.0 h1:4z+/sBqC5vUmSp1O0mS+czxwH9+LKXtCWtHH9rZGQL8=
+github.com/bombsimon/wsl/v5 v5.6.0/go.mod h1:Uqt2EfrMj2NV8UGoN1f1Y3m0NpUVCsUdrNCdet+8LvU=
github.com/bradleyjkemp/cupaloy/v2 v2.8.0 h1:any4BmKE+jGIaMpnU8YgH/I2LPiLBufr6oMMlVBbn9M=
github.com/bradleyjkemp/cupaloy/v2 v2.8.0/go.mod h1:bm7JXdkRd4BHJk9HpwqAI8BoAY1lps46Enkdqw6aRX0=
github.com/breml/bidichk v0.3.3 h1:WSM67ztRusf1sMoqH6/c4OBCUlRVTKq+CbSeo0R17sE=
github.com/breml/bidichk v0.3.3/go.mod h1:ISbsut8OnjB367j5NseXEGGgO/th206dVa427kR8YTE=
github.com/breml/errchkjson v0.4.1 h1:keFSS8D7A2T0haP9kzZTi7o26r7kE3vymjZNeNDRDwg=
github.com/breml/errchkjson v0.4.1/go.mod h1:a23OvR6Qvcl7DG/Z4o0el6BRAjKnaReoPQFciAl9U3s=
-github.com/butuzov/ireturn v0.4.1 h1:vWb3NO4t77iku/sjCQ/2pHTQeOmxEhjIriJqRLg1Y+I=
-github.com/butuzov/ireturn v0.4.1/go.mod h1:q+DXKzTDV5guNuXLnIab9fKXizTn2miZHLhxH7V/GB4=
-github.com/butuzov/mirror v1.3.3 h1:v0RsWBhfFc1RQqE/f3sHpSttKDtodFn0gFmtYyD4/hA=
-github.com/butuzov/mirror v1.3.3/go.mod h1:h9BzzwYnTiHO0GzgvaTqIg7VSsOUhdIv51cHFFBmX1w=
+github.com/butuzov/ireturn v0.4.0 h1:+s76bF/PfeKEdbG8b54aCocxXmi0wvYdOVsWxVO7n8E=
+github.com/butuzov/ireturn v0.4.0/go.mod h1:ghI0FrCmap8pDWZwfPisFD1vEc56VKH4NpQUxDHta70=
+github.com/butuzov/mirror v1.3.0 h1:HdWCXzmwlQHdVhwvsfBb2Au0r3HyINry3bDWLYXiKoc=
+github.com/butuzov/mirror v1.3.0/go.mod h1:AEij0Z8YMALaq4yQj9CPPVYOyJQyiexpQEQgihajRfI=
github.com/catenacyber/perfsprint v0.10.1 h1:u7Riei30bk46XsG8nknMhKLXG9BcXz3+3tl/WpKm0PQ=
github.com/catenacyber/perfsprint v0.10.1/go.mod h1:DJTGsi/Zufpuus6XPGJyKOTMELe347o6akPvWG9Zcsc=
github.com/ccojocar/zxcvbn-go v1.0.4 h1:FWnCIRMXPj43ukfX000kvBZvV6raSxakYr1nzyNrUcc=
@@ -186,24 +182,18 @@ github.com/cespare/xxhash/v2 v2.3.0 h1:UL815xU9SqsFlibzuggzjXhog7bL6oX9BbNZnL2UF
github.com/cespare/xxhash/v2 v2.3.0/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs=
github.com/charithe/durationcheck v0.0.11 h1:g1/EX1eIiKS57NTWsYtHDZ/APfeXKhye1DidBcABctk=
github.com/charithe/durationcheck v0.0.11/go.mod h1:x5iZaixRNl8ctbM+3B2RrPG5t856TxRyVQEnbIEM2X4=
-github.com/charmbracelet/colorprofile v0.4.3 h1:QPa1IWkYI+AOB+fE+mg/5/4HRMZcaXex9t5KX76i20Q=
-github.com/charmbracelet/colorprofile v0.4.3/go.mod h1:/zT4BhpD5aGFpqQQqw7a+VtHCzu+zrQtt1zhMt9mR4Q=
-github.com/charmbracelet/ultraviolet v0.0.0-20260811164956-006e29f97886 h1:rdnVWKgJpTVXKuKuJyxDJ+NFJdUaUqGvyGy61OcvlbA=
-github.com/charmbracelet/ultraviolet v0.0.0-20260811164956-006e29f97886/go.mod h1:nAw0d9PhFp1qdzi2xhQU5YOu5sVpDIHWlaW2Uz/bCro=
-github.com/charmbracelet/x/ansi v0.11.8 h1:JMFwp0CgDC2+jcOB162HH5k7I3FVbgFSMMYg7dSPBQQ=
-github.com/charmbracelet/x/ansi v0.11.8/go.mod h1:ZNN+3mXny/516oTQPLMPIBeSINvNJJQ8uQXDgbeJxY0=
-github.com/charmbracelet/x/term v0.2.2 h1:xVRT/S2ZcKdhhOuSP4t5cLi5o+JxklsoEObBSgfgZRk=
-github.com/charmbracelet/x/term v0.2.2/go.mod h1:kF8CY5RddLWrsgVwpw4kAa6TESp6EB5y3uxGLeCqzAI=
-github.com/charmbracelet/x/termios v0.1.1 h1:o3Q2bT8eqzGnGPOYheoYS8eEleT5ZVNYNy8JawjaNZY=
-github.com/charmbracelet/x/termios v0.1.1/go.mod h1:rB7fnv1TgOPOyyKRJ9o+AsTU/vK5WHJ2ivHeut/Pcwo=
-github.com/charmbracelet/x/windows v0.2.2 h1:IofanmuvaxnKHuV04sC0eBy/smG6kIKrWG2/jYn2GuM=
-github.com/charmbracelet/x/windows v0.2.2/go.mod h1:/8XtdKZzedat74NQFn0NGlGL4soHB0YQZrETF96h75k=
+github.com/charmbracelet/colorprofile v0.2.3-0.20250311203215-f60798e515dc h1:4pZI35227imm7yK2bGPcfpFEmuY1gc2YSTShr4iJBfs=
+github.com/charmbracelet/colorprofile v0.2.3-0.20250311203215-f60798e515dc/go.mod h1:X4/0JoqgTIPSFcRA/P6INZzIuyqdFY5rm8tb41s9okk=
+github.com/charmbracelet/lipgloss v1.1.0 h1:vYXsiLHVkK7fp74RkV7b2kq9+zDLoEU4MZoFqR/noCY=
+github.com/charmbracelet/lipgloss v1.1.0/go.mod h1:/6Q8FR2o+kj8rz4Dq0zQc3vYf7X+B0binUUBwA0aL30=
+github.com/charmbracelet/x/ansi v0.10.1 h1:rL3Koar5XvX0pHGfovN03f5cxLbCF2YvLeyz7D2jVDQ=
+github.com/charmbracelet/x/ansi v0.10.1/go.mod h1:3RQDQ6lDnROptfpWuUVIUG64bD2g2BgntdxH0Ya5TeE=
+github.com/charmbracelet/x/cellbuf v0.0.13-0.20250311204145-2c3ea96c31dd h1:vy0GVL4jeHEwG5YOXDmi86oYw2yuYUGqz6a8sLwg0X8=
+github.com/charmbracelet/x/cellbuf v0.0.13-0.20250311204145-2c3ea96c31dd/go.mod h1:xe0nKWGd3eJgtqZRaN9RjMtK7xUYchjzPr7q6kcvCCs=
+github.com/charmbracelet/x/term v0.2.1 h1:AQeHeLZ1OqSXhrAWpYUtZyX1T3zVxfpZuEQMIQaGIAQ=
+github.com/charmbracelet/x/term v0.2.1/go.mod h1:oQ4enTYFV7QN4m0i9mzHrViD7TQKvNEEkHUMCmsxdUg=
github.com/ckaznocha/intrange v0.3.1 h1:j1onQyXvHUsPWujDH6WIjhyH26gkRt/txNlV7LspvJs=
github.com/ckaznocha/intrange v0.3.1/go.mod h1:QVepyz1AkUoFQkpEqksSYpNpUo3c5W7nWh/s6SHIJJk=
-github.com/clipperhouse/displaywidth v0.11.0 h1:lBc6kY44VFw+TDx4I8opi/EtL9m20WSEFgwIwO+UVM8=
-github.com/clipperhouse/displaywidth v0.11.0/go.mod h1:bkrFNkf81G8HyVqmKGxsPufD3JhNl3dSqnGhOoSD/o0=
-github.com/clipperhouse/uax29/v2 v2.7.0 h1:+gs4oBZ2gPfVrKPthwbMzWZDaAFPGYK72F0NJv2v7Vk=
-github.com/clipperhouse/uax29/v2 v2.7.0/go.mod h1:EFJ2TJMRUaplDxHKj1qAEhCtQPW2tJSwu5BF98AuoVM=
github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2 h1:aBangftG7EVZoUb69Os8IaYg++6uMOdKK83QtkkvJik=
github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2/go.mod h1:qwXFYgsP6T7XnJtbKlf1HP8AjxZZyzxMmc+Lq5GjlU4=
github.com/cpuguy83/go-md2man/v2 v2.0.0-20190314233015-f79a8a8ca69d/go.mod h1:maD7wRr/U5Z6m/iR4s+kqSMx2CaBsrgA7czyZG/E6dU=
@@ -219,19 +209,16 @@ github.com/dave/dst v0.27.3/go.mod h1:jHh6EOibnHgcUW3WjKHisiooEkYwqpHLBSX1iOBhEy
github.com/dave/jennifer v1.7.1 h1:B4jJJDHelWcDhlRQxWeo0Npa/pYKBLrirAQoTN45txo=
github.com/dave/jennifer v1.7.1/go.mod h1:nXbxhEmQfOZhWml3D1cDK5M1FLnMSozpbFN/m3RmGZc=
github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
+github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
-github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc h1:U9qPSI2PIWSS1VwoXQT9A3Wy9MM3WgvqSxFWenqJduM=
-github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
github.com/denis-tingaikin/go-header v0.5.0 h1:SRdnP5ZKvcO9KKRP1KJrhFR3RrlGuD+42t4429eC9k8=
github.com/denis-tingaikin/go-header v0.5.0/go.mod h1:mMenU5bWrok6Wl2UsZjy+1okegmwQ3UgWl4V1D8gjlY=
-github.com/dlclark/regexp2 v1.12.0 h1:0j4c5qQmnC6XOWNjP3PIXURXN2gWx76rd3KvgdPkCz8=
-github.com/dlclark/regexp2 v1.12.0/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8=
-github.com/dlclark/regexp2/v2 v2.2.1 h1:mf4KkFUj0gJuarK8P+LgiS+Lit7m9N1yAwEfPbee7R0=
-github.com/dlclark/regexp2/v2 v2.2.1/go.mod h1:avUrQvPaLz2DrFNHJF0taWAFFX2C1GMSSoeiqFjcBmU=
+github.com/dlclark/regexp2 v1.11.5 h1:Q/sSnsKerHeCkc/jSTNq1oCm7KiVgUMZRDUoRu0JQZQ=
+github.com/dlclark/regexp2 v1.11.5/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8=
github.com/dustin/go-humanize v1.0.1 h1:GzkhY7T5VNhEkwH0PVJgjz+fX1rhBrR7pRT3mDkpeCY=
github.com/dustin/go-humanize v1.0.1/go.mod h1:Mu1zIs6XwVuF/gI1OepvI0qD18qycQx+mFykh5fBlto=
-github.com/ecosyste-ms/ecosystems-go v0.4.0 h1:5A+zF+XWT8sYYYjlc2/tI1SmiDGzbHLyT9CapVc5dGA=
-github.com/ecosyste-ms/ecosystems-go v0.4.0/go.mod h1:FVswCrp3DQkur1HjVqfDF/gYrDSEmiFflntcB1G0DbA=
+github.com/ecosyste-ms/ecosystems-go v0.2.0 h1:Nhpg54C+St8Sd/mf8bNJmQqx35ZgHw33TfFoxaXMQI8=
+github.com/ecosyste-ms/ecosystems-go v0.2.0/go.mod h1:CCdzT1iAZirbEZAbFSnWpK88eKKaIWex7gjtZ0UudXA=
github.com/envoyproxy/go-control-plane v0.14.0 h1:hbG2kr4RuFj222B6+7T83thSPqLjwBIfQawTkC++2HA=
github.com/envoyproxy/go-control-plane/envoy v1.37.0 h1:u3riX6BoYRfF4Dr7dwSOroNfdSbEPe9Yyl09/B6wBrQ=
github.com/envoyproxy/go-control-plane/envoy v1.37.0/go.mod h1:DReE9MMrmecPy+YvQOAOHNYMALuowAnbjjEMkkWOi6A=
@@ -241,52 +228,48 @@ github.com/ettle/strcase v0.2.0 h1:fGNiVF21fHXpX1niBgk0aROov1LagYsOwV/xqKDKR/Q=
github.com/ettle/strcase v0.2.0/go.mod h1:DajmHElDSaX76ITe3/VHVyMin4LWSJN5Z909Wp+ED1A=
github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a h1:yDWHCSQ40h88yih2JAcL6Ls/kVkSE8GFACTGVnMPruw=
github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a/go.mod h1:7Ga40egUymuWXxAe151lTNnCv97MddSOVsjpPPkityA=
-github.com/fatih/color v1.19.0 h1:Zp3PiM21/9Ld6FzSKyL5c/BULoe/ONr9KlbYVOfG8+w=
-github.com/fatih/color v1.19.0/go.mod h1:zNk67I0ZUT1bEGsSGyCZYZNrHuTkJJB+r6Q9VuMi0LE=
+github.com/fatih/color v1.18.0 h1:S8gINlzdQ840/4pfAwic/ZE0djQEH3wM94VfqLTZcOM=
+github.com/fatih/color v1.18.0/go.mod h1:4FelSpRwEGDpQ12mAdzqdOukCy4u8WUtOY6lkT/6HfU=
github.com/fatih/structtag v1.2.0 h1:/OdNE99OxoI/PqaW/SuSK9uxxT3f/tcSZgon/ssNSx4=
github.com/fatih/structtag v1.2.0/go.mod h1:mBJUNpUnHmRKrKlQQlmCrh5PuhftFbNv8Ys4/aAZl94=
-github.com/felixge/httpsnoop v1.1.0 h1:3YtUj32ZZkqZtt3sZZsClsymw/QDuVfpNhoA31zeORc=
-github.com/felixge/httpsnoop v1.1.0/go.mod h1:Zqxgdd+1Rkcz8euOqdr7lqgCRJztwr5hp9vDSi5UZCE=
-github.com/firefart/nonamedreturns v1.0.8 h1:iB32Dl17zJl1zlVEj/WlUWgx0HiRyQ85OUw1WHa4/II=
-github.com/firefart/nonamedreturns v1.0.8/go.mod h1:vxFNvm5AfP/8rgAKFzYmnqx0yp1HjrYsErZ9pHPTznA=
+github.com/felixge/httpsnoop v1.0.4 h1:NFTV2Zj1bL4mc9sqWACXbQFVBBg2W3GPvqp8/ESS2Wg=
+github.com/felixge/httpsnoop v1.0.4/go.mod h1:m8KPJKqk1gH5J9DgRY2ASl2lWCfGKXixSwevea8zH2U=
+github.com/firefart/nonamedreturns v1.0.6 h1:vmiBcKV/3EqKY3ZiPxCINmpS431OcE1S47AQUwhrg8E=
+github.com/firefart/nonamedreturns v1.0.6/go.mod h1:R8NisJnSIpvPWheCq0mNRXJok6D8h7fagJTF8EMEwCo=
github.com/frankban/quicktest v1.14.3 h1:FJKSZTDHjyhriyC81FLQ0LY93eSai0ZyR/ZIkd3ZUKE=
github.com/frankban/quicktest v1.14.3/go.mod h1:mgiwOwqx65TmIk1wJ6Q7wvnVMocbUorkibMOrVTHZps=
github.com/fsnotify/fsnotify v1.9.0 h1:2Ml+OJNzbYCTzsxtv8vKSFD9PbJjmhYF14k/jKC7S9k=
github.com/fsnotify/fsnotify v1.9.0/go.mod h1:8jBTzvmWwFyi3Pb8djgCCO5IBqzKJ/Jwo8TRcHyHii0=
github.com/fzipp/gocyclo v0.6.0 h1:lsblElZG7d3ALtGMx9fmxeTKZaLLpU8mET09yN4BBLo=
github.com/fzipp/gocyclo v0.6.0/go.mod h1:rXPyn8fnlpa0R2csP/31uerbiVBugk5whMdlyaLkLoA=
-github.com/ghostiam/protogetter v0.3.21 h1:EeWTGvL/Eyosp653hiWb6Byx4b69iJC4/E+za7vQHoI=
-github.com/ghostiam/protogetter v0.3.21/go.mod h1:iAKSpyoHwYzay+OpjoWgwzRtPFthEfuUvmlomTThck0=
-github.com/git-pkgs/archives v0.5.1 h1:qwu/vsoerQZF1iysRtfcxpy1KIUSJJSpXJ5JNxzNoQw=
-github.com/git-pkgs/archives v0.5.1/go.mod h1:AKpkxnts49R9uAt1mL2ULYcHrmYujCDVu24IsFvW9so=
+github.com/ghostiam/protogetter v0.3.20 h1:oW7OPFit2FxZOpmMRPP9FffU4uUpfeE/rEdE1f+MzD0=
+github.com/ghostiam/protogetter v0.3.20/go.mod h1:FjIu5Yfs6FT391m+Fjp3fbAYJ6rkL/J6ySpZBfnODuI=
+github.com/git-pkgs/archives v0.3.0 h1:iXKyO83jEFub1PGEDlHmk2tQ7XeV5LySTc0sEkH3x78=
+github.com/git-pkgs/archives v0.3.0/go.mod h1:LTJ1iQVFA7otizWMOyiI82NYVmyBWAPRzwu/e30rcXU=
github.com/git-pkgs/cooldown v0.1.1 h1:9OqqzCB8gANz/y44SmqGD0Jp8Qtu81D1sCbKl6Ehg7w=
github.com/git-pkgs/cooldown v0.1.1/go.mod h1:v7APuK/UouTiu8mWQZbdDmj7DfxxkGUeuhjaRB5gv9E=
-github.com/git-pkgs/enrichment v0.6.5 h1:U0SPzWVGoK4R8TwojCTASBRTEV+QSs0IitdLmzI/g/k=
-github.com/git-pkgs/enrichment v0.6.5/go.mod h1:Vt2PLMvWPOio9DLyC8Gdhh1yxsHwcRcG+L2Kkc9+kak=
-github.com/git-pkgs/integrity v0.1.1 h1:nHQ7SktOiGM1dOb5BFnkdtttG/6FCgE6r5ru6QnsGts=
-github.com/git-pkgs/integrity v0.1.1/go.mod h1:hxu24lcd230377hCF28JQW7sGcCbuNLqo/0ULeb+F1Q=
-github.com/git-pkgs/magic v0.2.0 h1:c7HqVxnP8c88EaVMH0/KraDFVTcmiXckRiSvNZEnvMQ=
-github.com/git-pkgs/magic v0.2.0/go.mod h1:3ndidt+yvFaI1M0aEkkzkOlFnLPkeVQASIUojazcxCI=
+github.com/git-pkgs/enrichment v0.4.1 h1:A8BKs0XwvpF1sF5qviZy4fkJAe18qB9OgpbRnmwnT34=
+github.com/git-pkgs/enrichment v0.4.1/go.mod h1:stHqZUitV9ZkwACqHzBysLMSe6T4QZn81hxTdSroNhM=
github.com/git-pkgs/packageurl-go v0.3.1 h1:WM3RBABQZLaRBxgKyYughc3cVBE8KyQxbSC6Jt5ak7M=
github.com/git-pkgs/packageurl-go v0.3.1/go.mod h1:rcIxiG37BlQLB6FZfgdj9Fm7yjhRQd3l+5o7J0QPAk4=
github.com/git-pkgs/pom v0.1.5 h1:TGT8Az2OMxGWsXnSagtUMGzZm7Oax8HrSCteA+mi0qY=
github.com/git-pkgs/pom v0.1.5/go.mod h1:ufdMBe1lKzqOeP9IUb9NPZ458xKV8E8NvuyBMxOfwIk=
-github.com/git-pkgs/purl v0.1.17 h1:oRSd8tqllTLl74Wa4WnuqU500hXd9OdUnImOEswQUVE=
-github.com/git-pkgs/purl v0.1.17/go.mod h1:7u7ora8tQdrkS7Auclr5v8dCJdjN4ej6AbrvYZi2b7k=
-github.com/git-pkgs/registries v0.8.1 h1:Yf2FFdARQ1HcdtZfWBYa5OZFwZHzhFYStiz7qbTDDUU=
-github.com/git-pkgs/registries v0.8.1/go.mod h1:5dc3V7rOhAI5755L/bDtjtYV4D5XV4J/4ZtyIXSEs0U=
-github.com/git-pkgs/spdx v0.3.1 h1:58JPY5X9pYpXvnzzZIgehItlBykeOOw52pNc4OBcS+c=
-github.com/git-pkgs/spdx v0.3.1/go.mod h1:cqRoZcvl530s/W+oGNvwjt4ODN8T1W6D/20MUZEFdto=
-github.com/git-pkgs/vers v0.3.1 h1:jy/ht2wIRJI5zQrccm6GTeYr+hGFwe2z8LV1HOr4Wco=
-github.com/git-pkgs/vers v0.3.1/go.mod h1:biTbSQK1qdbrsxDEKnqe3Jzclxz8vW6uDcwKjfUGcOo=
-github.com/git-pkgs/vulns v0.2.2 h1:4z6fE/Yqf34PTVSv1WsN09hMznjPa9t+1fHDIywZI3g=
-github.com/git-pkgs/vulns v0.2.2/go.mod h1:cQkJfI2WyW53Seg55Su0gjOSFE5ImSZ0XbHXeb33gfs=
+github.com/git-pkgs/purl v0.1.13 h1:at8BU6vnP5oonHFHAPA064BzgRqij+SZcOUDgNT2DC8=
+github.com/git-pkgs/purl v0.1.13/go.mod h1:8oCcdcYZA/e1B33e7Ylju6azboTKjdqf3ybcbQj6I/o=
+github.com/git-pkgs/registries v0.6.2 h1:26G5zW6Q7x1CSfNkaEqEjRMJiA4JwfdKOCJ7Qm+u0a8=
+github.com/git-pkgs/registries v0.6.2/go.mod h1:GR0Bu6nC3NQe6f7lfDoEVqAnoQkMocf4M98B12a7B3E=
+github.com/git-pkgs/spdx v0.1.4 h1:eQ0waEV3uUeItpWAOvdN1K1rL9hTgsU7fF74r1mDXMs=
+github.com/git-pkgs/spdx v0.1.4/go.mod h1:cqRoZcvl530s/W+oGNvwjt4ODN8T1W6D/20MUZEFdto=
+github.com/git-pkgs/vers v0.2.6 h1:IelZd7BP/JhzTloUTDY67nehUgoYva3g9viqAMCHJg8=
+github.com/git-pkgs/vers v0.2.6/go.mod h1:biTbSQK1qdbrsxDEKnqe3Jzclxz8vW6uDcwKjfUGcOo=
+github.com/git-pkgs/vulns v0.1.6 h1:8RRSgdlxp4JMU0Zykr63XTOMo5CyZKwt/PwaQxrx9Yg=
+github.com/git-pkgs/vulns v0.1.6/go.mod h1:TsZC4MjoCkKJslgmbcmRCnytwnFcjESC2N8b0a2xDWc=
github.com/github/go-spdx/v2 v2.7.0 h1:GzfXx4wFdlilARxmFRXW/mgUy3A4vSqZocCMFV6XFdQ=
github.com/github/go-spdx/v2 v2.7.0/go.mod h1:Ftc45YYG1WzpzwEPKRVm9Jv8vDqOrN4gWoCkK+bHer0=
-github.com/go-chi/chi/v5 v5.3.1 h1:3j4HZLGZQ3JpMCrPJF/Jl3mYJfWLKBfNJ6quurUGCf8=
-github.com/go-chi/chi/v5 v5.3.1/go.mod h1:R+tYY2hNuVUUjxoPtqUdgBqevM9s9njzkTLutVsOCto=
-github.com/go-critic/go-critic v0.14.4 h1:dSX4C3pWSeuMVxvQh6yG8U0ReSf3YOmKi4nwX5q7n/8=
-github.com/go-critic/go-critic v0.14.4/go.mod h1:xwntfW6SYAd7h1OqDzmN6hBX/JxsEKl5up/Y2bsxgVQ=
+github.com/go-chi/chi/v5 v5.3.0 h1:halUjDxhshgXHMrao5bB8eNBXo/rnzwr8m5m36glehM=
+github.com/go-chi/chi/v5 v5.3.0/go.mod h1:R+tYY2hNuVUUjxoPtqUdgBqevM9s9njzkTLutVsOCto=
+github.com/go-critic/go-critic v0.14.3 h1:5R1qH2iFeo4I/RJU8vTezdqs08Egi4u5p6vOESA0pog=
+github.com/go-critic/go-critic v0.14.3/go.mod h1:xwntfW6SYAd7h1OqDzmN6hBX/JxsEKl5up/Y2bsxgVQ=
github.com/go-jose/go-jose/v4 v4.1.4 h1:moDMcTHmvE6Groj34emNPLs/qtYXRVcd6S7NHbHz3kA=
github.com/go-jose/go-jose/v4 v4.1.4/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08=
github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=
@@ -304,8 +287,8 @@ github.com/go-openapi/spec v0.20.4/go.mod h1:faYFR1CvsJZ0mNsmsphTMSoRrNV3TEDoAM7
github.com/go-openapi/swag v0.19.5/go.mod h1:POnQmlKehdgb5mhVOsnJFsivZCEZ/vjK9gh66Z9tfKk=
github.com/go-openapi/swag v0.19.15 h1:D2NRCBzS9/pEY3gP9Nl8aDqGUcPFrwG2p+CNFrLyrCM=
github.com/go-openapi/swag v0.19.15/go.mod h1:QYRuS/SOXUCsnplDa677K7+DxSOj6IPNl/eQntq43wQ=
-github.com/go-quicktest/qt v1.102.0 h1:HSQxCeh5YZH3EL3W39ixjtyaEhcWSXQHtHnMBzSs474=
-github.com/go-quicktest/qt v1.102.0/go.mod h1:p4lGIVX+8Wa6ZPNDvqcxq36XpUDLh42FLetFU7odllI=
+github.com/go-quicktest/qt v1.101.0 h1:O1K29Txy5P2OK0dGo59b7b0LR6wKfIhttaAhHUyn7eI=
+github.com/go-quicktest/qt v1.101.0/go.mod h1:14Bz/f7NwaXPtdYEgzsx46kqSxVwTbzVZsDC26tQJow=
github.com/go-sql-driver/mysql v1.8.1/go.mod h1:wEBSXgmK//2ZFJyE+qWnIsVGmvmEKlqwuVSjsCm7DZg=
github.com/go-sql-driver/mysql v1.9.3 h1:U/N249h2WzJ3Ukj8SowVFjdtZKfu9vlLZxjPXV1aweo=
github.com/go-sql-driver/mysql v1.9.3/go.mod h1:qn46aNg1333BRMNU69Lq93t8du/dwxI64Gl8i5p1WMU=
@@ -346,14 +329,14 @@ github.com/golang/protobuf v1.5.4 h1:i7eJL8qZTpSEXOPTxNKhASYpMn+8e5Q6AdndVa1dWek
github.com/golang/protobuf v1.5.4/go.mod h1:lnTiLA8Wa4RWRcIUkrtSVa5nRhsEGBg48fD6rSs7xps=
github.com/golangci/asciicheck v0.5.0 h1:jczN/BorERZwK8oiFBOGvlGPknhvq0bjnysTj4nUfo0=
github.com/golangci/asciicheck v0.5.0/go.mod h1:5RMNAInbNFw2krqN6ibBxN/zfRFa9S6tA1nPdM0l8qQ=
-github.com/golangci/dupl v0.0.0-20260401084720-c99c5cf5c202 h1:CbTB8KpqnViI6lIXxp03Oclc4VFHi3K4BWC1TacsZ+A=
-github.com/golangci/dupl v0.0.0-20260401084720-c99c5cf5c202/go.mod h1:NUw9Zr2Sy7+HxzdjIULge71wI6yEg1lWQr7Evcu8K0E=
+github.com/golangci/dupl v0.0.0-20250308024227-f665c8d69b32 h1:WUvBfQL6EW/40l6OmeSBYQJNSif4O11+bmWEz+C7FYw=
+github.com/golangci/dupl v0.0.0-20250308024227-f665c8d69b32/go.mod h1:NUw9Zr2Sy7+HxzdjIULge71wI6yEg1lWQr7Evcu8K0E=
github.com/golangci/go-printf-func-name v0.1.1 h1:hIYTFJqAGp1iwoIfsNTpoq1xZAarogrvjO9AfiW3B4U=
github.com/golangci/go-printf-func-name v0.1.1/go.mod h1:Es64MpWEZbh0UBtTAICOZiB+miW53w/K9Or/4QogJss=
-github.com/golangci/gofmt v0.0.0-20260820135601-e84e05053792 h1:WL8YKrt3UbOBqSRU7GpP5BTtQTMWtVtj+mfPijgZeIg=
-github.com/golangci/gofmt v0.0.0-20260820135601-e84e05053792/go.mod h1:te5hX0dW4C5r6YbXs+6ysNr8Q5UTmdIqGbb+mlFiYmA=
-github.com/golangci/golangci-lint/v2 v2.13.1 h1:RuM4OcluM4xFQcGuRE6R7jA33pqxK/W1EsBxpugdZjg=
-github.com/golangci/golangci-lint/v2 v2.13.1/go.mod h1:HwX7mDzqHbcSxlhrTygjX1GJbAfQ3sJAqOx41qQlhDE=
+github.com/golangci/gofmt v0.0.0-20250106114630-d62b90e6713d h1:viFft9sS/dxoYY0aiOTsLKO2aZQAPT4nlQCsimGcSGE=
+github.com/golangci/gofmt v0.0.0-20250106114630-d62b90e6713d/go.mod h1:ivJ9QDg0XucIkmwhzCDsqcnxxlDStoTl89jDMIoNxKY=
+github.com/golangci/golangci-lint/v2 v2.10.1 h1:flhw5Px6ojbLyEFzXvJn5B2HEdkkRlkhE1SnmCbQBiE=
+github.com/golangci/golangci-lint/v2 v2.10.1/go.mod h1:dBsrOk6zj0vDhlTv+IiJGqkDokR24IVTS7W3EVfPTQY=
github.com/golangci/golines v0.15.0 h1:Qnph25g8Y1c5fdo1X7GaRDGgnMHgnxh4Gk4VfPTtRx0=
github.com/golangci/golines v0.15.0/go.mod h1:AZjXd23tbHMpowhtnGlj9KCNsysj72aeZVVHnVcZx10=
github.com/golangci/misspell v0.8.0 h1:qvxQhiE2/5z+BVRo1kwYA8yGz+lOlu5Jfvtx2b04Jbg=
@@ -362,8 +345,6 @@ github.com/golangci/plugin-module-register v0.1.2 h1:e5WM6PO6NIAEcij3B053CohVp3H
github.com/golangci/plugin-module-register v0.1.2/go.mod h1:1+QGTsKBvAIvPvoY/os+G5eoqxWn70HYDm2uvUyGuVw=
github.com/golangci/revgrep v0.8.0 h1:EZBctwbVd0aMeRnNUsFogoyayvKHyxlV3CdUA46FX2s=
github.com/golangci/revgrep v0.8.0/go.mod h1:U4R/s9dlXZsg8uJmaR1GrloUr14D7qDl8gi2iPXJH8k=
-github.com/golangci/rowserrcheck v0.0.0-20260419091836-c5f79b8a11ba h1:lqtcnSMDuuJdu/LrKWi5RJzpSNLOJXYe/nzQutTI5kg=
-github.com/golangci/rowserrcheck v0.0.0-20260419091836-c5f79b8a11ba/go.mod h1:sCBNcpRmhJCtbFGz49+IM3ETTFf7QdJ30AeYCd43NKk=
github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e h1:ai0EfmVYE2bRA5htgAG9r7s3tHsfjIhN98WshBTJ9jM=
github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e/go.mod h1:Vrn4B5oR9qRwM+f54koyeH3yzphlecwERs0el27Fr/s=
github.com/golangci/unconvert v0.0.0-20250410112200-a129a6e6413e h1:gD6P7NEo7Eqtt0ssnqSJNNndxe69DOQ24A5h7+i3KpM=
@@ -379,18 +360,18 @@ github.com/google/go-replayers/httpreplay v1.2.0 h1:VM1wEyyjaoU53BwrOnaf9VhAyQQE
github.com/google/go-replayers/httpreplay v1.2.0/go.mod h1:WahEFFZZ7a1P4VM1qEeHy+tME4bwyqPcwWbNlUI1Mcg=
github.com/google/martian/v3 v3.3.3 h1:DIhPTQrbPkgs2yJYdXU/eNACCG5DVQjySNRNlflZ9Fc=
github.com/google/martian/v3 v3.3.3/go.mod h1:iEPrYcgCF7jA9OtScMFQyAlZZ4YXTKEtJ1E6RWzmBA0=
-github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3 h1:LMLX+LgTNWpfvCBdFebv6EsYotImrt/Ppc5cXIriCSo=
-github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3/go.mod h1:jl5iWTm0/hd5PjEYEOuwAJ57L/CibdZfrqZ5XA5GrCk=
+github.com/google/pprof v0.0.0-20260115054156-294ebfa9ad83 h1:z2ogiKUYzX5Is6zr/vP9vJGqPwcdqsWjOt+V8J7+bTc=
+github.com/google/pprof v0.0.0-20260115054156-294ebfa9ad83/go.mod h1:MxpfABSjhmINe3F1It9d+8exIHFvUqtLIRCdOGNXqiI=
github.com/google/s2a-go v0.1.9 h1:LGD7gtMgezd8a/Xak7mEWL0PjoTQFvpRudN895yqKW0=
github.com/google/s2a-go v0.1.9/go.mod h1:YA0Ei2ZQL3acow2O62kdp9UlnvMmU7kA6Eutn0dXayM=
github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0=
github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
github.com/google/wire v0.7.0 h1:JxUKI6+CVBgCO2WToKy/nQk0sS+amI9z9EjVmdaocj4=
github.com/google/wire v0.7.0/go.mod h1:n6YbUQD9cPKTnHXEBN2DXlOp/mVADhVErcMFb0v3J18=
-github.com/googleapis/enterprise-certificate-proxy v0.3.18 h1:hvVi34VucdrV1IIsiWuqYM8kutw/92MxNEFxCJZEh0k=
-github.com/googleapis/enterprise-certificate-proxy v0.3.18/go.mod h1:rSEsBUemEBZEexP2y6jPp16LUmUbjmSbcPMQizR0o4k=
-github.com/googleapis/gax-go/v2 v2.23.0 h1:Tchl7qkvE7Ip3y+ztvNufYFvkfqTe7NfLTYGIdJRLuE=
-github.com/googleapis/gax-go/v2 v2.23.0/go.mod h1:rBQKOVJCdb8IFEzg+FCwlt1LP/xMDGuqUXhUG+XMXEg=
+github.com/googleapis/enterprise-certificate-proxy v0.3.14 h1:yh8ncqsbUY4shRD5dA6RlzjJaT4hi3kII+zYw8wmLb8=
+github.com/googleapis/enterprise-certificate-proxy v0.3.14/go.mod h1:vqVt9yG9480NtzREnTlmGSBmFrA+bzb0yl0TxoBQXOg=
+github.com/googleapis/gax-go/v2 v2.19.0 h1:fYQaUOiGwll0cGj7jmHT/0nPlcrZDFPrZRhTsoCr8hE=
+github.com/googleapis/gax-go/v2 v2.19.0/go.mod h1:w2ROXVdfGEVFXzmlciUU4EdjHgWvB5h2n6x/8XSTTJA=
github.com/gordonklaus/ineffassign v0.2.0 h1:Uths4KnmwxNJNzq87fwQQDDnbNb7De00VOk9Nu0TySs=
github.com/gordonklaus/ineffassign v0.2.0/go.mod h1:TIpymnagPSexySzs7F9FnO1XFTy8IT3a59vmZp5Y9Lw=
github.com/gostaticanalysis/analysisutil v0.7.1 h1:ZMCjoue3DtDWQ5WyU16YbjbQEQ3VuzwxALrpYd+HeKk=
@@ -410,8 +391,8 @@ github.com/hashicorp/go-immutable-radix/v2 v2.1.0/go.mod h1:hgdqLXA4f6NIjRVisM1T
github.com/hashicorp/go-uuid v1.0.3 h1:2gKiV6YVmrJ1i2CKKa9obLvRieoRGviZFL26PcT/Co8=
github.com/hashicorp/go-uuid v1.0.3/go.mod h1:6SBZvOh/SIDV7/2o3Jml5SYk/TvGqwFJ/bN7x4byOro=
github.com/hashicorp/go-version v1.2.1/go.mod h1:fltr4n8CU8Ke44wwGCBoEymUuxUHl09ZGVZPK5anwXA=
-github.com/hashicorp/go-version v1.9.0 h1:CeOIz6k+LoN3qX9Z0tyQrPtiB1DFYRPfCIBtaXPSCnA=
-github.com/hashicorp/go-version v1.9.0/go.mod h1:fltr4n8CU8Ke44wwGCBoEymUuxUHl09ZGVZPK5anwXA=
+github.com/hashicorp/go-version v1.8.0 h1:KAkNb1HAiZd1ukkxDFGmokVZe1Xy9HG6NUp+bPle2i4=
+github.com/hashicorp/go-version v1.8.0/go.mod h1:fltr4n8CU8Ke44wwGCBoEymUuxUHl09ZGVZPK5anwXA=
github.com/hashicorp/golang-lru/v2 v2.0.7 h1:a+bsQ5rvGLjzHuww6tVxozPZFVghXaHOwFs4luLUK2k=
github.com/hashicorp/golang-lru/v2 v2.0.7/go.mod h1:QeFd9opnmA6QUJc5vARoKUSoFhyfM2/ZepoAG6RGpeM=
github.com/hashicorp/hcl v1.0.0 h1:0Anlzjpi4vEasTeNFn2mLJgTSwt0+6sfsiTG8qcWGx4=
@@ -420,8 +401,10 @@ github.com/hexops/gotextdiff v1.0.3 h1:gitA9+qJrrTCsiCl7+kh75nPqQt1cx4ZkudSTLoUq
github.com/hexops/gotextdiff v1.0.3/go.mod h1:pSWU5MAI3yDq+fZBTazCSJysOMbxWL1BSow5/V2vxeg=
github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2s0bqwp9tc8=
github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw=
-github.com/jgautheron/goconst v1.11.0 h1:KgN90z5qXt5f0Uzf3cWXev3hfMMFUyNeKdpkSBRvLDk=
-github.com/jgautheron/goconst v1.11.0/go.mod h1:0p+wv1lFOiUr0IlNNT1nrm6+8DB8u2sU6KHGzFRXHDc=
+github.com/jgautheron/goconst v1.8.2 h1:y0XF7X8CikZ93fSNT6WBTb/NElBu9IjaY7CCYQrCMX4=
+github.com/jgautheron/goconst v1.8.2/go.mod h1:A0oxgBCHy55NQn6sYpO7UdnA9p+h7cPtoOZUmvNIako=
+github.com/jingyugao/rowserrcheck v1.1.1 h1:zibz55j/MJtLsjP1OF4bSdgXxwL1b+Vn7Tjzq7gFzUs=
+github.com/jingyugao/rowserrcheck v1.1.1/go.mod h1:4yvlZSDb3IyDTUZJUmpZfm2Hwok+Dtp+nu2qOq+er9c=
github.com/jjti/go-spancheck v0.6.5 h1:lmi7pKxa37oKYIMScialXUK6hP3iY5F1gu+mLBPgYB8=
github.com/jjti/go-spancheck v0.6.5/go.mod h1:aEogkeatBrbYsyW6y5TgDfihCulDYciL1B7rG2vSsrU=
github.com/jmoiron/sqlx v1.4.0 h1:1PLqN7S1UYp5t4SrVVnt4nUVNemrDAtxlulVe+Qgm3o=
@@ -435,12 +418,12 @@ github.com/karamaru-alpha/copyloopvar v1.2.2 h1:yfNQvP9YaGQR7VaWLYcfZUlRP2eo2vhE
github.com/karamaru-alpha/copyloopvar v1.2.2/go.mod h1:oY4rGZqZ879JkJMtX3RRkcXRkmUvH0x35ykgaKgsgJY=
github.com/keybase/go-keychain v0.0.1 h1:way+bWYa6lDppZoZcgMbYsvC7GxljxrskdNInRtuthU=
github.com/keybase/go-keychain v0.0.1/go.mod h1:PdEILRW3i9D8JcdM+FmY6RwkHGnhHxXwkPPMeUgOK1k=
-github.com/kisielk/errcheck v1.20.0 h1:9rwHBNKzd4wkDWcROy3DvFGNqEPlkxBg305rvk7HabI=
-github.com/kisielk/errcheck v1.20.0/go.mod h1:O+f80MKNwX8Oor2jwgpeQ9An7uJm+hRSgT+h22knRJU=
+github.com/kisielk/errcheck v1.9.0 h1:9xt1zI9EBfcYBvdU1nVrzMzzUPUtPKs9bVSIM3TAb3M=
+github.com/kisielk/errcheck v1.9.0/go.mod h1:kQxWMMVZgIkDq7U8xtG/n2juOjbLgZtedi0D+/VL/i8=
github.com/kkHAIKE/contextcheck v1.1.6 h1:7HIyRcnyzxL9Lz06NGhiKvenXq7Zw6Q0UQu/ttjfJCE=
github.com/kkHAIKE/contextcheck v1.1.6/go.mod h1:3dDbMRNBFaq8HFXWC1JyvDSPm43CmE6IuHam8Wr0rkg=
-github.com/klauspost/compress v1.19.1 h1:VsB4HPswih7mmZ8WleSFQ75c/Ui1M4trX5oAsJnhSlk=
-github.com/klauspost/compress v1.19.1/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ=
+github.com/klauspost/compress v1.18.0 h1:c/Cqfb0r+Yi+JtIEq73FWXVkRonBlf0CRNYc8Zttxdo=
+github.com/klauspost/compress v1.18.0/go.mod h1:2Pp+KzxcywXVXMr50+X0Q/Lsb43OQHYWRCY2AiWywWQ=
github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo=
github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE=
github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk=
@@ -458,8 +441,8 @@ github.com/lasiar/canonicalheader v1.1.2 h1:vZ5uqwvDbyJCnMhmFYimgMZnJMjwljN5VGY0
github.com/lasiar/canonicalheader v1.1.2/go.mod h1:qJCeLFS0G/QlLQ506T+Fk/fWMa2VmBUiEI2cuMK4djI=
github.com/ldez/exptostd v0.4.5 h1:kv2ZGUVI6VwRfp/+bcQ6Nbx0ghFWcGIKInkG/oFn1aQ=
github.com/ldez/exptostd v0.4.5/go.mod h1:QRjHRMXJrCTIm9WxVNH6VW7oN7KrGSht69bIRwvdFsM=
-github.com/ldez/gomoddirectives v0.9.0 h1:2YV/EX7nVlWL4jySusYTzBKHuE3D2fgcRsQuMa3yIoo=
-github.com/ldez/gomoddirectives v0.9.0/go.mod h1:DdZzfm9MdXCjn2/UGYXCFfo+tzrp2Ib4iD2Q0kIJkwE=
+github.com/ldez/gomoddirectives v0.8.0 h1:JqIuTtgvFC2RdH1s357vrE23WJF2cpDCPFgA/TWDGpk=
+github.com/ldez/gomoddirectives v0.8.0/go.mod h1:jutzamvZR4XYJLr0d5Honycp4Gy6GEg2mS9+2YX3F1Q=
github.com/ldez/grignotin v0.10.1 h1:keYi9rYsgbvqAZGI1liek5c+jv9UUjbvdj3Tbn5fn4o=
github.com/ldez/grignotin v0.10.1/go.mod h1:UlDbXFCARrXbWGNGP3S5vsysNXAPhnSuBufpTEbwOas=
github.com/ldez/structtags v0.6.1 h1:bUooFLbXx41tW8SvkfwfFkkjPYvFFs59AAMgVg6DUBk=
@@ -473,8 +456,8 @@ github.com/leonklingele/grouper v1.1.2/go.mod h1:6D0M/HVkhs2yRKRFZUoGjeDy7EZTfFB
github.com/lib/pq v1.10.9/go.mod h1:AlVN5x4E4T544tWzH6hKfbfQvm3HdbOxrmggDNAPY9o=
github.com/lib/pq v1.12.3 h1:tTWxr2YLKwIvK90ZXEw8GP7UFHtcbTtty8zsI+YjrfQ=
github.com/lib/pq v1.12.3/go.mod h1:/p+8NSbOcwzAEI7wiMXFlgydTwcgTr3OSKMsD2BitpA=
-github.com/lucasb-eyer/go-colorful v1.4.1 h1:1EO+WB73+EH8EVbzlrG3KLAfEypQWVHIBqlTf+2hNss=
-github.com/lucasb-eyer/go-colorful v1.4.1/go.mod h1:R4dSotOR9KMtayYi1e77YzuveK+i7ruzyGqttikkLy0=
+github.com/lucasb-eyer/go-colorful v1.2.0 h1:1nnpGOrhyZZuNyfu1QjKiUICQ74+3FNCN69Aj6K7nkY=
+github.com/lucasb-eyer/go-colorful v1.2.0/go.mod h1:R4dSotOR9KMtayYi1e77YzuveK+i7ruzyGqttikkLy0=
github.com/macabu/inamedparam v0.2.0 h1:VyPYpOc10nkhI2qeNUdh3Zket4fcZjEWe35poddBCpE=
github.com/macabu/inamedparam v0.2.0/go.mod h1:+Pee9/YfGe5LJ62pYXqB89lJ+0k5bsR8Wgz/C0Zlq3U=
github.com/magiconair/properties v1.8.6 h1:5ibWZ6iY0NctNGWo87LalDlEZ6R41TqbbDamhfG/Qzo=
@@ -486,8 +469,8 @@ github.com/mailru/easyjson v0.7.7 h1:UGYAvKxe3sBsEDzO8ZeWOSlIQfWFlxbzLZe7hwFURr0
github.com/mailru/easyjson v0.7.7/go.mod h1:xzfreul335JAWq5oZzymOObrkdz5UnU4kGfJJLY9Nlc=
github.com/manuelarte/embeddedstructfieldcheck v0.4.0 h1:3mAIyaGRtjK6EO9E73JlXLtiy7ha80b2ZVGyacxgfww=
github.com/manuelarte/embeddedstructfieldcheck v0.4.0/go.mod h1:z8dFSyXqp+fC6NLDSljRJeNQJJDWnY7RoWFzV3PC6UM=
-github.com/manuelarte/funcorder v0.6.0 h1:0hBngc4fa1IgNiI65A7sFGkMvoMCc878RjqB5V7rWP0=
-github.com/manuelarte/funcorder v0.6.0/go.mod h1:id3NDhXdQBmeqXH7eVC6Z89xS6JxvZ8kF9xUxpArU/g=
+github.com/manuelarte/funcorder v0.5.0 h1:llMuHXXbg7tD0i/LNw8vGnkDTHFpTnWqKPI85Rknc+8=
+github.com/manuelarte/funcorder v0.5.0/go.mod h1:Yt3CiUQthSBMBxjShjdXMexmzpP8YGvGLjrxJNkO2hA=
github.com/maratori/testableexamples v1.0.1 h1:HfOQXs+XgfeRBJ+Wz0XfH+FHnoY9TVqL6Fcevpzy4q8=
github.com/maratori/testableexamples v1.0.1/go.mod h1:XE2F/nQs7B9N08JgyRmdGjYVGqxWwClLPCGSQhXQSrQ=
github.com/maratori/testpackage v1.1.2 h1:ffDSh+AgqluCLMXhM19f/cpvQAKygKAJXFl9aUjmbqs=
@@ -496,24 +479,24 @@ github.com/matoous/godox v1.1.0 h1:W5mqwbyWrwZv6OQ5Z1a/DHGMOvXYCBP3+Ht7KMoJhq4=
github.com/matoous/godox v1.1.0/go.mod h1:jgE/3fUXiTurkdHOLT5WEkThTSuE7yxHv5iWPa80afs=
github.com/matryer/is v1.4.0 h1:sosSmIWwkYITGrxZ25ULNDeKiMNzFSr4V/eqBQP0PeE=
github.com/matryer/is v1.4.0/go.mod h1:8I/i5uYgLzgsgEloJE1U6xx5HkBQpAZvepWuujKwMRU=
-github.com/mattn/go-colorable v0.1.15 h1:+u9SLTRGnXv73cEsnsmoZBom+dMU88B2M0aDcWy0/jY=
-github.com/mattn/go-colorable v0.1.15/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8=
-github.com/mattn/go-isatty v0.0.24 h1:tGZZoVgT/KiqK1c8ocVLeDS8BSWMRd47J3Lbz7vsReI=
-github.com/mattn/go-isatty v0.0.24/go.mod h1:nMCL3Zebbrt45jsMDgnfIwz6ydEQApk5oEI3HqDio6A=
-github.com/mattn/go-runewidth v0.0.24 h1:cpokDiIn0MGnhdHwuWnJBITySJ20QyNGnY2kR/ay2DU=
-github.com/mattn/go-runewidth v0.0.24/go.mod h1:XBkDxAl56ILZc9knddidhrOlY5R/pDhgLpndooCuJAs=
+github.com/mattn/go-colorable v0.1.14 h1:9A9LHSqF/7dyVVX6g0U9cwm9pG3kP9gSzcuIPHPsaIE=
+github.com/mattn/go-colorable v0.1.14/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8=
+github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY=
+github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y=
+github.com/mattn/go-runewidth v0.0.16 h1:E5ScNMtiwvlvB5paMFdw9p4kSQzbXFikJ5SQO6TULQc=
+github.com/mattn/go-runewidth v0.0.16/go.mod h1:Jdepj2loyihRzMpdS35Xk/zdY8IAYHsh153qUoGf23w=
github.com/mattn/go-sqlite3 v1.14.22 h1:2gZY6PC6kBnID23Tichd1K+Z0oS6nE/XwU+Vz/5o4kU=
github.com/mattn/go-sqlite3 v1.14.22/go.mod h1:Uh1q+B4BYcTPb+yiD3kU8Ct7aC0hY9fxUwlHK0RXw+Y=
-github.com/mgechev/revive v1.15.0 h1:vJ0HzSBzfNyPbHKolgiFjHxLek9KUijhqh42yGoqZ8Q=
-github.com/mgechev/revive v1.15.0/go.mod h1:LlAKO3QQe9OJ0pVZzI2GPa8CbXGZ/9lNpCGvK4T/a8A=
+github.com/mgechev/revive v1.14.0 h1:CC2Ulb3kV7JFYt+izwORoS3VT/+Plb8BvslI/l1yZsc=
+github.com/mgechev/revive v1.14.0/go.mod h1:MvnujelCZBZCaoDv5B3foPo6WWgULSSFxvfxp7GsPfo=
github.com/mitchellh/go-homedir v1.1.0 h1:lukF9ziXFxDFPkA1vsr5zpc1XuPDn/wFntq5mG+4E0Y=
github.com/mitchellh/go-homedir v1.1.0/go.mod h1:SfyaCUpYCn1Vlf4IUYiD9fPX4A5wJrkLzIz1N1q0pr0=
github.com/mitchellh/mapstructure v1.5.0 h1:jeMsZIYE/09sWLaz43PL7Gy6RuMjD2eJVyuac5Z2hdY=
github.com/mitchellh/mapstructure v1.5.0/go.mod h1:bFUtVrKA4DC2yAKiSyO/QUcy7e+RRV2QTWOzhPopBRo=
github.com/moricho/tparallel v0.3.2 h1:odr8aZVFA3NZrNybggMkYO3rgPRcqjeQUlBBFVxKHTI=
github.com/moricho/tparallel v0.3.2/go.mod h1:OQ+K3b4Ln3l2TZveGCywybl68glfLEwFGqvnjok8b+U=
-github.com/muesli/cancelreader v0.2.2 h1:3I4Kt4BQjOR54NavqnDogx/MIoWBFa0StPA8ELUXHmA=
-github.com/muesli/cancelreader v0.2.2/go.mod h1:3XuTXfFS2VjM+HTLZY9Ak0l6eUKfijIfMUZ4EgX0QYo=
+github.com/muesli/termenv v0.16.0 h1:S5AlUN9dENB57rsbnkPyfdGuWIlkmzJjbFf0Tf5FWUc=
+github.com/muesli/termenv v0.16.0/go.mod h1:ZRfOIKPFDYQoDFF4Olj7/QJbW60Ol/kL1pU3VfY/Cnk=
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 h1:C3w9PqII01/Oq1c1nUAm88MOHcQC9l5mIlSMApZMrHA=
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822/go.mod h1:+n7T8mK8HuQTcFwEeznm/DIxMOiR9yIdICNftLE1DvQ=
github.com/nakabonne/nestif v0.3.1 h1:wm28nZjhQY5HyYPx+weN3Q65k6ilSBxDb8v5S81B81U=
@@ -525,16 +508,16 @@ github.com/nishanths/exhaustive v0.12.0 h1:vIY9sALmw6T/yxiASewa4TQcFsVYZQQRUQJhK
github.com/nishanths/exhaustive v0.12.0/go.mod h1:mEZ95wPIZW+x8kC4TgC+9YCUgiST7ecevsVDTgc2obs=
github.com/nishanths/predeclared v0.2.2 h1:V2EPdZPliZymNAn79T8RkNApBjMmVKh5XRpLm/w98Vk=
github.com/nishanths/predeclared v0.2.2/go.mod h1:RROzoN6TnGQupbC+lqggsOlcgysk3LMK/HI84Mp280c=
-github.com/nunnatsa/ginkgolinter v0.24.0 h1:Mp0EagluLFP98JatP6nqp/gGEoljNG97uf9AcxcBVy8=
-github.com/nunnatsa/ginkgolinter v0.24.0/go.mod h1:2ZMRuzX6+3XXyY6UZOwb6n+MCocVGbkIsDBC4vuWz5c=
-github.com/oapi-codegen/nullable v1.2.0 h1:VflFkDW980KhBPiFF7nWSyjg+r4Obqj8lXipV0UkP5w=
-github.com/oapi-codegen/nullable v1.2.0/go.mod h1:KUZ3vUzkmEKY90ksAmit2+5juDIhIZhfDl+0PwOQlFY=
-github.com/oapi-codegen/runtime v1.6.0 h1:7Xx+GlueD6nRuyKoCPzL434Jfi3BetbiJOrzCHp/VPU=
-github.com/oapi-codegen/runtime v1.6.0/go.mod h1:GwV7hC2hviaMzj+ITfHVRESK5J2W/GefVwIND/bMGvU=
-github.com/onsi/ginkgo/v2 v2.32.0 h1:Hw7s2pVrQo/8Yz5N77qdnpHaoc+c6cC9WIV1Jce+J6E=
-github.com/onsi/ginkgo/v2 v2.32.0/go.mod h1:+aXOY+vzZ5mu2iI2HpTZUPmM//oQfsNFX6gU9kNcA44=
-github.com/onsi/gomega v1.42.1 h1:iN1rCUX+44NZ1Dc97MPoeFYbFR0vh8zxoxMFwKdyZ6I=
-github.com/onsi/gomega v1.42.1/go.mod h1:REff/hsDsodHoKlWsP2mAPhu1+5/6hVYNf9rIEBpeSg=
+github.com/nunnatsa/ginkgolinter v0.23.0 h1:x3o4DGYOWbBMP/VdNQKgSj+25aJKx2Pe6lHr8gBcgf8=
+github.com/nunnatsa/ginkgolinter v0.23.0/go.mod h1:9qN1+0akwXEccwV1CAcCDfcoBlWXHB+ML9884pL4SZ4=
+github.com/oapi-codegen/nullable v1.1.0 h1:eAh8JVc5430VtYVnq00Hrbpag9PFRGWLjxR1/3KntMs=
+github.com/oapi-codegen/nullable v1.1.0/go.mod h1:KUZ3vUzkmEKY90ksAmit2+5juDIhIZhfDl+0PwOQlFY=
+github.com/oapi-codegen/runtime v1.4.1 h1:9nwLoI+KrWxzbBcp0jO/R8uXqbik/HUyCvPeU68Y/qo=
+github.com/oapi-codegen/runtime v1.4.1/go.mod h1:GwV7hC2hviaMzj+ITfHVRESK5J2W/GefVwIND/bMGvU=
+github.com/onsi/ginkgo/v2 v2.28.1 h1:S4hj+HbZp40fNKuLUQOYLDgZLwNUVn19N3Atb98NCyI=
+github.com/onsi/ginkgo/v2 v2.28.1/go.mod h1:CLtbVInNckU3/+gC8LzkGUb9oF+e8W8TdUsxPwvdOgE=
+github.com/onsi/gomega v1.39.1 h1:1IJLAad4zjPn2PsnhH70V4DKRFlrCzGBNrNaru+Vf28=
+github.com/onsi/gomega v1.39.1/go.mod h1:hL6yVALoTOxeWudERyfppUcZXjMwIMLnuSfruD2lcfg=
github.com/otiai10/copy v1.2.0/go.mod h1:rrF5dJ5F0t/EWSYODDu4j9/vEeYHMkc8jt0zJChqQWw=
github.com/otiai10/copy v1.14.0 h1:dCI/t1iTdYGtkvCuBG2BgR6KZa83PTclw4U5n2wAllU=
github.com/otiai10/copy v1.14.0/go.mod h1:ECfuL02W+/FkTWZWgQqXPWZgW9oeKCSQ5qVfSc4qc4w=
@@ -548,25 +531,24 @@ github.com/pandatix/go-cvss v0.6.2 h1:TFiHlzUkT67s6UkelHmK6s1INKVUG7nlKYiWWDTITG
github.com/pandatix/go-cvss v0.6.2/go.mod h1:jDXYlQBZrc8nvrMUVVvTG8PhmuShOnKrxP53nOFkt8Q=
github.com/pelletier/go-toml v1.9.5 h1:4yBQzkHv+7BHq2PQUZF3Mx0IYxG7LsP222s7Agd3ve8=
github.com/pelletier/go-toml v1.9.5/go.mod h1:u1nR/EPcESfeI/szUZKdtJ0xRNbUoANCkoOuaOx1Y+c=
-github.com/pelletier/go-toml/v2 v2.4.3 h1:GTRvJQutkOSftxIFD5xw9aepkYNuPWmVJpffdDPYVpY=
-github.com/pelletier/go-toml/v2 v2.4.3/go.mod h1:2gIqNv+qfxSVS7cM2xJQKtLSTLUE9V8t9Stt+h56mCY=
+github.com/pelletier/go-toml/v2 v2.2.4 h1:mye9XuhQ6gvn5h28+VilKrrPoQVanw5PMw/TB0t5Ec4=
+github.com/pelletier/go-toml/v2 v2.2.4/go.mod h1:2gIqNv+qfxSVS7cM2xJQKtLSTLUE9V8t9Stt+h56mCY=
github.com/peterbourgon/g2s v0.0.0-20170223122336-d4e7ad98afea h1:sKwxy1H95npauwu8vtF95vG/syrL0p8fSZo/XlDg5gk=
github.com/peterbourgon/g2s v0.0.0-20170223122336-d4e7ad98afea/go.mod h1:1VcHEd3ro4QMoHfiNl/j7Jkln9+KQuorp0PItHMJYNg=
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c h1:+mdjkGKdHQG3305AYmdv1U2eRNDiU2ErMBj1gwrq8eQ=
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c/go.mod h1:7rwL4CYBLnjLxUqIJNnCWiEdr3bn6IUYi15bNlnbCCU=
github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 h1:GFCKgmp0tecUJ0sJuv4pzYCqS9+RGSn52M3FUwPs+uo=
github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10/go.mod h1:t/avpk3KcrXxUnYOhZhMXJlSEyie6gQbtLq5NM3loB8=
+github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
-github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 h1:Jamvg5psRIccs7FGNTlIRMkT8wgtp5eCXdBlqhYGL6U=
-github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
-github.com/prometheus/client_golang v1.24.1 h1:JnJkREXzWxUdCuPFpIWZiPispT9xVV59uiuyR2bPlnU=
-github.com/prometheus/client_golang v1.24.1/go.mod h1:F+oSRECHg4sse5ucfYpYDeIv/hu68Zo0uoHKetWnzcE=
+github.com/prometheus/client_golang v1.23.2 h1:Je96obch5RDVy3FDMndoUsjAhG5Edi49h0RJWRi/o0o=
+github.com/prometheus/client_golang v1.23.2/go.mod h1:Tb1a6LWHB3/SPIzCoaDXI4I8UHKeFTEQ1YCr+0Gyqmg=
github.com/prometheus/client_model v0.6.2 h1:oBsgwpGs7iVziMvrGhE53c/GrLUsZdHnqNwqPLxwZyk=
github.com/prometheus/client_model v0.6.2/go.mod h1:y3m2F6Gdpfy6Ut/GBsUqTWZqCUvMVzSfMLjcu6wAwpE=
-github.com/prometheus/common v0.70.1 h1:1HvjP4D5oL3t8RsPlwxA9onvvStjtIHYE5XuuwOi/PY=
-github.com/prometheus/common v0.70.1/go.mod h1:VdFUQDMZK3VLkurFUVhia6uys/0suUp86TJz5qbJRhc=
-github.com/prometheus/procfs v0.21.1 h1:GljZCt+zSTS+NZq88cyQ1LjZ+RCHp3uVuabBWA5+OJI=
-github.com/prometheus/procfs v0.21.1/go.mod h1:aB55Cww9pdSJVHk0hUf0inxWyyjPogFIjmHKYgMKmtY=
+github.com/prometheus/common v0.67.5 h1:pIgK94WWlQt1WLwAC5j2ynLaBRDiinoAb86HZHTUGI4=
+github.com/prometheus/common v0.67.5/go.mod h1:SjE/0MzDEEAyrdr5Gqc6G+sXI67maCxzaT3A2+HqjUw=
+github.com/prometheus/procfs v0.20.1 h1:XwbrGOIplXW/AU3YhIhLODXMJYyC1isLFfYCsTEycfc=
+github.com/prometheus/procfs v0.20.1/go.mod h1:o9EMBZGRyvDrSPH1RqdxhojkuXstoe4UlK79eF5TGGo=
github.com/quasilyte/go-ruleguard v0.4.5 h1:AGY0tiOT5hJX9BTdx/xBdoCubQUAE2grkqY2lSwvZcA=
github.com/quasilyte/go-ruleguard v0.4.5/go.mod h1:Vl05zJ538vcEEwu16V/Hdu7IYZWyKSwIy4c88Ro1kRE=
github.com/quasilyte/go-ruleguard/dsl v0.3.23 h1:lxjt5B6ZCiBeeNO8/oQsegE6fLeCzuMRoVWSkXC4uvY=
@@ -577,14 +559,15 @@ github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727 h1:TCg2WBOl
github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727/go.mod h1:rlzQ04UMyJXu/aOvhd8qT+hvDrFpiwqp8MRXDY9szc0=
github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567 h1:M8mH9eK4OUR4lu7Gd+PU1fV2/qnDNfzT635KRSObncs=
github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567/go.mod h1:DWNGW8A4Y+GyBgPuaQJuWiy0XYftx4Xm/y5Jqk9I6VQ=
-github.com/raeperd/recvcheck v0.3.0 h1:PM+XYvyxIj3bo+kobJfFTdTuU3Lmfu96mKDbyHDbRt8=
-github.com/raeperd/recvcheck v0.3.0/go.mod h1:PZNwG+HztFYMH2ZPq0Hu3QgkV2yiA6VrtNz9c1fXWJo=
+github.com/raeperd/recvcheck v0.2.0 h1:GnU+NsbiCqdC2XX5+vMZzP+jAJC5fht7rcVTAhX74UI=
+github.com/raeperd/recvcheck v0.2.0/go.mod h1:n04eYkwIR0JbgD73wT8wL4JjPC3wm0nFtzBnWNocnYU=
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec h1:W09IVJc94icq4NjY3clb7Lk8O1qJ8BdBEF8z0ibU0rE=
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec/go.mod h1:qqbHyh8v60DhA7CoWK5oRCqLrMHRGoxYCSS9EjAz6Eo=
+github.com/rivo/uniseg v0.2.0/go.mod h1:J6wj4VEh+S6ZtnVlnTBMWIodfgj8LQOQFoIToxlJtxc=
github.com/rivo/uniseg v0.4.7 h1:WUdvkW8uEhrYfLC4ZzdpI2ztxP1I582+49Oc5Mq64VQ=
github.com/rivo/uniseg v0.4.7/go.mod h1:FN3SvrM+Zdj16jyLfmOkMNblXMcoc8DfTHruCPUcx88=
-github.com/rogpeppe/go-internal v1.16.0 h1:O9DK+vNMDVGLr2BeZqmpLeMjiMNkuXfcqntWbZV6S5g=
-github.com/rogpeppe/go-internal v1.16.0/go.mod h1:DrUVZyrJU+txYW5/1kwtXQSMFio52ZOxX7yM1VHvnxs=
+github.com/rogpeppe/go-internal v1.14.1 h1:UQB4HGPB6osV0SQTLymcB4TgvyWu6ZyliaW0tI/otEQ=
+github.com/rogpeppe/go-internal v1.14.1/go.mod h1:MaRKkUm5W0goXpeCfT7UZI6fk/L7L7so1lCWt35ZSgc=
github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529 h1:18kd+8ZUlt/ARXhljq+14TwAoKa61q6dX8jtwOf6DH8=
github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529/go.mod h1:qe5TWALJ8/a1Lqznoc5BDHpYX/8HU60Hm2AwRmqzxqA=
github.com/rubyist/circuitbreaker v2.2.1+incompatible h1:KUKd/pV8Geg77+8LNDwdow6rVCAYOp8+kHUyFvL6Mhk=
@@ -594,31 +577,31 @@ github.com/russross/blackfriday/v2 v2.1.0 h1:JIOH55/0cWyOuilr9/qlrm0BSXldqnqwMsf
github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM=
github.com/ryancurrah/gomodguard v1.4.1 h1:eWC8eUMNZ/wM/PWuZBv7JxxqT5fiIKSIyTvjb7Elr+g=
github.com/ryancurrah/gomodguard v1.4.1/go.mod h1:qnMJwV1hX9m+YJseXEBhd2s90+1Xn6x9dLz11ualI1I=
-github.com/ryancurrah/gomodguard/v2 v2.1.3 h1:E7sz3PJwE9Ba1reVxSpF6XLCPJZ74Kfw/LabTNM4GIA=
-github.com/ryancurrah/gomodguard/v2 v2.1.3/go.mod h1:CQicdLGatWMxLX53JzoBjYlsNZhHbmLv2AVa0s2aivU=
-github.com/ryanrolds/sqlclosecheck v0.6.0 h1:pEyL9okISdg1F1SEpJNlrEotkTGerv5BMk7U4AG0eVg=
-github.com/ryanrolds/sqlclosecheck v0.6.0/go.mod h1:xyX16hsDaCMXHrMJ3JMzGf5OpDfHTOTTQrT7HOFUmeU=
+github.com/ryanrolds/sqlclosecheck v0.5.1 h1:dibWW826u0P8jNLsLN+En7+RqWWTYrjCB9fJfSfdyCU=
+github.com/ryanrolds/sqlclosecheck v0.5.1/go.mod h1:2g3dUjoS6AL4huFdv6wn55WpLIDjY7ZgUR4J8HOO/XQ=
github.com/sanposhiho/wastedassign/v2 v2.1.0 h1:crurBF7fJKIORrV85u9UUpePDYGWnwvv3+A96WvwXT0=
github.com/sanposhiho/wastedassign/v2 v2.1.0/go.mod h1:+oSmSC+9bQ+VUAxA66nBb0Z7N8CK7mscKTDYC6aIek4=
-github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 h1:1EYB5IzjZawrrnELUi78f9fPu57HuXjmddZPjrls/28=
-github.com/santhosh-tekuri/jsonschema/v6 v6.0.3/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU=
+github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 h1:KRzFb2m7YtdldCEkzs6KqmJw4nqEVZGK7IN2kJkjTuQ=
+github.com/santhosh-tekuri/jsonschema/v6 v6.0.2/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU=
github.com/sashamelentyev/interfacebloat v1.1.0 h1:xdRdJp0irL086OyW1H/RTZTr1h/tMEOsumirXcOJqAw=
github.com/sashamelentyev/interfacebloat v1.1.0/go.mod h1:+Y9yU5YdTkrNvoX0xHc84dxiN1iBi9+G8zZIhPVoNjQ=
github.com/sashamelentyev/usestdlibvars v1.29.0 h1:8J0MoRrw4/NAXtjQqTHrbW9NN+3iMf7Knkq057v4XOQ=
github.com/sashamelentyev/usestdlibvars v1.29.0/go.mod h1:8PpnjHMk5VdeWlVb4wCdrB8PNbLqZ3wBZTZWkrpZZL8=
-github.com/securego/gosec/v2 v2.28.0 h1:ZsSdiDb0AtTpLFVol5z91gbMei9ZiLEPG/pZjZujp7c=
-github.com/securego/gosec/v2 v2.28.0/go.mod h1:lb4/9AHe+lJy/kjWmWRWWsEipvbwGKuxf+tY1Pmjdnk=
+github.com/securego/gosec/v2 v2.23.0 h1:h4TtF64qFzvnkqvsHC/knT7YC5fqyOCItlVR8+ptEBo=
+github.com/securego/gosec/v2 v2.23.0/go.mod h1:qRHEgXLFuYUDkI2T7W7NJAmOkxVhkR0x9xyHOIcMNZ0=
github.com/sergi/go-diff v1.2.0 h1:XU+rvMAioB0UC3q1MFrIQy4Vo5/4VsRDQQXHsEya6xQ=
github.com/sergi/go-diff v1.2.0/go.mod h1:STckp+ISIX8hZLjrqAeVduY0gWCT9IjLuqbuNXdaHfM=
+github.com/shurcooL/go v0.0.0-20180423040247-9e1955d9fb6e/go.mod h1:TDJrrUr11Vxrven61rcy3hJMUqaf/CLWYhHNPmT14Lk=
+github.com/shurcooL/go-goon v0.0.0-20170922171312-37c2f522c041/go.mod h1:N5mDOmsrJOB+vfqUK+7DmDyjhSLIIBnXo9lvZJj3MWQ=
github.com/shurcooL/sanitized_anchor_name v1.0.0/go.mod h1:1NzhyTcUVG4SuEtjjoZeVRXNmyL/1OwPU0+IJeTBvfc=
-github.com/sirupsen/logrus v1.10.1 h1:xi4336Zh11WpU14fXR6I67V3yaTPQYwRx2WEtHbRg4Q=
-github.com/sirupsen/logrus v1.10.1/go.mod h1:vsQHnG7xzNsxk3NrwboUiWPnIC3dmbjcGPykD7+tiHk=
+github.com/sirupsen/logrus v1.9.4 h1:TsZE7l11zFCLZnZ+teH4Umoq5BhEIfIzfRDZ1Uzql2w=
+github.com/sirupsen/logrus v1.9.4/go.mod h1:ftWc9WdOfJ0a92nsE2jF5u5ZwH8Bv2zdeOC42RjbV2g=
github.com/sivchari/containedctx v1.0.3 h1:x+etemjbsh2fB5ewm5FeLNi5bUjK0V8n0RB+Wwfd0XE=
github.com/sivchari/containedctx v1.0.3/go.mod h1:c1RDvCbnJLtH4lLcYD/GqwiBSSf4F5Qk0xld2rBqzJ4=
-github.com/sonatard/noctx v0.5.1 h1:wklWg9c9ZYugOAk7qG4yP4PBrlQsmSLPTvW1K4PRQMs=
-github.com/sonatard/noctx v0.5.1/go.mod h1:64XdbzFb18XL4LporKXp8poqZtPKbCrqQ402CV+kJas=
-github.com/sourcegraph/go-diff v0.8.0 h1:ipIyu4cTsLbIrln4l0qtHA3r0a7gyK4ntKjtQytHhvY=
-github.com/sourcegraph/go-diff v0.8.0/go.mod h1:hWlcO7Al+UZStZAP8rBumHpCK5ZHQ5BXsMls8p4+F5E=
+github.com/sonatard/noctx v0.4.0 h1:7MC/5Gg4SQ4lhLYR6mvOP6mQVSxCrdyiExo7atBs27o=
+github.com/sonatard/noctx v0.4.0/go.mod h1:64XdbzFb18XL4LporKXp8poqZtPKbCrqQ402CV+kJas=
+github.com/sourcegraph/go-diff v0.7.0 h1:9uLlrd5T46OXs5qpp8L/MTltk0zikUGi0sNNyCpA8G0=
+github.com/sourcegraph/go-diff v0.7.0/go.mod h1:iBszgVvyxdc8SFZ7gm69go2KDdt3ag071iBaWPF6cjs=
github.com/spdx/tools-golang v0.5.7 h1:+sWcKGnhwp3vLdMqPcLdA6QK679vd86cK9hQWH3AwCg=
github.com/spdx/tools-golang v0.5.7/go.mod h1:jg7w0LOpoNAw6OxKEzCoqPC2GCTj45LyTlVmXubDsYw=
github.com/spf13/afero v1.15.0 h1:b/YBCLWAJdFWJTN9cLhiXXcD7mzKn9Dm86dNnfyQw1I=
@@ -643,14 +626,14 @@ github.com/ssgreg/nlreturn/v2 v2.2.1/go.mod h1:E/iiPB78hV7Szg2YfRgyIrk1AD6JVMTRk
github.com/stbenjam/no-sprintf-host-port v0.3.1 h1:AyX7+dxI4IdLBPtDbsGAyqiTSLpCP9hWRrXQDU4Cm/g=
github.com/stbenjam/no-sprintf-host-port v0.3.1/go.mod h1:ODbZesTCHMVKthBHskvUUexdcNHAQRXk9NpSsL8p/HQ=
github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
-github.com/stretchr/objx v0.5.3 h1:jmXUvGomnU1o3W/V5h2VEradbpJDwGrzugQQvL0POH4=
-github.com/stretchr/objx v0.5.3/go.mod h1:rDQraq+vQZU7Fde9LOZLr8Tax6zZvy4kuNKF+QYS+U0=
+github.com/stretchr/objx v0.5.2 h1:xuMeJ0Sdp5ZMRXx/aWO6RZxdr3beISkG5/G/aIRr3pY=
+github.com/stretchr/objx v0.5.2/go.mod h1:FRsXN1f5AsAjCGJKqEizvkpNtU+EGNCLh3NxZ/8L+MA=
github.com/stretchr/testify v1.2.2/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs=
github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI=
github.com/stretchr/testify v1.4.0/go.mod h1:j7eGeouHqKxXV5pUuKE4zz7dFj8WfuZ+81PSLYec5m4=
github.com/stretchr/testify v1.6.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
-github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
-github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
+github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
+github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
github.com/subosito/gotenv v1.4.1 h1:jyEFiXpy21Wm81FBN71l9VoMMV8H8jG+qIK3GCpY6Qs=
github.com/subosito/gotenv v1.4.1/go.mod h1:ayKnFf/c6rvx/2iiLrJUk1e6plDbT3edrFNGqEflhK0=
github.com/swaggo/swag v1.16.6 h1:qBNcx53ZaX+M5dxVyTrgQ0PJ/ACK+NzhwcbieTt+9yI=
@@ -661,28 +644,28 @@ github.com/tenntenn/text/transform v0.0.0-20200319021203-7eef512accb3 h1:f+jULpR
github.com/tenntenn/text/transform v0.0.0-20200319021203-7eef512accb3/go.mod h1:ON8b8w4BN/kE1EOhwT0o+d62W65a6aPw1nouo9LMgyY=
github.com/terminalstatic/go-xsd-validate v0.1.6 h1:TenYeQ3eY631qNi1/cTmLH/s2slHPRKTTHT+XSHkepo=
github.com/terminalstatic/go-xsd-validate v0.1.6/go.mod h1:18lsvYFofBflqCrvo1umpABZ99+GneNTw2kEEc8UPJw=
-github.com/tetafro/godot v1.5.6 h1:IEkrFCwXaYHlOn4mGzGS3F3dkP6m9t0jpwqBFPIkKiA=
-github.com/tetafro/godot v1.5.6/go.mod h1:eOkMrVQurDui411nBY2FA05EYH01r14LuWY/NrVDVcU=
-github.com/timakin/bodyclose v0.0.0-20260129054331-73d1f95b84b4 h1:SiHe5XLTn9sFWJ5pBwJ5FN/4j34q9ZlOAD//kMoMYp0=
-github.com/timakin/bodyclose v0.0.0-20260129054331-73d1f95b84b4/go.mod h1:sDHLK7rb/59v/ZxZ7KtymgcoxuUMxjXq8gtu9VMOK8M=
+github.com/tetafro/godot v1.5.4 h1:u1ww+gqpRLiIA16yF2PV1CV1n/X3zhyezbNXC3E14Sg=
+github.com/tetafro/godot v1.5.4/go.mod h1:eOkMrVQurDui411nBY2FA05EYH01r14LuWY/NrVDVcU=
+github.com/timakin/bodyclose v0.0.0-20241222091800-1db5c5ca4d67 h1:9LPGD+jzxMlnk5r6+hJnar67cgpDIz/iyD+rfl5r2Vk=
+github.com/timakin/bodyclose v0.0.0-20241222091800-1db5c5ca4d67/go.mod h1:mkjARE7Yr8qU23YcGMSALbIxTQ9r9QBVahQOBRfU460=
github.com/timonwong/loggercheck v0.11.0 h1:jdaMpYBl+Uq9mWPXv1r8jc5fC3gyXx4/WGwTnnNKn4M=
github.com/timonwong/loggercheck v0.11.0/go.mod h1:HEAWU8djynujaAVX7QI65Myb8qgfcZ1uKbdpg3ZzKl8=
github.com/tomarrell/wrapcheck/v2 v2.12.0 h1:H/qQ1aNWz/eeIhxKAFvkfIA+N7YDvq6TWVFL27Of9is=
github.com/tomarrell/wrapcheck/v2 v2.12.0/go.mod h1:AQhQuZd0p7b6rfW+vUwHm5OMCGgp63moQ9Qr/0BpIWo=
github.com/tommy-muehle/go-mnd/v2 v2.5.1 h1:NowYhSdyE/1zwK9QCLeRb6USWdoif80Ie+v+yU8u1Zw=
github.com/tommy-muehle/go-mnd/v2 v2.5.1/go.mod h1:WsUAkMJMYww6l/ufffCD3m+P7LEvr8TnZn9lwVDlgzw=
-github.com/ulikunitz/xz v0.5.16 h1:ld6NyySjx5lowVKwJvMRLnW5nxKX/xnpSiFYZ/Lxur0=
-github.com/ulikunitz/xz v0.5.16/go.mod h1:H9Rt/W6/Qj27PGauhQc6nfCDy7vHpzsOThBSaYDoEhw=
+github.com/ulikunitz/xz v0.5.15 h1:9DNdB5s+SgV3bQ2ApL10xRc35ck0DuIX/isZvIk+ubY=
+github.com/ulikunitz/xz v0.5.15/go.mod h1:nbz6k7qbPmH4IRqmfOplQw/tblSgqTqBwxkY0oWt/14=
github.com/ultraware/funlen v0.2.0 h1:gCHmCn+d2/1SemTdYMiKLAHFYxTYz7z9VIDRaTGyLkI=
github.com/ultraware/funlen v0.2.0/go.mod h1:ZE0q4TsJ8T1SQcjmkhN/w+MceuatI6pBFSxxyteHIJA=
github.com/ultraware/whitespace v0.2.0 h1:TYowo2m9Nfj1baEQBjuHzvMRbp19i+RCcRYrSWoFa+g=
github.com/ultraware/whitespace v0.2.0/go.mod h1:XcP1RLD81eV4BW8UhQlpaR+SDc2givTvyI8a586WjW8=
github.com/urfave/cli/v2 v2.3.0 h1:qph92Y649prgesehzOrQjdWyxFOp/QVM+6imKHad91M=
github.com/urfave/cli/v2 v2.3.0/go.mod h1:LJmUH05zAU44vOAcrfzZQKsZbVcdbOG8rtL3/XcUArI=
-github.com/uudashr/gocognit v1.2.1 h1:CSJynt5txTnORn/DkhiB4mZjwPuifyASC8/6Q0I/QS4=
-github.com/uudashr/gocognit v1.2.1/go.mod h1:acaubQc6xYlXFEMb9nWX2dYBzJ/bIjEkc1zzvyIZg5Q=
-github.com/uudashr/iface v1.5.0 h1:PgdMt4uAettGG8K/Kbamc4B9FABgUgnS3TLbl6fnjEk=
-github.com/uudashr/iface v1.5.0/go.mod h1:pbeBPlbuU2qkNDn0mmfrxP2X+wjPMIQAy+r1MBXSXtg=
+github.com/uudashr/gocognit v1.2.0 h1:3BU9aMr1xbhPlvJLSydKwdLN3tEUUrzPSSM8S4hDYRA=
+github.com/uudashr/gocognit v1.2.0/go.mod h1:k/DdKPI6XBZO1q7HgoV2juESI2/Ofj9AcHPZhBBdrTU=
+github.com/uudashr/iface v1.4.1 h1:J16Xl1wyNX9ofhpHmQ9h9gk5rnv2A6lX/2+APLTo0zU=
+github.com/uudashr/iface v1.4.1/go.mod h1:pbeBPlbuU2qkNDn0mmfrxP2X+wjPMIQAy+r1MBXSXtg=
github.com/xeipuuv/gojsonpointer v0.0.0-20180127040702-4e3ac2762d5f h1:J9EGpcZtP0E/raorCMxlFGSTBrsSlaDGf3jU/qvAE2c=
github.com/xeipuuv/gojsonpointer v0.0.0-20180127040702-4e3ac2762d5f/go.mod h1:N2zxlSyiKSe5eX1tZViRH5QA0qijqEDrYZiPEAiq3wU=
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 h1:EzJWgHovont7NscjpAxXsDA8S8BMYve8Y5+7cuRE7R0=
@@ -702,6 +685,7 @@ github.com/ykadowak/zerologlint v0.1.5/go.mod h1:KaUskqF3e/v59oPmdq1U1DnKcuHokl2
github.com/yuin/goldmark v1.1.25/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
github.com/yuin/goldmark v1.1.32/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
github.com/yuin/goldmark v1.2.1/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
+github.com/yuin/goldmark v1.3.5/go.mod h1:mwnBkeHKe2W/ZEtQ+71ViKU8L12m81fl3OWwC1Zlc8k=
github.com/yuin/goldmark v1.4.1/go.mod h1:mwnBkeHKe2W/ZEtQ+71ViKU8L12m81fl3OWwC1Zlc8k=
github.com/yuin/goldmark v1.4.13/go.mod h1:6yULJ656Px+3vBD8DxQVa3kxgyrAnzto9xy5taEt/CY=
gitlab.com/bosi/decorder v0.4.2 h1:qbQaV3zgwnBZ4zPMhGLW4KZe7A7NwxEhJx39R3shffo=
@@ -710,20 +694,20 @@ go-simpler.org/assert v0.9.0 h1:PfpmcSvL7yAnWyChSjOz6Sp6m9j5lyK8Ok9pEL31YkQ=
go-simpler.org/assert v0.9.0/go.mod h1:74Eqh5eI6vCK6Y5l3PI8ZYFXG4Sa+tkr70OIPJAUr28=
go-simpler.org/musttag v0.14.0 h1:XGySZATqQYSEV3/YTy+iX+aofbZZllJaqwFWs+RTtSo=
go-simpler.org/musttag v0.14.0/go.mod h1:uP8EymctQjJ4Z1kUnjX0u2l60WfUdQxCwSNKzE1JEOE=
-go-simpler.org/sloglint v0.12.0 h1:UzWDlLWNE5FLqsvyq3tWYHuQMbqrervOhT8qPl4Mmw4=
-go-simpler.org/sloglint v0.12.0/go.mod h1:jBjjC2bm8rYrs88oTRlFX497kWjJsyZWYoNaXkGRI6I=
+go-simpler.org/sloglint v0.11.1 h1:xRbPepLT/MHPTCA6TS/wNfZrDzkGvCCqUv4Bdwc3H7s=
+go-simpler.org/sloglint v0.11.1/go.mod h1:2PowwiCOK8mjiF+0KGifVOT8ZsCNiFzvfyJeJOIt8MQ=
go.augendre.info/arangolint v0.4.0 h1:xSCZjRoS93nXazBSg5d0OGCi9APPLNMmmLrC995tR50=
go.augendre.info/arangolint v0.4.0/go.mod h1:l+f/b4plABuFISuKnTGD4RioXiCCgghv2xqst/xOvAA=
-go.augendre.info/fatcontext v0.10.0 h1:HhFopmivh8U1+AU7f0kuwUeg2eiIns7YsGQOMHwSJ90=
-go.augendre.info/fatcontext v0.10.0/go.mod h1:pqpGvA9GlrXy+aXkp8L2dKz12Zp4g2FhzcAtwToU+2w=
+go.augendre.info/fatcontext v0.9.0 h1:Gt5jGD4Zcj8CDMVzjOJITlSb9cEch54hjRRlN3qDojE=
+go.augendre.info/fatcontext v0.9.0/go.mod h1:L94brOAT1OOUNue6ph/2HnwxoNlds9aXDF2FcUntbNw=
go.opentelemetry.io/auto/sdk v1.2.1 h1:jXsnJ4Lmnqd11kwkBV2LgLoFMZKizbCi5fNZ/ipaZ64=
go.opentelemetry.io/auto/sdk v1.2.1/go.mod h1:KRTj+aOaElaLi+wW1kO/DZRXwkF4C5xPbEe3ZiIhN7Y=
-go.opentelemetry.io/contrib/detectors/gcp v1.43.0 h1:62yY3dT7/ShwOxzA0RsKRgshBmfElKI4d/Myu2OxDFU=
-go.opentelemetry.io/contrib/detectors/gcp v1.43.0/go.mod h1:RyaZMFY7yi1kAs45S6mbFGz8O8rqB0dTY14uzvG4LCs=
+go.opentelemetry.io/contrib/detectors/gcp v1.42.0 h1:kpt2PEJuOuqYkPcktfJqWWDjTEd/FNgrxcniL7kQrXQ=
+go.opentelemetry.io/contrib/detectors/gcp v1.42.0/go.mod h1:W9zQ439utxymRrXsUOzZbFX4JhLxXU4+ZnCt8GG7yA8=
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.67.0 h1:yI1/OhfEPy7J9eoa6Sj051C7n5dvpj0QX8g4sRchg04=
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.67.0/go.mod h1:NoUCKYWK+3ecatC4HjkRktREheMeEtrXoQxrqYFeHSc=
-go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0 h1:8tvICD4vSTOOsNrsI4Ljf6C+6UKvpTEH5XY3JMoyPoo=
-go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0/go.mod h1:z9+yiacE0IHRqM4qFfkbt/JYlmYXgss8GY/jXoNuPJI=
+go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.67.0 h1:OyrsyzuttWTSur2qN/Lm0m2a8yqyIjUVBZcxFPuXq2o=
+go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.67.0/go.mod h1:C2NGBr+kAB4bk3xtMXfZ94gqFDtg/GkI7e9zqGh5Beg=
go.opentelemetry.io/otel v1.44.0 h1:JjwHmHpA4iZ3wBxluu2fbbE7j4kqlE8jXyAyPXH7HqU=
go.opentelemetry.io/otel v1.44.0/go.mod h1:BMgjTHL9WPRlRjL2oZCBTL4whCGtXch2H4BhOPIAyYc=
go.opentelemetry.io/otel/metric v1.44.0 h1:1w0gILTcHdr3YI+ixLyjemwrVnsMURbTZFrSYCdDdmc=
@@ -742,45 +726,53 @@ go.uber.org/multierr v1.11.0 h1:blXXJkSxSSfBVBlC76pxqeO+LN3aDfLQo+309xJstO0=
go.uber.org/multierr v1.11.0/go.mod h1:20+QtiLqy0Nd6FdQB9TLXag12DsQkrbs3htMFfDN80Y=
go.uber.org/zap v1.27.1 h1:08RqriUEv8+ArZRYSTXy1LeBScaMpVSTBhCeaZYfMYc=
go.uber.org/zap v1.27.1/go.mod h1:GB2qFLM7cTU87MWRP2mPIjqfIDnGu+VIO4V/SdhGo2E=
-go.yaml.in/yaml/v2 v2.4.4 h1:tuyd0P+2Ont/d6e2rl3be67goVK4R6deVxCUX5vyPaQ=
-go.yaml.in/yaml/v2 v2.4.4/go.mod h1:gMZqIpDtDqOfM0uNfy0SkpRhvUryYH0Z6wdMYcacYXQ=
+go.yaml.in/yaml/v2 v2.4.3 h1:6gvOSjQoTB3vt1l+CU+tSyi/HOjfOjRLJ4YwYZGwRO0=
+go.yaml.in/yaml/v2 v2.4.3/go.mod h1:zSxWcmIDjOzPXpjlTTbAsKokqkDNAVtZO0WOMiT90s8=
+go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc=
go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
-go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
-go.yaml.in/yaml/v3 v3.0.5/go.mod h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg=
gocloud.dev v0.46.0 h1:niIuZwSjMtBx8K+ITB2s5kZullB13PGOS2ZoQPZxQ4Q=
gocloud.dev v0.46.0/go.mod h1:ACQe+2qO+hEO+pdcvvsM+RB63r8TyGD1W3ESCLFyzvM=
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI=
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto=
golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc=
-golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M=
-golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis=
+golang.org/x/crypto v0.13.0/go.mod h1:y6Z2r+Rw4iayiXXAIxJIDAJ1zMW4yaTpebo8fPOliYc=
+golang.org/x/crypto v0.14.0/go.mod h1:MVFd36DqK4CsrnJYDkBA3VC4m2GkXAM0PvzMCn4JQf4=
+golang.org/x/crypto v0.53.0 h1:QZ4Muo8THX6CizN2vPPd5fBGHyogrdK9fG4wLPFUsto=
+golang.org/x/crypto v0.53.0/go.mod h1:DNLU434OwVakk9PzuwV8w62mAJpRJL3vsgcfp4Qnsio=
golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa h1:Zt3DZoOFFYkKhDT3v7Lm9FDMEV06GpzjG2jrqW+QTE0=
golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa/go.mod h1:K79w1Vqn7PoiZn+TkNpx3BUWUQksGO3JcVX6qIjytmA=
golang.org/x/exp/typeparams v0.0.0-20220428152302-39d4317da171/go.mod h1:AbB0pIl9nAr9wVwH+Z2ZpaocVmF5I4GyWCDIsVjR0bk=
golang.org/x/exp/typeparams v0.0.0-20230203172020-98cc5a0785f9/go.mod h1:AbB0pIl9nAr9wVwH+Z2ZpaocVmF5I4GyWCDIsVjR0bk=
-golang.org/x/exp/typeparams v0.0.0-20260811152304-ee035b5b010f h1:+lI8cDJ4uceLipg2f1ODay7fEuLkk0BIHXd6PB8icxo=
-golang.org/x/exp/typeparams v0.0.0-20260811152304-ee035b5b010f/go.mod h1:PqrXSW65cXDZH0k4IeUbhmg/bcAZDbzNz3byBpKCsXo=
+golang.org/x/exp/typeparams v0.0.0-20260209203927-2842357ff358 h1:qWFG1Dj7TBjOjOvhEOkmyGPVoquqUKnIU0lEVLp8xyk=
+golang.org/x/exp/typeparams v0.0.0-20260209203927-2842357ff358/go.mod h1:4Mzdyp/6jzw9auFDJ3OMF5qksa7UvPnzKqTVGcb04ms=
golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
golang.org/x/mod v0.4.1/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
+golang.org/x/mod v0.4.2/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
golang.org/x/mod v0.6.0-dev.0.20220106191415-9b9b3d81d5e3/go.mod h1:3p9vT2HGsQu2K1YbXdKPJLVgG5VJdoTa1poYQBtP1AY=
golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4=
golang.org/x/mod v0.8.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs=
-golang.org/x/mod v0.40.0 h1:hUv+3cXcdRHz08UmSiOob7sadHig73uo5bkXxQ/tvUs=
-golang.org/x/mod v0.40.0/go.mod h1:0/weTWkPWGBikyTWAX3dkjVztMmBA5hM0DH6BElSupE=
+golang.org/x/mod v0.12.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs=
+golang.org/x/mod v0.13.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c=
+golang.org/x/mod v0.36.0 h1:JJjpVx6myfUsUdAzZuOSTTmRE0PfZeNWzzvKrP7amb4=
+golang.org/x/mod v0.36.0/go.mod h1:moc6ELqsWcOw5Ef3xVprK5ul/MvtVvkIXLziUOICjUQ=
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
golang.org/x/net v0.0.0-20200625001655-4c5254603344/go.mod h1:/O7V0waA8r7cgGh81Ro3o1hOxt32SMVPicZroKQ2sZA=
golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU=
golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg=
+golang.org/x/net v0.0.0-20210405180319-a5a99cb37ef4/go.mod h1:p54w0d4576C0XHj96bSt6lcn1PtDYWL6XObtHCRCNQM=
golang.org/x/net v0.0.0-20210421230115-4e50805a0758/go.mod h1:72T/g9IO56b78aLF+1Kcs5dz7/ng1VjMUvfKvpfy+jM=
golang.org/x/net v0.0.0-20211015210444-4f30a5c0130f/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y=
golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c=
golang.org/x/net v0.6.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs=
-golang.org/x/net v0.58.0 h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To=
-golang.org/x/net v0.58.0/go.mod h1:YwCddHnFlT7eLQqVprV19OnhLGtc5xOKgE0RyqgfWAU=
+golang.org/x/net v0.10.0/go.mod h1:0qNGK6F8kojg2nk9dLZ2mShWaEBan6FAoqfSigmmuDg=
+golang.org/x/net v0.15.0/go.mod h1:idbUs1IY1+zTqbi8yxTbhexhEEk5ur9LInksu6HrEpk=
+golang.org/x/net v0.16.0/go.mod h1:NxSsAGuq816PNPmqtQdLE42eU2Fs7NoRIZrHJAlaCOE=
+golang.org/x/net v0.56.0 h1:Rw8j/hFzGvJUZwNBXnAtf5sVDVt+65SK2C7IxCxZt5o=
+golang.org/x/net v0.56.0/go.mod h1:D3Ku6r+V6JROoZK144D2XfMHFcMq/0zSfLelVTCFKec=
golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs=
golang.org/x/oauth2 v0.36.0/go.mod h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7Q=
golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
@@ -790,16 +782,20 @@ golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJ
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sync v0.1.0/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
-golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek=
-golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
+golang.org/x/sync v0.3.0/go.mod h1:FU7BRWz2tNW+3quACPkgCx/L+uEAv1htQ0V83Z9Rj+Y=
+golang.org/x/sync v0.4.0/go.mod h1:FU7BRWz2tNW+3quACPkgCx/L+uEAv1htQ0V83Z9Rj+Y=
+golang.org/x/sync v0.21.0 h1:HLII4xRRTtCRkxYp4HNFF0Js/Og6q2i++KXbg0gHCwM=
+golang.org/x/sync v0.21.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20200323222414-85ca7c5b95cd/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20200930185726-fdedc70b468f/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20210124154548-22da62e12c0c/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
+golang.org/x/sys v0.0.0-20210330210617-4fbd30eecc44/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20210420072515-93ed5bcd2bfe/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20210423082822-04245dca01da/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
+golang.org/x/sys v0.0.0-20210510120138-977fb7262007/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.0.0-20210615035016-665e8c7367d1/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.0.0-20211019181941-9d821ace8654/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.0.0-20211105183446-c75c47738b0c/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
@@ -807,19 +803,28 @@ golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a/go.mod h1:oPkhp1MJrh7nUepCBc
golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.1.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
-golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
-golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
+golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
+golang.org/x/sys v0.8.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
+golang.org/x/sys v0.12.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
+golang.org/x/sys v0.13.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
+golang.org/x/sys v0.46.0 h1:noSf2Fq6F8DBgS+LysIkx7rIExoNHJsxOAtPp4rthXw=
+golang.org/x/sys v0.46.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8=
golang.org/x/term v0.5.0/go.mod h1:jMB1sMXY+tzblOD4FWmEbocvup2/aLOaQEp7JmGp78k=
+golang.org/x/term v0.8.0/go.mod h1:xPskH00ivmX89bAKVGSKKtLOWNx2+17Eiy94tnKShWo=
+golang.org/x/term v0.12.0/go.mod h1:owVbMEjm3cBLCHdkQu9b1opXd4ETQWc3BhuQGKgXgvU=
+golang.org/x/term v0.13.0/go.mod h1:LTmsnFJwVN6bCy1rVCoS+qHT1HhALEFxKncY3WNNh4U=
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
golang.org/x/text v0.3.2/go.mod h1:bEr9sfX3Q8Zfm5fL9x+3itogRgK3+ptLWKqgva+5dAk=
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
golang.org/x/text v0.3.6/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ=
golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8=
-golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8=
-golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M=
+golang.org/x/text v0.9.0/go.mod h1:e1OnstbJyHTd6l/uOt8jFFHp6TRDWZR/bV3emEE/zU8=
+golang.org/x/text v0.13.0/go.mod h1:TvPlkZtksWOMsz7fbANvkp4WM8x/WCo/om8BMLbz+aE=
+golang.org/x/text v0.38.0 h1:sXmwo9DwP3OK9EZ7PqAdaooSGozfl/3a6/xJcbzPRhE=
+golang.org/x/text v0.38.0/go.mod h1:YXZt3QhHUKYT53r2lLKFIVi6Ao1jdzrTR/KQ09qyxF4=
golang.org/x/time v0.15.0 h1:bbrp8t3bGUeFOx08pvsMYRTCVSMk89u4tKbNOZbp88U=
golang.org/x/time v0.15.0/go.mod h1:Y4YMaQmXwGQZoFaVFk4YpCt4FLQMYKZe9oeV/f4MSno=
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
@@ -828,11 +833,14 @@ golang.org/x/tools v0.0.0-20200329025819-fd4102a86c65/go.mod h1:Sl4aGygMT6LrqrWc
golang.org/x/tools v0.0.0-20200724022722-7017fd6b1305/go.mod h1:njjCfa9FT2d7l9Bc6FUM5FLjQPp3cFF28FI3qnDFljA=
golang.org/x/tools v0.1.1-0.20210205202024-ef80cdb6ec6d/go.mod h1:9bzcO0MWcOuT0tm1iBGzDVPshzfwoVvREIui8C+MHqU=
golang.org/x/tools v0.1.1-0.20210302220138-2ac05c832e1a/go.mod h1:9bzcO0MWcOuT0tm1iBGzDVPshzfwoVvREIui8C+MHqU=
+golang.org/x/tools v0.1.1/go.mod h1:o0xws9oXOQQZyjljx8fwUC0k7L1pTE6eaCbjGeHmOkk=
golang.org/x/tools v0.1.10/go.mod h1:Uh6Zz+xoGYZom868N8YTex3t7RhtHDBrE8Gzo9bV56E=
golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc=
golang.org/x/tools v0.6.0/go.mod h1:Xwgl3UAJ/d3gWutnCtw505GrjyAbvKui8lOU390QaIU=
-golang.org/x/tools v0.49.0 h1:3NI7VXzL9+1WZD52Dx2ttoPwD5DWrFGpl9mFZDlmisI=
-golang.org/x/tools v0.49.0/go.mod h1:SJNXV9DBKT0UbdttsQjbfJlAE/q+y36++zo3uL3N0Oo=
+golang.org/x/tools v0.13.0/go.mod h1:HvlwmtVNQAhOuCjW7xxvovg8wbNq7LwfXh/k7wXUl58=
+golang.org/x/tools v0.14.0/go.mod h1:uYBEerGOWcJyEORxN+Ek8+TT266gXkNlHdJBwexUsBg=
+golang.org/x/tools v0.45.0 h1:18qN3FAooORvApf5XjCXgsuayZOEtXf6JK18I3+ONa8=
+golang.org/x/tools v0.45.0/go.mod h1:LuUGqqaXcXMEFEruIVJVm5mgDD8vww/z/SR1gQ4uE/0=
golang.org/x/tools/go/expect v0.1.1-deprecated h1:jpBZDwmgPhXsKZC6WhL20P4b/wmnpsEAGHaNy0n/rJM=
golang.org/x/tools/go/expect v0.1.1-deprecated/go.mod h1:eihoPOH+FgIqa3FpoTwguz/bVUSGBlGQU67vpBeOrBY=
golang.org/x/tools/go/packages/packagestest v0.1.1-deprecated h1:1h2MnaIAIXISqTFKdENegdpAgUXz6NrPEsbIeWaBRvM=
@@ -845,18 +853,18 @@ golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da h1:noIWHXmPHxILtqtCOPIhS
golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da/go.mod h1:NDW/Ps6MPRej6fsCIbMTohpP40sJ/P/vI1MoTEGwX90=
gonum.org/v1/gonum v0.17.0 h1:VbpOemQlsSMrYmn7T2OUvQ4dqxQXU+ouZFQsZOx50z4=
gonum.org/v1/gonum v0.17.0/go.mod h1:El3tOrEuMpv2UdMrbNlKEh9vd86bmQ6vqIcDwxEOc1E=
-google.golang.org/api v0.288.0 h1:glhO/J88obKP5I269W3hB73dvBKrjU56ZfmNlNXpgTU=
-google.golang.org/api v0.288.0/go.mod h1:lM2kYRzYUCBY91P9h6VF1PYmvhxii3O5hji37qRvIcY=
-google.golang.org/genproto v0.0.0-20260319201613-d00831a3d3e7 h1:XzmzkmB14QhVhgnawEVsOn6OFsnpyxNPRY9QV01dNB0=
-google.golang.org/genproto v0.0.0-20260319201613-d00831a3d3e7/go.mod h1:L43LFes82YgSonw6iTXTxXUX1OlULt4AQtkik4ULL/I=
-google.golang.org/genproto/googleapis/api v0.0.0-20260630182238-925bb5da69e7 h1:jQ9p21COKWjP3VwuFrNRiiOTMh3mPpN45R7SLrH/HUU=
-google.golang.org/genproto/googleapis/api v0.0.0-20260630182238-925bb5da69e7/go.mod h1:KqHwBx2upmfa1XSi1WuRvC+2VGCLtooKkfmyvRbUmqA=
-google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800 h1:qEHAMpSaUhtD0p3NbEEI83HwNGFxEwaSJ1G9PLnCBZE=
-google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8=
-google.golang.org/grpc v1.82.1 h1:NnAxzGRA0677vCa4BUkOAnO5+FfQqVl9iUXeD0IqcGE=
-google.golang.org/grpc v1.82.1/go.mod h1:yzTZ1TB1Z3SG+LIYaI+WiE8D5+PZ3ArnrSp8zF3+/ZA=
-google.golang.org/protobuf v1.36.12 h1:pJOKDDOyeXErUroCihFAd5LQuwXBSpVnKGrj5o/fwxc=
-google.golang.org/protobuf v1.36.12/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco=
+google.golang.org/api v0.272.0 h1:eLUQZGnAS3OHn31URRf9sAmRk3w2JjMx37d2k8AjJmA=
+google.golang.org/api v0.272.0/go.mod h1:wKjowi5LNJc5qarNvDCvNQBn3rVK8nSy6jg2SwRwzIA=
+google.golang.org/genproto v0.0.0-20260316180232-0b37fe3546d5 h1:JNfk58HZ8lfmXbYK2vx/UvsqIL59TzByCxPIX4TDmsE=
+google.golang.org/genproto v0.0.0-20260316180232-0b37fe3546d5/go.mod h1:x5julN69+ED4PcFk/XWayw35O0lf/nGa4aNgODCmNmw=
+google.golang.org/genproto/googleapis/api v0.0.0-20260316180232-0b37fe3546d5 h1:CogIeEXn4qWYzzQU0QqvYBM8yDF9cFYzDq9ojSpv0Js=
+google.golang.org/genproto/googleapis/api v0.0.0-20260316180232-0b37fe3546d5/go.mod h1:EIQZ5bFCfRQDV4MhRle7+OgjNtZ6P1PiZBgAKuxXu/Y=
+google.golang.org/genproto/googleapis/rpc v0.0.0-20260316180232-0b37fe3546d5 h1:aJmi6DVGGIStN9Mobk/tZOOQUBbj0BPjZjjnOdoZKts=
+google.golang.org/genproto/googleapis/rpc v0.0.0-20260316180232-0b37fe3546d5/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8=
+google.golang.org/grpc v1.81.1 h1:VnnIIZ88UzOOKLukQi+ImGz8O1Wdp8nAGGnvOfEIWQQ=
+google.golang.org/grpc v1.81.1/go.mod h1:xGH9GfzOyMTGIOXBJmXt+BX/V0kcdQbdcuwQ/zNw42I=
+google.golang.org/protobuf v1.36.11 h1:fV6ZwhNocDyBLK0dj+fg8ektcVegBBuEolpbTQyBNVE=
+google.golang.org/protobuf v1.36.11/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco=
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
gopkg.in/check.v1 v1.0.0-20200227125254-8fa46927fb4f/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
@@ -872,22 +880,22 @@ gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C
gopkg.in/yaml.v3 v3.0.0-20200615113413-eeeca48fe776/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
-honnef.co/go/tools v0.8.0 h1:UacpzPr7D6i5BAjTkA7sNVcx4kIbhAZcQ4zYtKiXx68=
-honnef.co/go/tools v0.8.0/go.mod h1:XA+OnlRA9EDh/ukGvXMNSZNKGwFQJ+5dER0ioUkOxks=
-modernc.org/cc/v4 v4.29.1 h1:MKgdCV3WykTSPqpVrnxdEDS0HEd2FHpKZDzxzU5LyeI=
-modernc.org/cc/v4 v4.29.1/go.mod h1:OnovgIhbbMXMu1aISnJ0wvVD1KnW+cAUJkIrAWh+kVI=
-modernc.org/ccgo/v4 v4.34.6 h1:sBgfIwyN0TQ9C5hwIeuqyeAKyMWnbvj2fvpF4L11uzU=
-modernc.org/ccgo/v4 v4.34.6/go.mod h1:SZ8YcN9NG7XVsQYdm6jYBvi8PQP1qi+kqB6OhjqI3Fk=
+honnef.co/go/tools v0.7.0 h1:w6WUp1VbkqPEgLz4rkBzH/CSU6HkoqNLp6GstyTx3lU=
+honnef.co/go/tools v0.7.0/go.mod h1:pm29oPxeP3P82ISxZDgIYeOaf9ta6Pi0EWvCFoLG2vc=
+modernc.org/cc/v4 v4.28.4 h1:Hd/4Es+MBj+/7hSdZaisNyu6bv3V0Dp2MdllyfqaH+c=
+modernc.org/cc/v4 v4.28.4/go.mod h1:OnovgIhbbMXMu1aISnJ0wvVD1KnW+cAUJkIrAWh+kVI=
+modernc.org/ccgo/v4 v4.34.4 h1:OVnSOWQjVKOYkFxoHYB+qQmSHK5gqMqARM+K9DpR/Ws=
+modernc.org/ccgo/v4 v4.34.4/go.mod h1:qdKqE8FNIYyysougB1RX9MxCzp5oJOcQXSobANJ4TuE=
modernc.org/fileutil v1.4.0 h1:j6ZzNTftVS054gi281TyLjHPp6CPHr2KCxEXjEbD6SM=
modernc.org/fileutil v1.4.0/go.mod h1:EqdKFDxiByqxLk8ozOxObDSfcVOv/54xDs/DUHdvCUU=
modernc.org/gc/v2 v2.6.5 h1:nyqdV8q46KvTpZlsw66kWqwXRHdjIlJOhG6kxiV/9xI=
modernc.org/gc/v2 v2.6.5/go.mod h1:YgIahr1ypgfe7chRuJi2gD7DBQiKSLMPgBQe9oIiito=
-modernc.org/gc/v3 v3.1.4 h1:2g65LGVSmFQrXeITAw97x7hCRvZFcyE1uDP+7Vng7JI=
-modernc.org/gc/v3 v3.1.4/go.mod h1:HFK/6AGESC7Ex+EZJhJ2Gni6cTaYpSMmU/cT9RmlfYY=
+modernc.org/gc/v3 v3.1.3 h1:6QAplYyVO+KdPW3pGnqmJDUxtkec8ooEWvks/hhU3lc=
+modernc.org/gc/v3 v3.1.3/go.mod h1:HFK/6AGESC7Ex+EZJhJ2Gni6cTaYpSMmU/cT9RmlfYY=
modernc.org/goabi0 v0.2.0 h1:HvEowk7LxcPd0eq6mVOAEMai46V+i7Jrj13t4AzuNks=
modernc.org/goabi0 v0.2.0/go.mod h1:CEFRnnJhKvWT1c1JTI3Avm+tgOWbkOu5oPA8eH8LnMI=
-modernc.org/libc v1.74.4 h1:fX1Omw4o2/1C2iRkkIsrQTasJQldLhRmuPreXLoWs9k=
-modernc.org/libc v1.74.4/go.mod h1:eeQAS9W3sZeKYMFubydxJpII9ybHWshk+7or7bLG9co=
+modernc.org/libc v1.73.4 h1:+ra4Ui8ngyt8HDcO1FTDPWlkAh6yOdaO2yAoh8MddQA=
+modernc.org/libc v1.73.4/go.mod h1:DXZ3eO8qMCNn2SnmTNCiC71nJ9Rcq3PsnpU6Vc4rWK8=
modernc.org/mathutil v1.7.1 h1:GCZVGXdaN8gTqB1Mf/usp1Y/hSqgI2vAGGP4jZMCxOU=
modernc.org/mathutil v1.7.1/go.mod h1:4p5IwJITfppl0G4sUEDtCr4DthTaT47/N3aT6MhfgJg=
modernc.org/memory v1.11.0 h1:o4QC8aMQzmcwCK3t3Ux/ZHmwFPzE6hf2Y5LbkRs+hbI=
@@ -896,15 +904,15 @@ modernc.org/opt v0.2.0 h1:tGyef5ApycA7FSEOMraay9SaTk5zmbx7Tu+cJs4QKZg=
modernc.org/opt v0.2.0/go.mod h1:03fq9lsNfvkYSfxrfUhZCWPk1lm4cq4N+Bh//bEtgns=
modernc.org/sortutil v1.2.1 h1:+xyoGf15mM3NMlPDnFqrteY07klSFxLElE2PVuWIJ7w=
modernc.org/sortutil v1.2.1/go.mod h1:7ZI3a3REbai7gzCLcotuw9AC4VZVpYMjDzETGsSMqJE=
-modernc.org/sqlite v1.56.0 h1:/D8e2RfFqoy/Zc6PuC76U28zFwmI/sYx1Kjm4yEn9e0=
-modernc.org/sqlite v1.56.0/go.mod h1:yCJ2cmAaIkHQ25oXWrF8H4O1lIfPYPR26yCEDj2P3pQ=
+modernc.org/sqlite v1.53.0 h1:20WG8N9q4ji/dEqGk4uiI0c6OPjSeLTNYGFCc3+7c1M=
+modernc.org/sqlite v1.53.0/go.mod h1:xoEpOIpGrgT48H5iiyt/YXPCZPEzlfmfFwtk8Lklw8s=
modernc.org/strutil v1.2.1 h1:UneZBkQA+DX2Rp35KcM69cSsNES9ly8mQWD71HKlOA0=
modernc.org/strutil v1.2.1/go.mod h1:EHkiggD70koQxjVdSBM3JKM7k6L0FbGE5eymy9i3B9A=
modernc.org/token v1.1.0 h1:Xl7Ap9dKaEs5kLoOQeQmPWevfnk/DM5qcLcYlA8ys6Y=
modernc.org/token v1.1.0/go.mod h1:UGzOrNV1mAFSEB63lOFHIpNRUVMvYTc6yu1SMY/XTDM=
-mvdan.cc/gofumpt v0.11.0 h1:0H01XB95PnN2QgCSR9ELdZyTlJqNZ7181B0BTMh5VZc=
-mvdan.cc/gofumpt v0.11.0/go.mod h1:BeT5wCsOJt6J9zT2MZIOGszjUHzFkn1/l9g6xAzqsXo=
-mvdan.cc/unparam v0.0.0-20260818115549-3f964bcb5673 h1:dEE6li4OPIE54oojY2qaayFS1fSp17G14si0gXRxl0U=
-mvdan.cc/unparam v0.0.0-20260818115549-3f964bcb5673/go.mod h1:62roFV3D3nYOWIXv3PfGO4UYEKAotz2WgLywT87ONd8=
+mvdan.cc/gofumpt v0.9.2 h1:zsEMWL8SVKGHNztrx6uZrXdp7AX8r421Vvp23sz7ik4=
+mvdan.cc/gofumpt v0.9.2/go.mod h1:iB7Hn+ai8lPvofHd9ZFGVg2GOr8sBUw1QUWjNbmIL/s=
+mvdan.cc/unparam v0.0.0-20251027182757-5beb8c8f8f15 h1:ssMzja7PDPJV8FStj7hq9IKiuiKhgz9ErWw+m68e7DI=
+mvdan.cc/unparam v0.0.0-20251027182757-5beb8c8f8f15/go.mod h1:4M5MMXl2kW6fivUT6yRGpLLPNfuGtU2Z0cPvFquGDYU=
sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs=
sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4=
diff --git a/internal/accesslog/accesslog.go b/internal/accesslog/accesslog.go
deleted file mode 100644
index 6a3cb01..0000000
--- a/internal/accesslog/accesslog.go
+++ /dev/null
@@ -1,109 +0,0 @@
-// Package accesslog writes proxy activity as JSON Lines.
-package accesslog
-
-import (
- "context"
- "encoding/json"
- "fmt"
- "net/url"
- "os"
- "sync"
- "time"
-)
-
-const (
- accessLogFileMode os.FileMode = 0o600
-
- // EventRequest identifies the response sent by the proxy to a client.
- EventRequest = "request"
- // EventUpstream identifies one HTTP exchange with an upstream service.
- EventUpstream = "upstream"
-)
-
-type requestIDKey struct{}
-
-// Entry is one proxy activity record.
-type Entry struct {
- Time time.Time `json:"time"`
- Event string `json:"event"`
- RequestID string `json:"request_id,omitempty"`
- Method string `json:"method"`
- Path string `json:"path,omitempty"`
- URL string `json:"url,omitempty"`
- StatusCode int `json:"status_code,omitempty"`
- DurationMS int64 `json:"duration_ms"`
- RemoteAddr string `json:"remote_addr,omitempty"`
- Error string `json:"error,omitempty"`
-}
-
-// Logger appends complete JSON objects to a file, one per line.
-type Logger struct {
- mu sync.Mutex
- file *os.File
- encoder *json.Encoder
-}
-
-// Open opens path for append, creating it with owner-only permissions when needed.
-func Open(path string) (*Logger, error) {
- file, err := os.OpenFile(path, os.O_APPEND|os.O_CREATE|os.O_WRONLY, accessLogFileMode)
- if err != nil {
- return nil, fmt.Errorf("opening access log: %w", err)
- }
-
- return &Logger{
- file: file,
- encoder: json.NewEncoder(file),
- }, nil
-}
-
-// Write appends an entry to the log.
-func (l *Logger) Write(entry Entry) error {
- if entry.Time.IsZero() {
- entry.Time = time.Now().UTC()
- }
-
- l.mu.Lock()
- defer l.mu.Unlock()
-
- if err := l.encoder.Encode(entry); err != nil {
- return fmt.Errorf("writing access log: %w", err)
- }
- return nil
-}
-
-// Close closes the log file after any active writer finishes.
-func (l *Logger) Close() error {
- l.mu.Lock()
- defer l.mu.Unlock()
-
- if err := l.file.Close(); err != nil {
- return fmt.Errorf("closing access log: %w", err)
- }
- return nil
-}
-
-// WithRequestID stores a proxy request ID in ctx.
-func WithRequestID(ctx context.Context, requestID string) context.Context {
- return context.WithValue(ctx, requestIDKey{}, requestID)
-}
-
-// RequestID returns the proxy request ID stored in ctx.
-func RequestID(ctx context.Context) string {
- requestID, _ := ctx.Value(requestIDKey{}).(string)
- return requestID
-}
-
-// URLWithoutSecrets returns a URL without user information, query values, or fragments.
-func URLWithoutSecrets(value *url.URL) string {
- if value == nil {
- return ""
- }
-
- clean := *value
- clean.User = nil
- clean.RawQuery = ""
- clean.ForceQuery = false
- clean.Fragment = ""
- clean.RawFragment = ""
- return clean.String()
-}
diff --git a/internal/accesslog/accesslog_test.go b/internal/accesslog/accesslog_test.go
deleted file mode 100644
index 4e53fa8..0000000
--- a/internal/accesslog/accesslog_test.go
+++ /dev/null
@@ -1,91 +0,0 @@
-package accesslog
-
-import (
- "bufio"
- "context"
- "encoding/json"
- "net/url"
- "os"
- "path/filepath"
- "sync"
- "testing"
-)
-
-func TestLoggerWritesJSONLines(t *testing.T) {
- path := filepath.Join(t.TempDir(), "access.jsonl")
- logger, err := Open(path)
- if err != nil {
- t.Fatal(err)
- }
-
- const entries = 20
- var wg sync.WaitGroup
- for range entries {
- wg.Add(1)
- go func() {
- defer wg.Done()
- if err := logger.Write(Entry{
- Event: EventUpstream,
- RequestID: "request-id",
- Method: "GET",
- URL: "https://registry.example/packages/example",
- StatusCode: 429,
- }); err != nil {
- t.Errorf("Write: %v", err)
- }
- }()
- }
- wg.Wait()
-
- if err := logger.Close(); err != nil {
- t.Fatal(err)
- }
-
- file, err := os.Open(path)
- if err != nil {
- t.Fatal(err)
- }
- defer func() { _ = file.Close() }()
-
- scanner := bufio.NewScanner(file)
- count := 0
- for scanner.Scan() {
- var entry Entry
- if err := json.Unmarshal(scanner.Bytes(), &entry); err != nil {
- t.Fatalf("line %d is not JSON: %v", count+1, err)
- }
- if entry.Time.IsZero() {
- t.Errorf("line %d has no time", count+1)
- }
- if entry.StatusCode != 429 {
- t.Errorf("line %d status_code = %d, want 429", count+1, entry.StatusCode)
- }
- count++
- }
- if err := scanner.Err(); err != nil {
- t.Fatal(err)
- }
- if count != entries {
- t.Errorf("lines = %d, want %d", count, entries)
- }
-}
-
-func TestRequestID(t *testing.T) {
- ctx := WithRequestID(context.Background(), "abc-123")
- if got := RequestID(ctx); got != "abc-123" {
- t.Errorf("RequestID = %q, want %q", got, "abc-123")
- }
-}
-
-func TestURLWithoutSecrets(t *testing.T) {
- value, err := url.Parse("https://user:password@registry.example/package.tgz?token=secret#fragment")
- if err != nil {
- t.Fatal(err)
- }
-
- got := URLWithoutSecrets(value)
- want := "https://registry.example/package.tgz"
- if got != want {
- t.Errorf("URLWithoutSecrets = %q, want %q", got, want)
- }
-}
diff --git a/internal/config/config.go b/internal/config/config.go
index a3dfbc6..16928dc 100644
--- a/internal/config/config.go
+++ b/internal/config/config.go
@@ -54,12 +54,10 @@ import (
"net/url"
"os"
"path/filepath"
- "sort"
"strconv"
"strings"
"time"
- "github.com/git-pkgs/purl"
"gopkg.in/yaml.v3"
)
@@ -91,9 +89,6 @@ type Config struct {
// Log configures logging.
Log LogConfig `json:"log" yaml:"log"`
- // AccessLog configures the JSONL activity log.
- AccessLog AccessLogConfig `json:"access_log" yaml:"access_log"`
-
// Upstream configures upstream registry URLs (optional overrides).
Upstream UpstreamConfig `json:"upstream" yaml:"upstream"`
@@ -115,12 +110,6 @@ type Config struct {
// size return ErrMetadataTooLarge. Default: "100MB".
MetadataMaxSize string `json:"metadata_max_size" yaml:"metadata_max_size"`
- // HTTPTimeout is the timeout for individual upstream HTTP requests made
- // by protocol handlers (metadata fetches, pass-through file requests).
- // Uses Go duration syntax (e.g. "30s", "2m"). Default: "30s".
- // Set to "0" to disable the timeout entirely.
- HTTPTimeout string `json:"http_timeout" yaml:"http_timeout"`
-
// MirrorAPI enables the /api/mirror endpoints for starting mirror jobs via HTTP.
// Disabled by default to prevent unauthenticated users from triggering downloads.
MirrorAPI bool `json:"mirror_api" yaml:"mirror_api"`
@@ -142,38 +131,9 @@ type CooldownConfig struct {
Ecosystems map[string]string `json:"ecosystems" yaml:"ecosystems"`
// Packages overrides the cooldown for specific packages (keyed by PURL).
- // Valid PURL keys are normalized to canonical form before use.
Packages map[string]string `json:"packages" yaml:"packages"`
}
-// NormalizedPackages returns a copy of the package overrides with valid PURL
-// keys in canonical form. An explicitly canonical key wins over an equivalent
-// noncanonical key, and invalid keys are preserved unchanged.
-func (c *CooldownConfig) NormalizedPackages() map[string]string {
- if c == nil || c.Packages == nil {
- return nil
- }
-
- keys := make([]string, 0, len(c.Packages))
- for key := range c.Packages {
- keys = append(keys, key)
- }
- sort.Strings(keys)
-
- normalized := make(map[string]string, len(c.Packages))
- for _, key := range keys {
- canonical := key
- if parsed, err := purl.Parse(key); err == nil {
- canonical = parsed.String()
- }
- if _, exists := normalized[canonical]; exists && key != canonical {
- continue
- }
- normalized[canonical] = c.Packages[key]
- }
- return normalized
-}
-
// StorageConfig configures artifact storage.
type StorageConfig struct {
// URL is the storage backend URL.
@@ -283,12 +243,6 @@ type LogConfig struct {
Format string `json:"format" yaml:"format"`
}
-// AccessLogConfig configures the JSONL activity log.
-type AccessLogConfig struct {
- // Path is the file to append activity records to. Empty disables the access log.
- Path string `json:"path" yaml:"path"`
-}
-
// UpstreamConfig configures upstream registry URLs and authentication.
// Leave empty to use defaults.
type UpstreamConfig struct {
@@ -313,45 +267,24 @@ type UpstreamConfig struct {
// Default: https://static.crates.io/crates
CargoDownload string `json:"cargo_download" yaml:"cargo_download"`
- // Debian is the upstream APT repository base URL.
- // Example: http://archive.ubuntu.com/ubuntu would get Ubuntu.
- // Default: http://deb.debian.org/debian
- Debian string `json:"debian" yaml:"debian"`
-
- // Helm maps repository names to HTTP Helm chart repository URLs.
- // Requests use /helm/{name}/index.yaml and chart URLs in the index are
- // rewritten to the same named proxy endpoint.
- Helm map[string]string `json:"helm" yaml:"helm"`
-
- // OCI maps names to OCI registry URLs. Requests to a named registry use
- // the repository prefix upstream/{name}/, for example
- // oci://proxy.example.com/upstream/ghcr/owner/chart.
- OCI map[string]string `json:"oci" yaml:"oci"`
-
// Auth configures authentication for upstream registries.
- // Keys are absolute URL scopes matched by scheme, host, effective port,
- // and path-segment prefix.
+ // Keys are URL prefixes that are matched against request URLs.
// Example: "https://npm.pkg.github.com" matches all requests to that host.
Auth map[string]AuthConfig `json:"auth" yaml:"auth"`
}
// AuthForURL returns the auth config that matches the given URL.
-// The longest matching URL scope wins.
+// Matches are based on URL prefix - the longest matching prefix wins.
func (u *UpstreamConfig) AuthForURL(url string) *AuthConfig {
if u.Auth == nil {
return nil
}
- target, err := parseAuthURL(url)
- if err != nil {
- return nil
- }
var bestMatch *AuthConfig
var bestLen int
for pattern, auth := range u.Auth {
- configured, err := parseAuthURL(pattern)
- if err == nil && authURLMatches(configured, target) && len(pattern) > bestLen {
+ if strings.HasPrefix(url, pattern) && len(pattern) > bestLen {
a := auth // copy to avoid loop variable capture
bestMatch = &a
bestLen = len(pattern)
@@ -361,73 +294,6 @@ func (u *UpstreamConfig) AuthForURL(url string) *AuthConfig {
return bestMatch
}
-// Validate checks upstream authentication URL scopes.
-func (u *UpstreamConfig) Validate() error {
- for pattern := range u.Auth {
- if _, err := parseAuthURL(pattern); err != nil {
- return fmt.Errorf("invalid upstream.auth URL %q: %w", pattern, err)
- }
- }
- if err := validateNamedUpstreams("upstream.helm", u.Helm); err != nil {
- return err
- }
- if err := validateNamedUpstreams("upstream.oci", u.OCI); err != nil {
- return err
- }
- return nil
-}
-
-func validateNamedUpstreams(field string, upstreams map[string]string) error {
- for name, upstreamURL := range upstreams {
- if name == "" || name == "." || name == ".." || strings.ContainsAny(name, `/\\`) {
- return fmt.Errorf("invalid %s name %q", field, name)
- }
- if err := validateAbsoluteURL(field+"."+name, upstreamURL); err != nil {
- return err
- }
- }
- return nil
-}
-
-func parseAuthURL(value string) (*url.URL, error) {
- parsed, err := url.Parse(value)
- if err != nil || !parsed.IsAbs() || parsed.Hostname() == "" || parsed.Opaque != "" {
- return nil, fmt.Errorf("invalid authentication URL")
- }
- return parsed, nil
-}
-
-func authURLMatches(configured, target *url.URL) bool {
- if !strings.EqualFold(configured.Scheme, target.Scheme) ||
- !strings.EqualFold(configured.Hostname(), target.Hostname()) ||
- authURLPort(configured) != authURLPort(target) {
- return false
- }
- if configured.RawQuery != "" && configured.RawQuery != target.RawQuery {
- return false
- }
-
- configuredPath := strings.TrimSuffix(configured.EscapedPath(), "/")
- if configuredPath == "" {
- return true
- }
- targetPath := strings.TrimSuffix(target.EscapedPath(), "/")
- return targetPath == configuredPath || strings.HasPrefix(targetPath, configuredPath+"/")
-}
-
-func authURLPort(value *url.URL) string {
- if port := value.Port(); port != "" {
- return port
- }
- if strings.EqualFold(value.Scheme, "https") {
- return "443"
- }
- if strings.EqualFold(value.Scheme, "http") {
- return "80"
- }
- return ""
-}
-
// AuthConfig configures authentication for an upstream registry.
type AuthConfig struct {
// Type is the authentication type: "bearer", "basic", or "header".
@@ -475,7 +341,6 @@ func Default() *Config {
GradlePluginPortal: "https://plugins.gradle.org/m2",
Cargo: "https://index.crates.io",
CargoDownload: "https://static.crates.io/crates",
- Debian: "http://deb.debian.org/debian",
},
Gradle: GradleConfig{
BuildCache: GradleBuildCacheConfig{
@@ -520,21 +385,6 @@ func Load(path string) (*Config, error) {
return cfg, nil
}
-// setEnvString sets *dst from the named environment variable, leaving it
-// untouched if the variable is unset or empty.
-func setEnvString(dst *string, key string) {
- if v := os.Getenv(key); v != "" {
- *dst = v
- }
-}
-
-// setEnvBool is setEnvString for boolean fields, parsed via envBool.
-func setEnvBool(dst *bool, key string) {
- if v := os.Getenv(key); v != "" {
- *dst = envBool(v)
- }
-}
-
// LoadFromEnv applies environment variable overrides to a Config.
// Environment variables use the PROXY_ prefix:
// - PROXY_LISTEN
@@ -545,39 +395,89 @@ func setEnvBool(dst *bool, key string) {
// - PROXY_DATABASE_PATH
// - PROXY_LOG_LEVEL
// - PROXY_LOG_FORMAT
-// - PROXY_ACCESS_LOG_PATH
// - PROXY_HEALTH_STORAGE_PROBE_INTERVAL
func (c *Config) LoadFromEnv() {
- setEnvString(&c.Listen, "PROXY_LISTEN")
- setEnvString(&c.BaseURL, "PROXY_BASE_URL")
- setEnvString(&c.UIBaseURL, "PROXY_UI_URL")
- setEnvString(&c.Storage.URL, "PROXY_STORAGE_URL")
- setEnvString(&c.Storage.Path, "PROXY_STORAGE_PATH")
- setEnvString(&c.Storage.MaxSize, "PROXY_STORAGE_MAX_SIZE")
- setEnvBool(&c.Storage.DirectServe, "PROXY_STORAGE_DIRECT_SERVE")
- setEnvString(&c.Storage.DirectServeTTL, "PROXY_STORAGE_DIRECT_SERVE_TTL")
- setEnvString(&c.Storage.DirectServeBaseURL, "PROXY_STORAGE_DIRECT_SERVE_BASE_URL")
- setEnvString(&c.Database.Driver, "PROXY_DATABASE_DRIVER")
- setEnvString(&c.Database.Path, "PROXY_DATABASE_PATH")
- setEnvString(&c.Database.URL, "PROXY_DATABASE_URL")
- setEnvString(&c.Log.Level, "PROXY_LOG_LEVEL")
- setEnvString(&c.Log.Format, "PROXY_LOG_FORMAT")
- setEnvString(&c.AccessLog.Path, "PROXY_ACCESS_LOG_PATH")
- setEnvString(&c.Upstream.Maven, "PROXY_UPSTREAM_MAVEN")
- setEnvString(&c.Upstream.GradlePluginPortal, "PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL")
- setEnvString(&c.Upstream.Debian, "PROXY_UPSTREAM_DEBIAN")
- setEnvString(&c.Cooldown.Default, "PROXY_COOLDOWN_DEFAULT")
- setEnvBool(&c.CacheMetadata, "PROXY_CACHE_METADATA")
- setEnvBool(&c.MirrorAPI, "PROXY_MIRROR_API")
- setEnvString(&c.MetadataTTL, "PROXY_METADATA_TTL")
- setEnvString(&c.MetadataMaxSize, "PROXY_METADATA_MAX_SIZE")
- setEnvString(&c.HTTPTimeout, "PROXY_HTTP_TIMEOUT")
- setEnvBool(&c.Gradle.BuildCache.ReadOnly, "PROXY_GRADLE_BUILD_CACHE_READ_ONLY")
- setEnvString(&c.Gradle.BuildCache.MaxUploadSize, "PROXY_GRADLE_BUILD_CACHE_MAX_UPLOAD_SIZE")
- setEnvString(&c.Gradle.BuildCache.MaxAge, "PROXY_GRADLE_BUILD_CACHE_MAX_AGE")
- setEnvString(&c.Gradle.BuildCache.MaxSize, "PROXY_GRADLE_BUILD_CACHE_MAX_SIZE")
- setEnvString(&c.Gradle.BuildCache.SweepInterval, "PROXY_GRADLE_BUILD_CACHE_SWEEP_INTERVAL")
- setEnvString(&c.Health.StorageProbeInterval, "PROXY_HEALTH_STORAGE_PROBE_INTERVAL")
+ if v := os.Getenv("PROXY_LISTEN"); v != "" {
+ c.Listen = v
+ }
+ if v := os.Getenv("PROXY_BASE_URL"); v != "" {
+ c.BaseURL = v
+ }
+ if v := os.Getenv("PROXY_UI_URL"); v != "" {
+ c.UIBaseURL = v
+ }
+ if v := os.Getenv("PROXY_STORAGE_URL"); v != "" {
+ c.Storage.URL = v
+ }
+ if v := os.Getenv("PROXY_STORAGE_PATH"); v != "" {
+ c.Storage.Path = v
+ }
+ if v := os.Getenv("PROXY_STORAGE_MAX_SIZE"); v != "" {
+ c.Storage.MaxSize = v
+ }
+ if v := os.Getenv("PROXY_STORAGE_DIRECT_SERVE"); v != "" {
+ c.Storage.DirectServe = envBool(v)
+ }
+ if v := os.Getenv("PROXY_STORAGE_DIRECT_SERVE_TTL"); v != "" {
+ c.Storage.DirectServeTTL = v
+ }
+ if v := os.Getenv("PROXY_STORAGE_DIRECT_SERVE_BASE_URL"); v != "" {
+ c.Storage.DirectServeBaseURL = v
+ }
+ if v := os.Getenv("PROXY_DATABASE_DRIVER"); v != "" {
+ c.Database.Driver = v
+ }
+ if v := os.Getenv("PROXY_DATABASE_PATH"); v != "" {
+ c.Database.Path = v
+ }
+ if v := os.Getenv("PROXY_DATABASE_URL"); v != "" {
+ c.Database.URL = v
+ }
+ if v := os.Getenv("PROXY_LOG_LEVEL"); v != "" {
+ c.Log.Level = v
+ }
+ if v := os.Getenv("PROXY_LOG_FORMAT"); v != "" {
+ c.Log.Format = v
+ }
+ if v := os.Getenv("PROXY_UPSTREAM_MAVEN"); v != "" {
+ c.Upstream.Maven = v
+ }
+ if v := os.Getenv("PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL"); v != "" {
+ c.Upstream.GradlePluginPortal = v
+ }
+ if v := os.Getenv("PROXY_COOLDOWN_DEFAULT"); v != "" {
+ c.Cooldown.Default = v
+ }
+ if v := os.Getenv("PROXY_CACHE_METADATA"); v != "" {
+ c.CacheMetadata = envBool(v)
+ }
+ if v := os.Getenv("PROXY_MIRROR_API"); v != "" {
+ c.MirrorAPI = envBool(v)
+ }
+ if v := os.Getenv("PROXY_METADATA_TTL"); v != "" {
+ c.MetadataTTL = v
+ }
+ if v := os.Getenv("PROXY_METADATA_MAX_SIZE"); v != "" {
+ c.MetadataMaxSize = v
+ }
+ if v := os.Getenv("PROXY_GRADLE_BUILD_CACHE_READ_ONLY"); v != "" {
+ c.Gradle.BuildCache.ReadOnly = v == "true" || v == "1"
+ }
+ if v := os.Getenv("PROXY_GRADLE_BUILD_CACHE_MAX_UPLOAD_SIZE"); v != "" {
+ c.Gradle.BuildCache.MaxUploadSize = v
+ }
+ if v := os.Getenv("PROXY_GRADLE_BUILD_CACHE_MAX_AGE"); v != "" {
+ c.Gradle.BuildCache.MaxAge = v
+ }
+ if v := os.Getenv("PROXY_GRADLE_BUILD_CACHE_MAX_SIZE"); v != "" {
+ c.Gradle.BuildCache.MaxSize = v
+ }
+ if v := os.Getenv("PROXY_GRADLE_BUILD_CACHE_SWEEP_INTERVAL"); v != "" {
+ c.Gradle.BuildCache.SweepInterval = v
+ }
+ if v := os.Getenv("PROXY_HEALTH_STORAGE_PROBE_INTERVAL"); v != "" {
+ c.Health.StorageProbeInterval = v
+ }
}
// validateAbsoluteURL returns an error if value is not a parseable URL with
@@ -667,23 +567,15 @@ func (c *Config) Validate() error {
return err
}
- if err := validateHTTPTimeout(c.HTTPTimeout); err != nil {
- return err
- }
-
- return c.validateComponents()
-}
-
-func (c *Config) validateComponents() error {
- if err := c.Upstream.Validate(); err != nil {
- return err
- }
-
if err := c.Health.Validate(); err != nil {
return err
}
- return c.Gradle.BuildCache.Validate()
+ if err := c.Gradle.BuildCache.Validate(); err != nil {
+ return err
+ }
+
+ return nil
}
// Validate checks the /health configuration. An unset interval is allowed
@@ -744,7 +636,6 @@ func (g *GradleBuildCacheConfig) Validate() error {
const (
defaultMetadataTTL = 5 * time.Minute //nolint:mnd // sensible default
defaultDirectServeTTL = 15 * time.Minute //nolint:mnd // sensible default
- defaultHTTPTimeout = 30 * time.Second //nolint:mnd // sensible default
defaultMetadataMaxSize = 100 << 20
defaultGradleBuildCacheMaxUploadSize = 100 << 20
defaultGradleBuildCacheSweepInterval = 10 * time.Minute
@@ -765,20 +656,6 @@ func (c *Config) ParseMaxSize() int64 {
return size
}
-func validateHTTPTimeout(s string) error {
- if s == "" || s == "0" {
- return nil
- }
- d, err := time.ParseDuration(s)
- if err != nil {
- return fmt.Errorf("invalid http_timeout %q: %w", s, err)
- }
- if d < 0 {
- return fmt.Errorf("invalid http_timeout %q: must be non-negative", s)
- }
- return nil
-}
-
func validateMetadataMaxSize(s string) error {
if s == "" {
return nil
@@ -806,22 +683,6 @@ func (c *Config) ParseMetadataMaxSize() int64 {
return size
}
-// ParseHTTPTimeout returns the upstream HTTP client timeout.
-// Returns 30s if unset, 0 (no timeout) if explicitly set to "0".
-func (c *Config) ParseHTTPTimeout() time.Duration {
- if c.HTTPTimeout == "" {
- return defaultHTTPTimeout
- }
- if c.HTTPTimeout == "0" {
- return 0
- }
- d, err := time.ParseDuration(c.HTTPTimeout)
- if err != nil || d < 0 {
- return defaultHTTPTimeout
- }
- return d
-}
-
// ParseMetadataTTL returns the metadata TTL duration.
// Returns 5 minutes if unset, 0 if explicitly disabled.
func (c *Config) ParseMetadataTTL() time.Duration {
@@ -928,7 +789,8 @@ func ParseSize(s string) (int64, error) {
}
for _, s2 := range suffixes {
- if numStr, ok := strings.CutSuffix(s, s2.suffix); ok {
+ if strings.HasSuffix(s, s2.suffix) {
+ numStr := strings.TrimSuffix(s, s2.suffix)
num, err := strconv.ParseFloat(numStr, 64)
if err != nil {
return 0, fmt.Errorf("invalid number %q", numStr)
diff --git a/internal/config/config_test.go b/internal/config/config_test.go
index 0ccc308..bb3ec74 100644
--- a/internal/config/config_test.go
+++ b/internal/config/config_test.go
@@ -3,7 +3,6 @@ package config
import (
"os"
"path/filepath"
- "strings"
"testing"
"time"
)
@@ -26,9 +25,6 @@ func TestDefault(t *testing.T) {
if cfg.Database.Path == "" {
t.Error("Database.Path should not be empty")
}
- if cfg.AccessLog.Path != "" {
- t.Errorf("AccessLog.Path = %q, want disabled by default", cfg.AccessLog.Path)
- }
if cfg.Gradle.BuildCache.MaxUploadSize != "100MB" {
t.Errorf("Gradle.BuildCache.MaxUploadSize = %q, want %q", cfg.Gradle.BuildCache.MaxUploadSize, "100MB")
}
@@ -41,9 +37,6 @@ func TestDefault(t *testing.T) {
if cfg.Upstream.GradlePluginPortal != "https://plugins.gradle.org/m2" {
t.Errorf("Upstream.GradlePluginPortal = %q, want %q", cfg.Upstream.GradlePluginPortal, "https://plugins.gradle.org/m2")
}
- if cfg.Upstream.Debian != "http://deb.debian.org/debian" {
- t.Errorf("Upstream.Debian = %q, want %q", cfg.Upstream.Debian, "http://deb.debian.org/debian")
- }
}
func TestValidate(t *testing.T) {
@@ -215,8 +208,6 @@ database:
log:
level: "debug"
format: "json"
-access_log:
- path: "/var/log/proxy/access.jsonl"
`
if err := os.WriteFile(path, []byte(content), 0644); err != nil {
t.Fatalf("writing config file: %v", err)
@@ -245,9 +236,6 @@ access_log:
if cfg.Log.Format != "json" {
t.Errorf("Log.Format = %q, want %q", cfg.Log.Format, "json")
}
- if cfg.AccessLog.Path != "/var/log/proxy/access.jsonl" {
- t.Errorf("AccessLog.Path = %q, want %q", cfg.AccessLog.Path, "/var/log/proxy/access.jsonl")
- }
}
func TestLoadJSON(t *testing.T) {
@@ -283,10 +271,8 @@ func TestLoadFromEnv(t *testing.T) {
t.Setenv("PROXY_UI_URL", "https://ui.env.example.com/ui")
t.Setenv("PROXY_STORAGE_PATH", "/env/cache")
t.Setenv("PROXY_LOG_LEVEL", testLevelDebug)
- t.Setenv("PROXY_ACCESS_LOG_PATH", "/tmp/proxy-access.jsonl")
t.Setenv("PROXY_UPSTREAM_MAVEN", "https://maven.example.com/repository/maven-public")
t.Setenv("PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL", "https://plugins.example.com/m2")
- t.Setenv("PROXY_UPSTREAM_DEBIAN", "http://archive.ubuntu.com/ubuntu")
t.Setenv("PROXY_GRADLE_BUILD_CACHE_READ_ONLY", "true")
t.Setenv("PROXY_GRADLE_BUILD_CACHE_MAX_UPLOAD_SIZE", "32MB")
t.Setenv("PROXY_GRADLE_BUILD_CACHE_MAX_AGE", "12h")
@@ -310,18 +296,12 @@ func TestLoadFromEnv(t *testing.T) {
if cfg.Log.Level != testLevelDebug {
t.Errorf("Log.Level = %q, want %q", cfg.Log.Level, testLevelDebug)
}
- if cfg.AccessLog.Path != "/tmp/proxy-access.jsonl" {
- t.Errorf("AccessLog.Path = %q, want %q", cfg.AccessLog.Path, "/tmp/proxy-access.jsonl")
- }
if cfg.Upstream.Maven != "https://maven.example.com/repository/maven-public" {
t.Errorf("Upstream.Maven = %q, want %q", cfg.Upstream.Maven, "https://maven.example.com/repository/maven-public")
}
if cfg.Upstream.GradlePluginPortal != "https://plugins.example.com/m2" {
t.Errorf("Upstream.GradlePluginPortal = %q, want %q", cfg.Upstream.GradlePluginPortal, "https://plugins.example.com/m2")
}
- if cfg.Upstream.Debian != "http://archive.ubuntu.com/ubuntu" {
- t.Errorf("Upstream.Debian = %q, want %q", cfg.Upstream.Debian, "http://archive.ubuntu.com/ubuntu")
- }
if !cfg.Gradle.BuildCache.ReadOnly {
t.Error("Gradle.BuildCache.ReadOnly = false, want true")
}
@@ -383,34 +363,6 @@ cooldown:
if cfg.Cooldown.Packages["pkg:npm/@babel/core"] != "14d" {
t.Errorf("Cooldown.Packages[@babel/core] = %q, want %q", cfg.Cooldown.Packages["pkg:npm/@babel/core"], "14d")
}
- if got := cfg.Cooldown.NormalizedPackages()["pkg:npm/%40babel/core"]; got != "14d" {
- t.Errorf("normalized Cooldown.Packages[@babel/core] = %q, want %q", got, "14d")
- }
-}
-
-func TestCooldownConfigNormalizedPackages(t *testing.T) {
- rawScoped := "pkg:npm/@typescript/typescript-darwin-arm64"
- canonicalScoped := "pkg:npm/%40typescript/typescript-darwin-arm64"
- cfg := CooldownConfig{Packages: map[string]string{
- rawScoped: "2d",
- canonicalScoped: "3d",
- "not-a-purl": "4d",
- }}
-
- got := cfg.NormalizedPackages()
-
- if got[canonicalScoped] != "3d" {
- t.Errorf("canonical scoped package duration = %q, want %q", got[canonicalScoped], "3d")
- }
- if _, exists := got[rawScoped]; exists {
- t.Errorf("raw scoped package key %q was not canonicalized", rawScoped)
- }
- if got["not-a-purl"] != "4d" {
- t.Errorf("invalid PURL duration = %q, want preserved value %q", got["not-a-purl"], "4d")
- }
- if cfg.Packages[rawScoped] != "2d" {
- t.Error("NormalizedPackages mutated the source map")
- }
}
func TestLoadCooldownFromEnv(t *testing.T) {
@@ -572,69 +524,6 @@ func TestValidateHealthStorageProbeInterval(t *testing.T) {
}
}
-func TestParseHTTPTimeout(t *testing.T) {
- tests := []struct {
- name string
- timeout string
- want time.Duration
- }{
- {"empty defaults to 30s", "", 30 * time.Second},
- {"explicit zero disables", "0", 0},
- {"2 minutes", "2m", 2 * time.Minute},
- {"90 seconds", "90s", 90 * time.Second},
- {"invalid defaults to 30s", "not-a-duration", 30 * time.Second},
- }
-
- for _, tt := range tests {
- t.Run(tt.name, func(t *testing.T) {
- cfg := Default()
- cfg.HTTPTimeout = tt.timeout
- got := cfg.ParseHTTPTimeout()
- if got != tt.want {
- t.Errorf("ParseHTTPTimeout() = %v, want %v", got, tt.want)
- }
- })
- }
-}
-
-func TestValidateHTTPTimeout(t *testing.T) {
- cfg := Default()
- cfg.HTTPTimeout = "not-a-duration"
- if err := cfg.Validate(); err == nil {
- t.Error("expected validation error for invalid http_timeout")
- }
-
- cfg.HTTPTimeout = "-5s"
- if err := cfg.Validate(); err == nil {
- t.Error("expected validation error for negative http_timeout")
- }
-
- cfg.HTTPTimeout = "2m"
- if err := cfg.Validate(); err != nil {
- t.Errorf("unexpected error for valid http_timeout: %v", err)
- }
-
- cfg.HTTPTimeout = "0"
- if err := cfg.Validate(); err != nil {
- t.Errorf("unexpected error for zero http_timeout: %v", err)
- }
-
- cfg.HTTPTimeout = ""
- if err := cfg.Validate(); err != nil {
- t.Errorf("unexpected error for empty http_timeout: %v", err)
- }
-}
-
-func TestLoadHTTPTimeoutFromEnv(t *testing.T) {
- cfg := Default()
- t.Setenv("PROXY_HTTP_TIMEOUT", "90s")
- cfg.LoadFromEnv()
-
- if cfg.HTTPTimeout != "90s" {
- t.Errorf("HTTPTimeout = %q, want %q", cfg.HTTPTimeout, "90s")
- }
-}
-
func TestLoadMetadataTTLFromEnv(t *testing.T) {
cfg := Default()
t.Setenv("PROXY_METADATA_TTL", "10m")
@@ -808,114 +697,3 @@ func TestDatabaseConfigString(t *testing.T) {
}
}
}
-
-func TestUpstreamAuthForURLMatchesURLComponents(t *testing.T) {
- registryAuth := AuthConfig{Type: "bearer", Token: "registry-token"}
- privateAuth := AuthConfig{Type: "bearer", Token: "private-token"}
- config := UpstreamConfig{Auth: map[string]AuthConfig{
- "https://registry.example.com": registryAuth,
- "https://registry.example.com/private": privateAuth,
- }}
-
- tests := []struct {
- name string
- url string
- wantToken string
- }{
- {name: "registry root", url: "https://registry.example.com/package", wantToken: "registry-token"},
- {name: "host is case insensitive", url: "https://REGISTRY.EXAMPLE.COM/package", wantToken: "registry-token"},
- {name: "longest path match", url: "https://registry.example.com/private/package", wantToken: "private-token"},
- {name: "exact path match", url: "https://registry.example.com/private", wantToken: "private-token"},
- {name: "path segment boundary", url: "https://registry.example.com/private-other/package", wantToken: "registry-token"},
- {name: "lookalike host rejected", url: "https://registry.example.com.evil.test/package"},
- {name: "different scheme rejected", url: "http://registry.example.com/package"},
- {name: "different port rejected", url: "https://registry.example.com:8443/package"},
- }
-
- for _, tt := range tests {
- t.Run(tt.name, func(t *testing.T) {
- auth := config.AuthForURL(tt.url)
- if tt.wantToken == "" {
- if auth != nil {
- t.Fatalf("AuthForURL() = %+v, want nil", auth)
- }
- return
- }
- if auth == nil {
- t.Fatal("AuthForURL() = nil, want authentication")
- }
- if auth.Token != tt.wantToken {
- t.Errorf("token = %q, want %q", auth.Token, tt.wantToken)
- }
- })
- }
-}
-
-func TestValidateUpstreamAuthURLs(t *testing.T) {
- t.Run("valid absolute URL", func(t *testing.T) {
- cfg := Default()
- cfg.Upstream.Auth = map[string]AuthConfig{
- "https://registry.example.com/private": {Type: "bearer", Token: "token"},
- }
-
- if err := cfg.Validate(); err != nil {
- t.Fatalf("Validate() error = %v", err)
- }
- })
-
- t.Run("invalid URL", func(t *testing.T) {
- cfg := Default()
- cfg.Upstream.Auth = map[string]AuthConfig{
- "registry.example.com": {Type: "bearer", Token: "token"},
- }
-
- err := cfg.Validate()
- if err == nil {
- t.Fatal("Validate() error = nil, want invalid upstream.auth URL error")
- }
- if !strings.Contains(err.Error(), "upstream.auth") || !strings.Contains(err.Error(), "registry.example.com") {
- t.Errorf("Validate() error = %q, want field and URL", err)
- }
- })
-}
-
-func TestValidateNamedUpstreams(t *testing.T) {
- tests := []struct {
- name string
- modify func(*Config)
- wantErr bool
- }{
- {
- name: "valid Helm and OCI upstreams",
- modify: func(cfg *Config) {
- cfg.Upstream.Helm = map[string]string{"bitnami": "https://charts.bitnami.com/bitnami"}
- cfg.Upstream.OCI = map[string]string{"ghcr": "https://ghcr.io"}
- },
- },
- {
- name: "Helm upstream name contains path separator",
- modify: func(cfg *Config) {
- cfg.Upstream.Helm = map[string]string{"team/charts": "https://charts.example.com"}
- },
- wantErr: true,
- },
- {
- name: "OCI upstream URL is not absolute",
- modify: func(cfg *Config) {
- cfg.Upstream.OCI = map[string]string{"private": "registry.example.com"}
- },
- wantErr: true,
- },
- }
-
- for _, tt := range tests {
- t.Run(tt.name, func(t *testing.T) {
- cfg := Default()
- tt.modify(cfg)
- err := cfg.Validate()
- if (err != nil) != tt.wantErr {
- t.Errorf("Validate() error = %v, wantErr %t", err, tt.wantErr)
- }
- })
- }
-}
diff --git a/internal/database/database_test.go b/internal/database/database_test.go
index bb2b195..6fca4ea 100644
--- a/internal/database/database_test.go
+++ b/internal/database/database_test.go
@@ -8,11 +8,6 @@ import (
"time"
)
-const (
- testContentHash = "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
- testIntegrity = "sha512-z4PhNX7vuL3xVChQ1m2AB9Yg5AULVxXcg/SpIdNs6c5H0NE8XYXysP+DGNKHfuwvY7kxvUdBeoGlODJ6+SfaPg=="
-)
-
func TestCreateAndOpen(t *testing.T) {
dir := t.TempDir()
dbPath := filepath.Join(dir, "test.db")
@@ -137,7 +132,7 @@ func TestVersionCRUD(t *testing.T) {
v := &Version{
PURL: "pkg:npm/lodash@4.17.21",
PackagePURL: "pkg:npm/lodash",
- Integrity: sql.NullString{String: testIntegrity, Valid: true},
+ Integrity: sql.NullString{String: "sha512-abc123", Valid: true},
}
err = db.UpsertVersion(v)
@@ -205,7 +200,7 @@ func TestArtifactCRUD(t *testing.T) {
t.Error("expected artifact to not be cached yet")
}
- err = db.MarkArtifactCached(versionPURL, "lodash-4.17.21.tgz", "/cache/npm/lodash-4.17.21.tgz", testContentHash, 12345, "application/gzip")
+ err = db.MarkArtifactCached(versionPURL, "lodash-4.17.21.tgz", "/cache/npm/lodash-4.17.21.tgz", "sha256-abc", 12345, "application/gzip")
if err != nil {
t.Fatalf("MarkArtifactCached failed: %v", err)
}
@@ -244,86 +239,6 @@ func TestArtifactCRUD(t *testing.T) {
})
}
-func TestGetCachedArtifact(t *testing.T) {
- runWithBothDatabases(t, func(t *testing.T, db *DB) {
- const (
- packagePURL = "pkg:npm/lodash"
- versionPURL = "pkg:npm/lodash@4.17.21"
- filename = "lodash-4.17.21.tgz"
- )
- seedCachedArtifactTestData(t, db, packagePURL, versionPURL, filename)
-
- cached, err := db.GetCachedArtifact(packagePURL, versionPURL, filename)
- if err != nil {
- t.Fatalf("GetCachedArtifact before cache failed: %v", err)
- }
- if cached != nil {
- t.Fatalf("expected no cached artifact, got %+v", cached)
- }
-
- if err := db.MarkArtifactCached(versionPURL, filename, "/cache/npm/"+filename,
- testContentHash, 12345, "application/gzip"); err != nil {
- t.Fatalf("MarkArtifactCached failed: %v", err)
- }
-
- cached, err = db.GetCachedArtifact(packagePURL, versionPURL, filename)
- if err != nil {
- t.Fatalf("GetCachedArtifact failed: %v", err)
- }
- if cached == nil {
- t.Fatal("expected cached artifact, got nil")
- }
- if cached.Ecosystem != "npm" {
- t.Errorf("expected npm ecosystem, got %q", cached.Ecosystem)
- }
- if cached.StoragePath != "/cache/npm/"+filename {
- t.Errorf("expected cached storage path, got %q", cached.StoragePath)
- }
- if cached.ContentHash.String != testContentHash {
- t.Errorf("expected cached content hash, got %q", cached.ContentHash.String)
- }
- if cached.Size.Int64 != 12345 {
- t.Errorf("expected cached size 12345, got %d", cached.Size.Int64)
- }
- if cached.ContentType.String != "application/gzip" {
- t.Errorf("expected cached content type, got %q", cached.ContentType.String)
- }
- if cached.Integrity.String != testIntegrity {
- t.Errorf("expected cached integrity, got %q", cached.Integrity.String)
- }
-
- cached, err = db.GetCachedArtifact("pkg:npm/other", versionPURL, filename)
- if err != nil {
- t.Fatalf("GetCachedArtifact with wrong package failed: %v", err)
- }
- if cached != nil {
- t.Fatalf("expected package mismatch to miss cache, got %+v", cached)
- }
- })
-}
-
-func seedCachedArtifactTestData(t *testing.T, db *DB, packagePURL, versionPURL, filename string) {
- t.Helper()
-
- if err := db.UpsertPackage(&Package{PURL: packagePURL, Ecosystem: "npm", Name: "lodash"}); err != nil {
- t.Fatalf("UpsertPackage failed: %v", err)
- }
- if err := db.UpsertVersion(&Version{
- PURL: versionPURL,
- PackagePURL: packagePURL,
- Integrity: sql.NullString{String: testIntegrity, Valid: true},
- }); err != nil {
- t.Fatalf("UpsertVersion failed: %v", err)
- }
- if err := db.UpsertArtifact(&Artifact{
- VersionPURL: versionPURL,
- Filename: filename,
- UpstreamURL: "https://registry.npmjs.org/lodash/-/" + filename,
- }); err != nil {
- t.Fatalf("UpsertArtifact failed: %v", err)
- }
-}
-
func TestCacheManagement(t *testing.T) {
runWithBothDatabases(t, func(t *testing.T, db *DB) {
pkg := &Package{
diff --git a/internal/database/metadata_cache_test.go b/internal/database/metadata_cache_test.go
index 09dcba3..5701816 100644
--- a/internal/database/metadata_cache_test.go
+++ b/internal/database/metadata_cache_test.go
@@ -30,12 +30,8 @@ func TestUpsertAndGetMetadataCache(t *testing.T) {
StoragePath: "_metadata/npm/lodash/metadata",
ETag: sql.NullString{String: `"abc123"`, Valid: true},
ContentType: sql.NullString{String: "application/json", Valid: true},
- ContentDigest: sql.NullString{
- String: "sha256:0123456789abcdef",
- Valid: true,
- },
- Size: sql.NullInt64{Int64: 1024, Valid: true},
- FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
+ Size: sql.NullInt64{Int64: 1024, Valid: true},
+ FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
}
err := db.UpsertMetadataCache(entry)
@@ -66,9 +62,6 @@ func TestUpsertAndGetMetadataCache(t *testing.T) {
if !got.ContentType.Valid || got.ContentType.String != "application/json" {
t.Errorf("content_type = %v, want %q", got.ContentType, "application/json")
}
- if !got.ContentDigest.Valid || got.ContentDigest.String != "sha256:0123456789abcdef" {
- t.Errorf("content_digest = %v, want %q", got.ContentDigest, "sha256:0123456789abcdef")
- }
if !got.Size.Valid || got.Size.Int64 != 1024 {
t.Errorf("size = %v, want 1024", got.Size)
}
@@ -185,47 +178,3 @@ func TestMetadataCacheTableCreatedByMigration(t *testing.T) {
t.Error("metadata_cache table should exist after migration")
}
}
-
-func TestMetadataCacheContentDigestMigrationPreservesExistingRows(t *testing.T) {
- dbPath := filepath.Join(t.TempDir(), "test.db")
- db, err := Create(dbPath)
- if err != nil {
- t.Fatalf("Create failed: %v", err)
- }
- defer func() { _ = db.Close() }()
-
- if _, err := db.Exec("ALTER TABLE metadata_cache DROP COLUMN content_digest"); err != nil {
- t.Fatalf("dropping content_digest: %v", err)
- }
- if _, err := db.Exec("DELETE FROM migrations WHERE name = ?", "006_add_metadata_content_digest"); err != nil {
- t.Fatalf("resetting digest migration: %v", err)
- }
- if _, err := db.Exec(`
- INSERT INTO metadata_cache (ecosystem, name, storage_path, content_type, size, fetched_at, created_at, updated_at)
- VALUES (?, ?, ?, ?, ?, ?, ?, ?)
- `, "oci-manifest", "cache-key", "_metadata/oci-manifest/cache-key/metadata", "application/json", 2, time.Now(), time.Now(), time.Now()); err != nil {
- t.Fatalf("inserting legacy cache row: %v", err)
- }
-
- if err := db.MigrateSchema(); err != nil {
- t.Fatalf("MigrateSchema() error = %v", err)
- }
- hasDigest, err := db.HasColumn("metadata_cache", "content_digest")
- if err != nil {
- t.Fatalf("HasColumn() error = %v", err)
- }
- if !hasDigest {
- t.Fatal("metadata_cache.content_digest was not added")
- }
-
- entry, err := db.GetMetadataCache("oci-manifest", "cache-key")
- if err != nil {
- t.Fatalf("GetMetadataCache() error = %v", err)
- }
- if entry == nil || entry.StoragePath != "_metadata/oci-manifest/cache-key/metadata" {
- t.Fatalf("existing metadata cache row was not preserved: %#v", entry)
- }
- if entry.ContentDigest.Valid {
- t.Errorf("legacy content digest = %q, want NULL", entry.ContentDigest.String)
- }
-}
diff --git a/internal/database/queries.go b/internal/database/queries.go
index 9fa5381..5d95596 100644
--- a/internal/database/queries.go
+++ b/internal/database/queries.go
@@ -191,28 +191,6 @@ func (db *DB) GetArtifact(versionPURL, filename string) (*Artifact, error) {
return &a, nil
}
-// GetCachedArtifact returns the fields needed to serve a cached artifact.
-func (db *DB) GetCachedArtifact(packagePURL, versionPURL, filename string) (*CachedArtifact, error) {
- var artifact CachedArtifact
- query := db.Rebind(`
- SELECT packages.ecosystem, artifacts.storage_path, artifacts.content_hash, artifacts.size,
- artifacts.content_type, versions.integrity
- FROM artifacts
- JOIN versions ON versions.purl = artifacts.version_purl
- JOIN packages ON packages.purl = versions.package_purl
- WHERE packages.purl = ? AND artifacts.version_purl = ? AND artifacts.filename = ?
- AND artifacts.storage_path IS NOT NULL AND artifacts.fetched_at IS NOT NULL
- `)
- err := db.Get(&artifact, query, packagePURL, versionPURL, filename)
- if err == sql.ErrNoRows {
- return nil, nil
- }
- if err != nil {
- return nil, err
- }
- return &artifact, nil
-}
-
func (db *DB) GetArtifactByPath(storagePath string) (*Artifact, error) {
var a Artifact
query := db.Rebind(`
@@ -465,14 +443,11 @@ func (db *DB) GetMostPopularPackages(limit int) ([]PopularPackage, error) {
}
type RecentPackage struct {
- Ecosystem string `db:"ecosystem"`
- Name string `db:"name"`
- VersionPURL string `db:"version_purl"`
- CachedAt time.Time `db:"fetched_at"`
- Size int64 `db:"size"`
- // Version is derived from VersionPURL rather than selected, so that the
- // PURL percent-encoding is decoded (e.g. "%2B" back to "+").
- Version string `db:"-"`
+ Ecosystem string `db:"ecosystem"`
+ Name string `db:"name"`
+ Version string `db:"version"`
+ CachedAt time.Time `db:"fetched_at"`
+ Size int64 `db:"size"`
}
func (db *DB) GetRecentlyCachedPackages(limit int) ([]RecentPackage, error) {
@@ -486,10 +461,10 @@ func (db *DB) GetRecentlyCachedPackages(limit int) ([]RecentPackage, error) {
}
var packages []RecentPackage
- // There is no separate version column, so the full version PURL is selected
- // and the version is decoded from it in Go.
+ // We need to extract version from the purl since there's no separate version column
query := db.Rebind(`
- SELECT p.ecosystem, p.name, v.purl as version_purl,
+ SELECT p.ecosystem, p.name,
+ SUBSTR(v.purl, INSTR(v.purl, '@') + 1) as version,
a.fetched_at, COALESCE(a.size, 0) as size
FROM artifacts a
JOIN versions v ON v.purl = a.version_purl
@@ -499,13 +474,25 @@ func (db *DB) GetRecentlyCachedPackages(limit int) ([]RecentPackage, error) {
LIMIT ?
`)
+ // For postgres, use different string function
+ if db.dialect == DialectPostgres {
+ query = db.Rebind(`
+ SELECT p.ecosystem, p.name,
+ SUBSTRING(v.purl FROM POSITION('@' IN v.purl) + 1) as version,
+ a.fetched_at, COALESCE(a.size, 0) as size
+ FROM artifacts a
+ JOIN versions v ON v.purl = a.version_purl
+ JOIN packages p ON p.purl = v.package_purl
+ WHERE a.storage_path IS NOT NULL AND a.fetched_at IS NOT NULL
+ ORDER BY a.fetched_at DESC
+ LIMIT ?
+ `)
+ }
+
err = db.Select(&packages, query, limit)
if err != nil {
return nil, err
}
- for i := range packages {
- packages[i].Version = VersionFromPURL(packages[i].VersionPURL)
- }
return packages, nil
}
@@ -907,7 +894,7 @@ func (db *DB) GetMetadataCache(ecosystem, name string) (*MetadataCacheEntry, err
var entry MetadataCacheEntry
query := db.Rebind(`
SELECT id, ecosystem, name, storage_path, etag, content_type,
- content_digest, size, last_modified, fetched_at, created_at, updated_at
+ size, last_modified, fetched_at, created_at, updated_at
FROM metadata_cache WHERE ecosystem = ? AND name = ?
`)
err := db.Get(&entry, query, ecosystem, name)
@@ -927,13 +914,12 @@ func (db *DB) UpsertMetadataCache(entry *MetadataCacheEntry) error {
if db.dialect == DialectPostgres {
query = `
INSERT INTO metadata_cache (ecosystem, name, storage_path, etag, content_type,
- content_digest, size, last_modified, fetched_at, created_at, updated_at)
- VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11)
+ size, last_modified, fetched_at, created_at, updated_at)
+ VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10)
ON CONFLICT(ecosystem, name) DO UPDATE SET
storage_path = EXCLUDED.storage_path,
etag = EXCLUDED.etag,
content_type = EXCLUDED.content_type,
- content_digest = EXCLUDED.content_digest,
size = EXCLUDED.size,
last_modified = EXCLUDED.last_modified,
fetched_at = EXCLUDED.fetched_at,
@@ -942,13 +928,12 @@ func (db *DB) UpsertMetadataCache(entry *MetadataCacheEntry) error {
} else {
query = `
INSERT INTO metadata_cache (ecosystem, name, storage_path, etag, content_type,
- content_digest, size, last_modified, fetched_at, created_at, updated_at)
- VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
+ size, last_modified, fetched_at, created_at, updated_at)
+ VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
ON CONFLICT(ecosystem, name) DO UPDATE SET
storage_path = excluded.storage_path,
etag = excluded.etag,
content_type = excluded.content_type,
- content_digest = excluded.content_digest,
size = excluded.size,
last_modified = excluded.last_modified,
fetched_at = excluded.fetched_at,
@@ -958,7 +943,7 @@ func (db *DB) UpsertMetadataCache(entry *MetadataCacheEntry) error {
_, err := db.Exec(query,
entry.Ecosystem, entry.Name, entry.StoragePath, entry.ETag,
- entry.ContentType, entry.ContentDigest, entry.Size, entry.LastModified, entry.FetchedAt, now, now,
+ entry.ContentType, entry.Size, entry.LastModified, entry.FetchedAt, now, now,
)
if err != nil {
return fmt.Errorf("upserting metadata cache: %w", err)
diff --git a/internal/database/schema.go b/internal/database/schema.go
index c73877d..c8d8d1e 100644
--- a/internal/database/schema.go
+++ b/internal/database/schema.go
@@ -102,7 +102,6 @@ CREATE TABLE IF NOT EXISTS metadata_cache (
storage_path TEXT NOT NULL,
etag TEXT,
content_type TEXT,
- content_digest TEXT,
size INTEGER,
last_modified DATETIME,
fetched_at DATETIME,
@@ -203,7 +202,6 @@ CREATE TABLE IF NOT EXISTS metadata_cache (
storage_path TEXT NOT NULL,
etag TEXT,
content_type TEXT,
- content_digest TEXT,
size BIGINT,
last_modified TIMESTAMP,
fetched_at TIMESTAMP,
@@ -361,7 +359,6 @@ var migrations = []migration{
{"003_ensure_artifacts_table", migrateEnsureArtifactsTable},
{"004_ensure_vulnerabilities_table", migrateEnsureVulnerabilitiesTable},
{"005_ensure_metadata_cache_table", migrateEnsureMetadataCacheTable},
- {"006_add_metadata_content_digest", migrateAddMetadataContentDigest},
}
// isTableNotFound returns true if the error indicates a missing table.
@@ -584,20 +581,6 @@ func migrateEnsureMetadataCacheTable(db *DB) error {
return db.EnsureMetadataCacheTable()
}
-func migrateAddMetadataContentDigest(db *DB) error {
- hasColumn, err := db.HasColumn("metadata_cache", "content_digest")
- if err != nil {
- return fmt.Errorf("checking metadata_cache content_digest column: %w", err)
- }
- if hasColumn {
- return nil
- }
- if _, err := db.Exec("ALTER TABLE metadata_cache ADD COLUMN content_digest TEXT"); err != nil {
- return fmt.Errorf("adding metadata_cache content_digest column: %w", err)
- }
- return nil
-}
-
// EnsureMetadataCacheTable creates the metadata_cache table if it doesn't exist.
func (db *DB) EnsureMetadataCacheTable() error {
has, err := db.HasTable("metadata_cache")
@@ -618,7 +601,6 @@ func (db *DB) EnsureMetadataCacheTable() error {
storage_path TEXT NOT NULL,
etag TEXT,
content_type TEXT,
- content_digest TEXT,
size BIGINT,
last_modified TIMESTAMP,
fetched_at TIMESTAMP,
@@ -636,7 +618,6 @@ func (db *DB) EnsureMetadataCacheTable() error {
storage_path TEXT NOT NULL,
etag TEXT,
content_type TEXT,
- content_digest TEXT,
size INTEGER,
last_modified DATETIME,
fetched_at DATETIME,
diff --git a/internal/database/types.go b/internal/database/types.go
index 5ddb9f3..47dc47e 100644
--- a/internal/database/types.go
+++ b/internal/database/types.go
@@ -2,7 +2,6 @@ package database
import (
"database/sql"
- "net/url"
"strings"
"time"
)
@@ -48,79 +47,10 @@ type Version struct {
// Version extracts the version string from the PURL.
// e.g., "pkg:npm/lodash@4.17.21" -> "4.17.21"
func (v *Version) Version() string {
- return VersionFromPURL(v.PURL)
-}
-
-// EscapedVersion returns the version escaped for use as a single URL path
-// segment.
-//
-// Version returns decoded text, which is what should be shown to a user but is
-// not safe to drop into a link: html/template preserves reserved characters and
-// existing escapes in a URL, so "release/1" would split into two path segments,
-// "v1?build" would start a query string, and a literal "%2B" would be read back
-// as "+". Escaping here and decoding in splitWildcardPath round-trips the value,
-// so the link resolves to the version that was stored.
-func (v *Version) EscapedVersion() string {
- return url.PathEscape(v.Version())
-}
-
-// DisplayPURL returns the PURL with its path components percent-decoded, for
-// showing in the UI. The stored PURL keeps the canonical encoding (which is
-// what the API and all lookups use); this is only a readable rendering, so that
-// a version like "7.91+dfsg1-2ubuntu0.1" is not shown as "7.91%2Bdfsg1-2ubuntu0.1"
-// and an npm scope is shown as "@babel" rather than "%40babel". Qualifiers and
-// subpath keep their encoding, since decoding those would be ambiguous.
-func (v *Version) DisplayPURL() string {
- base, suffix := v.PURL, ""
- if i := strings.IndexAny(base, "?#"); i >= 0 {
- base, suffix = base[:i], base[i:]
+ if idx := strings.LastIndex(v.PURL, "@"); idx >= 0 {
+ return v.PURL[idx+1:]
}
-
- name, version := base, ""
- if idx := strings.LastIndex(base, "@"); idx >= 0 {
- name, version = base[:idx], "@"+decodePURLComponent(base[idx+1:])
- }
-
- parts := strings.Split(name, "/")
- for i, part := range parts {
- parts[i] = decodePURLComponent(part)
- }
- return strings.Join(parts, "/") + version + suffix
-}
-
-// VersionFromPURL extracts the decoded version string from a PURL.
-//
-// PURL percent-encodes characters that are not safe in a path component, so a
-// Debian version like "7.91+dfsg1-2ubuntu0.1" is stored as
-// "pkg:deb/nmap@7.91%2Bdfsg1-2ubuntu0.1". The raw substring after "@" is
-// therefore not the version: it must be percent-decoded before being displayed
-// or used to build a URL, otherwise "%2B" leaks into the UI and round-tripping
-// the value back into a PURL double-encodes it.
-//
-// e.g., "pkg:npm/lodash@4.17.21" -> "4.17.21"
-func VersionFromPURL(p string) string {
- // Qualifiers ("?key=value") and subpath ("#path") follow the version.
- if i := strings.IndexAny(p, "?#"); i >= 0 {
- p = p[:i]
- }
- idx := strings.LastIndex(p, "@")
- if idx < 0 {
- return ""
- }
- return decodePURLComponent(p[idx+1:])
-}
-
-// decodePURLComponent percent-decodes a single PURL path component, returning
-// the input unchanged if it is not valid percent-encoding.
-func decodePURLComponent(s string) string {
- if !strings.Contains(s, "%") {
- return s
- }
- decoded, err := url.PathUnescape(s)
- if err != nil {
- return s
- }
- return decoded
+ return ""
}
// Artifact represents a cached artifact in the database.
@@ -146,30 +76,19 @@ func (a *Artifact) IsCached() bool {
return a.StoragePath.Valid && a.FetchedAt.Valid
}
-// CachedArtifact contains the fields needed to serve a cached artifact.
-type CachedArtifact struct {
- Ecosystem string `db:"ecosystem"`
- StoragePath string `db:"storage_path"`
- ContentHash sql.NullString `db:"content_hash"`
- Size sql.NullInt64 `db:"size"`
- ContentType sql.NullString `db:"content_type"`
- Integrity sql.NullString `db:"integrity"`
-}
-
// MetadataCacheEntry represents a cached metadata blob for offline serving.
type MetadataCacheEntry struct {
- ID int64 `db:"id" json:"id"`
- Ecosystem string `db:"ecosystem" json:"ecosystem"`
- Name string `db:"name" json:"name"`
- StoragePath string `db:"storage_path" json:"storage_path"`
- ETag sql.NullString `db:"etag" json:"etag,omitempty"`
- ContentType sql.NullString `db:"content_type" json:"content_type,omitempty"`
- ContentDigest sql.NullString `db:"content_digest" json:"content_digest,omitempty"`
- Size sql.NullInt64 `db:"size" json:"size,omitempty"`
- LastModified sql.NullTime `db:"last_modified" json:"last_modified,omitempty"`
- FetchedAt sql.NullTime `db:"fetched_at" json:"fetched_at,omitempty"`
- CreatedAt time.Time `db:"created_at" json:"created_at"`
- UpdatedAt time.Time `db:"updated_at" json:"updated_at"`
+ ID int64 `db:"id" json:"id"`
+ Ecosystem string `db:"ecosystem" json:"ecosystem"`
+ Name string `db:"name" json:"name"`
+ StoragePath string `db:"storage_path" json:"storage_path"`
+ ETag sql.NullString `db:"etag" json:"etag,omitempty"`
+ ContentType sql.NullString `db:"content_type" json:"content_type,omitempty"`
+ Size sql.NullInt64 `db:"size" json:"size,omitempty"`
+ LastModified sql.NullTime `db:"last_modified" json:"last_modified,omitempty"`
+ FetchedAt sql.NullTime `db:"fetched_at" json:"fetched_at,omitempty"`
+ CreatedAt time.Time `db:"created_at" json:"created_at"`
+ UpdatedAt time.Time `db:"updated_at" json:"updated_at"`
}
// Vulnerability represents a cached vulnerability record.
diff --git a/internal/database/version_purl_test.go b/internal/database/version_purl_test.go
deleted file mode 100644
index 517022b..0000000
--- a/internal/database/version_purl_test.go
+++ /dev/null
@@ -1,159 +0,0 @@
-package database
-
-import (
- "database/sql"
- "net/url"
- "testing"
- "time"
-)
-
-func TestVersionFromPURL(t *testing.T) {
- tests := []struct {
- name string
- purl string
- want string
- }{
- {"simple", "pkg:npm/lodash@4.17.21", "4.17.21"},
- {"namespaced", "pkg:composer/symfony/console@6.0.0", "6.0.0"},
- // Debian/Ubuntu versions routinely contain "+", which PURL encodes.
- {"encoded plus", "pkg:deb/nmap@7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1", "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1"},
- {"encoded epoch", "pkg:deb/curl@1%3A7.81.0-1", "1:7.81.0-1"},
- {"encoded plus with qualifier", "pkg:deb/nmap@7.91%2Bdfsg1?repository_url=http%3A%2F%2Fexample.com", "7.91+dfsg1"},
- {"tilde is not encoded", "pkg:deb/foo@1.0~rc1", "1.0~rc1"},
- {"no version", "pkg:npm/lodash", ""},
- {"invalid escape passed through", "pkg:npm/lodash@1.0%zz", "1.0%zz"},
- }
-
- for _, tt := range tests {
- t.Run(tt.name, func(t *testing.T) {
- if got := VersionFromPURL(tt.purl); got != tt.want {
- t.Errorf("VersionFromPURL(%q) = %q, want %q", tt.purl, got, tt.want)
- }
- v := &Version{PURL: tt.purl}
- if got := v.Version(); got != tt.want {
- t.Errorf("Version.Version() for %q = %q, want %q", tt.purl, got, tt.want)
- }
- })
- }
-}
-
-// TestVersionEscapedVersion checks the value the templates put in a URL. It
-// must survive the round trip back through the router: escaping here and
-// decoding per path segment on the way in has to yield the original version.
-func TestVersionEscapedVersion(t *testing.T) {
- tests := []struct {
- name string
- purl string
- want string
- }{
- {"simple", "pkg:npm/lodash@4.17.21", "4.17.21"},
- // "+" is legal in a path segment, so it stays literal and the UI keeps
- // showing the version the way Debian writes it.
- {"plus stays literal", "pkg:deb/nmap@7.91%2Bdfsg1-2ubuntu0.1", "7.91+dfsg1-2ubuntu0.1"},
- // A slash would otherwise split the version into two path segments.
- {"slash", "pkg:golang/example@release%2F1", "release%2F1"},
- // A question mark would otherwise start the query string.
- {"question mark", "pkg:npm/example@v1%3Fbuild", "v1%3Fbuild"},
- // A version containing a literal "%2B" is stored double-encoded; the
- // link must re-encode it or it decodes back to "+" instead.
- {"literal percent escape", "pkg:npm/example@1.0%252B", "1.0%252B"},
- {"space", "pkg:npm/example@1.0%20beta", "1.0%20beta"},
- {"no version", "pkg:npm/lodash", ""},
- }
-
- for _, tt := range tests {
- t.Run(tt.name, func(t *testing.T) {
- v := &Version{PURL: tt.purl}
- got := v.EscapedVersion()
- if got != tt.want {
- t.Errorf("EscapedVersion() for %q = %q, want %q", tt.purl, got, tt.want)
- }
- // The router decodes each path segment, which must give back the
- // version the page displays.
- decoded, err := url.PathUnescape(got)
- if err != nil {
- t.Fatalf("PathUnescape(%q) failed: %v", got, err)
- }
- if decoded != v.Version() {
- t.Errorf("round trip for %q = %q, want %q", tt.purl, decoded, v.Version())
- }
- })
- }
-}
-
-func TestVersionDisplayPURL(t *testing.T) {
- tests := []struct {
- name string
- purl string
- want string
- }{
- {"simple", "pkg:npm/lodash@4.17.21", "pkg:npm/lodash@4.17.21"},
- {
- "encoded plus",
- "pkg:deb/nmap@7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1",
- "pkg:deb/nmap@7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1",
- },
- {
- "qualifier preserved",
- "pkg:deb/nmap@7.91%2Bdfsg1?repository_url=http%3A%2F%2Fexample.com",
- "pkg:deb/nmap@7.91+dfsg1?repository_url=http%3A%2F%2Fexample.com",
- },
- // The namespace is encoded too: MakePURLString("npm", "@babel/core", …)
- // produces "pkg:npm/%40babel/core@…".
- {"encoded npm scope", "pkg:npm/%40babel/core@7.0.0", "pkg:npm/@babel/core@7.0.0"},
- {"encoded scope without version", "pkg:npm/%40babel/core", "pkg:npm/@babel/core"},
- {"no version", "pkg:npm/lodash", "pkg:npm/lodash"},
- }
-
- for _, tt := range tests {
- t.Run(tt.name, func(t *testing.T) {
- v := &Version{PURL: tt.purl}
- if got := v.DisplayPURL(); got != tt.want {
- t.Errorf("DisplayPURL() for %q = %q, want %q", tt.purl, got, tt.want)
- }
- })
- }
-}
-
-// TestGetRecentlyCachedPackagesDecodesVersion guards the dashboard's "recently
-// cached" list, which derives the version from the version PURL.
-func TestGetRecentlyCachedPackagesDecodesVersion(t *testing.T) {
- runWithBothDatabases(t, func(t *testing.T, db *DB) {
- const versionPURL = "pkg:deb/nmap@7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1"
-
- if err := db.UpsertPackage(&Package{
- PURL: "pkg:deb/nmap", Ecosystem: "deb", Name: "nmap",
- }); err != nil {
- t.Fatalf("UpsertPackage failed: %v", err)
- }
- if err := db.UpsertVersion(&Version{
- PURL: versionPURL, PackagePURL: "pkg:deb/nmap",
- }); err != nil {
- t.Fatalf("UpsertVersion failed: %v", err)
- }
- if err := db.UpsertArtifact(&Artifact{
- VersionPURL: versionPURL,
- Filename: "nmap_7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1_amd64.deb",
- UpstreamURL: "http://archive.ubuntu.com/ubuntu/pool/universe/n/nmap/nmap.deb",
- StoragePath: sql.NullString{String: "/cache/nmap.deb", Valid: true},
- FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
- }); err != nil {
- t.Fatalf("UpsertArtifact failed: %v", err)
- }
-
- recent, err := db.GetRecentlyCachedPackages(10)
- if err != nil {
- t.Fatalf("GetRecentlyCachedPackages failed: %v", err)
- }
- if len(recent) != 1 {
- t.Fatalf("expected 1 recent package, got %d", len(recent))
- }
- const want = "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1"
- if recent[0].Version != want {
- t.Errorf("Version = %q, want %q", recent[0].Version, want)
- }
- if recent[0].VersionPURL != versionPURL {
- t.Errorf("VersionPURL = %q, want %q", recent[0].VersionPURL, versionPURL)
- }
- })
-}
diff --git a/internal/enrichment/enrichment.go b/internal/enrichment/enrichment.go
index 6b09db9..247dd2b 100644
--- a/internal/enrichment/enrichment.go
+++ b/internal/enrichment/enrichment.go
@@ -201,6 +201,43 @@ func (s *Service) CheckVulnerabilities(ctx context.Context, ecosystem, name, ver
return results, nil
}
+// BulkCheckVulnerabilities queries vulnerabilities for multiple package versions.
+func (s *Service) BulkCheckVulnerabilities(ctx context.Context, packages []struct{ Ecosystem, Name, Version string }) (map[string][]VulnInfo, error) {
+ purls := make([]*purl.PURL, len(packages))
+ for i, pkg := range packages {
+ purls[i] = purl.MakePURL(pkg.Ecosystem, pkg.Name, pkg.Version)
+ }
+
+ vulnResults, err := s.vulnSource.QueryBatch(ctx, purls)
+ if err != nil {
+ return nil, err
+ }
+
+ result := make(map[string][]VulnInfo, len(packages))
+ for i, vulnList := range vulnResults {
+ pkg := packages[i]
+ key := purl.MakePURLString(pkg.Ecosystem, pkg.Name, pkg.Version)
+
+ var infos []VulnInfo
+ for _, v := range vulnList {
+ info := VulnInfo{
+ ID: v.ID,
+ Summary: v.Summary,
+ Severity: v.SeverityLevel(),
+ CVSSScore: v.CVSSScore(),
+ FixedVersion: v.FixedVersion(pkg.Ecosystem, pkg.Name),
+ }
+ for _, ref := range v.References {
+ info.References = append(info.References, ref.URL)
+ }
+ infos = append(infos, info)
+ }
+ result[key] = infos
+ }
+
+ return result, nil
+}
+
// IsOutdated checks if a version is older than the latest version.
func (s *Service) IsOutdated(currentVersion, latestVersion string) bool {
if latestVersion == "" || currentVersion == "" {
@@ -251,6 +288,19 @@ func (s *Service) CategorizeLicense(license string) LicenseCategory {
return LicenseUnknown
}
+// NormalizeLicense normalizes a license string to SPDX format.
+func (s *Service) NormalizeLicense(license string) string {
+ if license == "" {
+ return ""
+ }
+
+ if normalized, err := spdx.NormalizeExpressionLax(license); err == nil {
+ return normalized
+ }
+
+ return license
+}
+
// EnrichmentResult contains all enrichment data for a package version.
type EnrichmentResult struct {
Package *PackageInfo
diff --git a/internal/enrichment/enrichment_test.go b/internal/enrichment/enrichment_test.go
index e6a6dde..aa9a16e 100644
--- a/internal/enrichment/enrichment_test.go
+++ b/internal/enrichment/enrichment_test.go
@@ -74,3 +74,25 @@ func TestCategorizeLicense(t *testing.T) {
}
}
}
+
+func TestNormalizeLicense(t *testing.T) {
+ logger := slog.New(slog.NewTextHandler(os.Stdout, nil))
+ svc := New(logger)
+
+ tests := []struct {
+ input string
+ expected string
+ }{
+ {"MIT", "MIT"},
+ {"Apache 2", "Apache-2.0"},
+ {"Apache-2.0", "Apache-2.0"},
+ {"", ""},
+ }
+
+ for _, tc := range tests {
+ result := svc.NormalizeLicense(tc.input)
+ if result != tc.expected {
+ t.Errorf("NormalizeLicense(%q) = %q, want %q", tc.input, result, tc.expected)
+ }
+ }
+}
diff --git a/internal/handler/cargo.go b/internal/handler/cargo.go
index 79fb750..5d7810c 100644
--- a/internal/handler/cargo.go
+++ b/internal/handler/cargo.go
@@ -6,9 +6,10 @@ import (
"errors"
"fmt"
"net/http"
- "net/url"
"strings"
"time"
+
+ "github.com/git-pkgs/purl"
)
const (
@@ -29,18 +30,11 @@ type CargoHandler struct {
}
// NewCargoHandler creates a new cargo protocol handler.
-func NewCargoHandler(proxy *Proxy, proxyURL, indexURL, downloadURL string) *CargoHandler {
- if strings.TrimSpace(indexURL) == "" {
- indexURL = cargoUpstream
- }
- if strings.TrimSpace(downloadURL) == "" {
- downloadURL = cargoDownloadBase
- }
-
+func NewCargoHandler(proxy *Proxy, proxyURL string) *CargoHandler {
return &CargoHandler{
proxy: proxy,
- indexURL: strings.TrimSuffix(indexURL, "/"),
- downloadURL: strings.TrimSuffix(downloadURL, "/"),
+ indexURL: cargoUpstream,
+ downloadURL: cargoDownloadBase,
proxyURL: strings.TrimSuffix(proxyURL, "/"),
}
}
@@ -149,7 +143,7 @@ func (h *CargoHandler) applyCooldownFiltering(downstreamResponse http.ResponseWr
continue
}
- cratePURL := canonicalPackagePURL("cargo", crate.Name)
+ cratePURL := purl.MakePURLString("cargo", crate.Name, "")
if !h.proxy.Cooldown.IsAllowed("cargo", cratePURL, publishedAt) {
h.proxy.Logger.Info("cooldown: filtering cargo version",
@@ -197,17 +191,10 @@ func (h *CargoHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
h.proxy.Logger.Info("cargo download request",
"crate", name, "version", version, "filename", filename)
- downloadURL := fmt.Sprintf(
- "%s/%s/%s",
- h.downloadURL,
- url.PathEscape(name),
- url.PathEscape(filename),
- )
- result, err := h.proxy.GetOrFetchArtifactFromURL(
- r.Context(), "cargo", name, version, filename, downloadURL,
- )
+ result, err := h.proxy.GetOrFetchArtifact(r.Context(), "cargo", name, version, filename)
if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch crate")
+ h.proxy.Logger.Error("failed to get artifact", "error", err)
+ http.Error(w, "failed to fetch crate", http.StatusBadGateway)
return
}
diff --git a/internal/handler/cargo_test.go b/internal/handler/cargo_test.go
index 895ff7b..10d3faf 100644
--- a/internal/handler/cargo_test.go
+++ b/internal/handler/cargo_test.go
@@ -2,7 +2,6 @@ package handler
import (
"encoding/json"
- "io"
"log/slog"
"net/http"
"net/http/httptest"
@@ -11,7 +10,6 @@ import (
"time"
"github.com/git-pkgs/cooldown"
- "github.com/git-pkgs/registries/fetch"
)
func cargoTestProxy() *Proxy {
@@ -72,75 +70,6 @@ func TestCargoConfigEndpoint(t *testing.T) {
}
}
-func TestCargoHandlerUsesConfiguredUpstreams(t *testing.T) {
- t.Run("index", func(t *testing.T) {
- var requestPath, authHeader string
- upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- requestPath = r.URL.Path
- authHeader = r.Header.Get("Authorization")
- if authHeader != "Bearer cargo-token" {
- w.WriteHeader(http.StatusUnauthorized)
- return
- }
- w.Header().Set("Content-Type", "text/plain")
- _, _ = io.WriteString(w, `{"name":"serde","vers":"1.0.0"}`)
- }))
- defer upstream.Close()
-
- proxy, _, _, _ := setupTestProxy(t)
- proxy.HTTPClient = upstream.Client()
- proxy.AuthForURL = func(string) (string, string) {
- return "Authorization", "Bearer cargo-token"
- }
- h := NewCargoHandler(
- proxy,
- "http://proxy.test",
- upstream.URL+"/index/",
- "https://crates.example.test/files/",
- )
-
- req := httptest.NewRequest(http.MethodGet, "/se/rd/serde", nil)
- w := httptest.NewRecorder()
- h.Routes().ServeHTTP(w, req)
-
- if w.Code != http.StatusOK {
- t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
- }
- if requestPath != "/index/se/rd/serde" {
- t.Errorf("upstream path = %q, want %q", requestPath, "/index/se/rd/serde")
- }
- if authHeader != "Bearer cargo-token" {
- t.Errorf("Authorization = %q, want %q", authHeader, "Bearer cargo-token")
- }
- })
-
- t.Run("download", func(t *testing.T) {
- proxy, _, _, artifactFetcher := setupTestProxy(t)
- artifactFetcher.artifact = &fetch.Artifact{
- Body: io.NopCloser(strings.NewReader("crate")),
- ContentType: "application/gzip",
- }
- h := NewCargoHandler(
- proxy,
- "http://proxy.test",
- "https://index.example.test/root/",
- "https://crates.example.test/files/",
- )
-
- req := httptest.NewRequest(http.MethodGet, "/crates/serde/1.0.0/download", nil)
- w := httptest.NewRecorder()
- h.Routes().ServeHTTP(w, req)
-
- if w.Code != http.StatusOK {
- t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
- }
- want := "https://crates.example.test/files/serde/serde-1.0.0.crate"
- if artifactFetcher.fetchedURL != want {
- t.Errorf("fetched URL = %q, want %q", artifactFetcher.fetchedURL, want)
- }
- })
-}
-
func TestCargoIndexProxy(t *testing.T) {
// Create a mock upstream index server
indexContent := `{"name":"serde","vers":"1.0.0","deps":[],"cksum":"abc123"}
diff --git a/internal/handler/composer.go b/internal/handler/composer.go
index 45935b7..bc3bc1d 100644
--- a/internal/handler/composer.go
+++ b/internal/handler/composer.go
@@ -10,6 +10,8 @@ import (
"path"
"strings"
"time"
+
+ "github.com/git-pkgs/purl"
)
const (
@@ -214,7 +216,7 @@ func deepCopyValue(v any) any {
// filterAndRewriteVersions applies cooldown filtering and rewrites dist URLs
// for a single package's version list.
func (h *ComposerHandler) filterAndRewriteVersions(packageName string, versionList []any) []any {
- packagePURL := canonicalPackagePURL("composer", packageName)
+ packagePURL := purl.MakePURLString("composer", packageName, "")
filtered := versionList[:0]
for _, v := range versionList {
@@ -346,7 +348,8 @@ func (h *ComposerHandler) handleDownload(w http.ResponseWriter, r *http.Request)
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "composer", packageName, version, filename, downloadURL)
if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch package")
+ h.proxy.Logger.Error("failed to get artifact", "error", err)
+ http.Error(w, "failed to fetch package", http.StatusBadGateway)
return
}
diff --git a/internal/handler/conan.go b/internal/handler/conan.go
index c0476f9..53f6428 100644
--- a/internal/handler/conan.go
+++ b/internal/handler/conan.go
@@ -84,7 +84,8 @@ func (h *ConanHandler) handleRecipeFile(w http.ResponseWriter, r *http.Request)
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "conan", packageName, storageVersion, storageFilename, upstreamURL)
if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch file")
+ h.proxy.Logger.Error("failed to get artifact", "error", err)
+ http.Error(w, "failed to fetch file", http.StatusBadGateway)
return
}
@@ -121,7 +122,8 @@ func (h *ConanHandler) handlePackageFile(w http.ResponseWriter, r *http.Request)
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "conan", packageName, storageVersion, storageFilename, upstreamURL)
if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch file")
+ h.proxy.Logger.Error("failed to get artifact", "error", err)
+ http.Error(w, "failed to fetch file", http.StatusBadGateway)
return
}
diff --git a/internal/handler/conda.go b/internal/handler/conda.go
index 224c25f..cfa20c8 100644
--- a/internal/handler/conda.go
+++ b/internal/handler/conda.go
@@ -6,6 +6,8 @@ import (
"net/http"
"strings"
"time"
+
+ "github.com/git-pkgs/purl"
)
const (
@@ -72,7 +74,8 @@ func (h *CondaHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "conda", packageName, version, filename, upstreamURL)
if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch package")
+ h.proxy.Logger.Error("failed to get artifact", "error", err)
+ http.Error(w, "failed to fetch package", http.StatusBadGateway)
return
}
@@ -215,7 +218,7 @@ func (h *CondaHandler) applyCooldownFiltering(body []byte) ([]byte, error) {
continue
}
- packagePURL := canonicalPackagePURL("conda", name)
+ packagePURL := purl.MakePURLString("conda", name, "")
if !h.proxy.Cooldown.IsAllowed("conda", packagePURL, publishedAt) {
version, _ := entryMap["version"].(string)
diff --git a/internal/handler/container.go b/internal/handler/container.go
index 74819dd..8ba5e97 100644
--- a/internal/handler/container.go
+++ b/internal/handler/container.go
@@ -2,7 +2,6 @@ package handler
import (
"encoding/json"
- "errors"
"fmt"
"io"
"net/http"
@@ -11,40 +10,31 @@ import (
)
const (
- dockerHubRegistry = "https://registry-1.docker.io"
- blobMatchCount = 3 // full match + name + digest
- manifestMatchCount = 3 // full match + name + reference
- tagsListMatchCount = 2 // full match + name
- registrySelectorParts = 3 // upstream + name + repository
+ dockerHubRegistry = "https://registry-1.docker.io"
+ dockerHubAuth = "https://auth.docker.io"
+ blobMatchCount = 3 // full match + name + digest
+ manifestMatchCount = 3 // full match + name + reference
+ tagsListMatchCount = 2 // full match + name
)
// ContainerHandler handles OCI/Docker container registry protocol requests.
// It implements the OCI Distribution Spec for pulling images.
// Reference: https://github.com/opencontainers/distribution-spec/blob/main/spec.md
type ContainerHandler struct {
- proxy *Proxy
- registryURL string
- proxyURL string
- namedRegistries map[string]string
+ proxy *Proxy
+ registryURL string
+ authURL string
+ proxyURL string
}
// NewContainerHandler creates a new container registry protocol handler.
-// Named registries are selected with the repository prefix
-// upstream/{name}/, leaving unprefixed requests compatible with the Docker Hub
-// mirror behavior.
-func NewContainerHandler(proxy *Proxy, proxyURL string, namedRegistries ...map[string]string) *ContainerHandler {
- h := &ContainerHandler{
+func NewContainerHandler(proxy *Proxy, proxyURL string) *ContainerHandler {
+ return &ContainerHandler{
proxy: proxy,
registryURL: dockerHubRegistry,
+ authURL: dockerHubAuth,
proxyURL: strings.TrimSuffix(proxyURL, "/"),
}
- if len(namedRegistries) > 0 {
- h.namedRegistries = make(map[string]string, len(namedRegistries[0]))
- for name, registryURL := range namedRegistries[0] {
- h.namedRegistries[name] = strings.TrimSuffix(registryURL, "/")
- }
- }
- return h
}
// Routes returns the HTTP handler for container registry requests.
@@ -97,68 +87,48 @@ func (h *ContainerHandler) handleBlobDownload(w http.ResponseWriter, r *http.Req
return
}
- registryURL, upstreamName, cacheName, ok := h.registryForName(name)
- if !ok {
- h.containerError(w, http.StatusNotFound, "NAME_UNKNOWN", "unknown upstream registry")
- return
- }
+ h.proxy.Logger.Info("container blob request", "name", name, "digest", digest)
- h.proxy.Logger.Info("container blob request", "name", upstreamName, "digest", digest)
-
- filename := digest
- cached, err := h.proxy.GetCachedArtifact(r.Context(), "oci", cacheName, digest, filename)
+ // Get auth token for upstream
+ token, err := h.getAuthToken(r.Context(), name, "pull")
if err != nil {
- h.proxy.Logger.Error("failed to check blob cache", "error", err)
- h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to check blob cache")
- return
- }
- if cached != nil {
- w.Header().Set("Docker-Content-Digest", digest)
- if cached.ContentType != "" {
- w.Header().Set("Content-Type", cached.ContentType)
- } else {
- w.Header().Set("Content-Type", "application/octet-stream")
- }
- serveArtifact(w, r.Method, cached)
+ h.proxy.Logger.Error("failed to get auth token", "error", err)
+ h.containerError(w, http.StatusUnauthorized, "UNAUTHORIZED", "failed to authenticate")
return
}
// For HEAD requests, just proxy to upstream
if r.Method == http.MethodHead {
- h.proxyBlobHead(w, r, registryURL, upstreamName, digest)
+ h.proxyBlobHead(w, r, name, digest, token)
return
}
- // Try to get from cache, or fetch from the authentication-aware upstream client.
- result, err := h.proxy.GetOrFetchArtifactFromURL(
+ // Try to get from cache, or fetch from upstream with auth
+ filename := digest
+ headers := http.Header{"Authorization": {"Bearer " + token}}
+ result, err := h.proxy.GetOrFetchArtifactFromURLWithHeaders(
r.Context(),
"oci",
- cacheName,
+ name,
digest, // use digest as version
filename,
- fmt.Sprintf("%s/v2/%s/blobs/%s", registryURL, upstreamName, digest),
+ fmt.Sprintf("%s/v2/%s/blobs/%s", h.registryURL, name, digest),
+ headers,
)
if err != nil {
- if errors.Is(err, ErrUpstreamNotFound) {
- h.containerError(w, http.StatusNotFound, "BLOB_UNKNOWN", "blob unknown to registry")
- return
- }
h.proxy.Logger.Error("failed to fetch blob", "error", err)
- h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch blob")
+ h.containerError(w, http.StatusBadGateway, "BLOB_UNKNOWN", "failed to fetch blob")
return
}
w.Header().Set("Docker-Content-Digest", digest)
- if result.ContentType != "" {
- w.Header().Set("Content-Type", result.ContentType)
- } else {
- w.Header().Set("Content-Type", "application/octet-stream")
- }
+ w.Header().Set("Content-Type", "application/octet-stream")
ServeArtifact(w, result)
}
-// handleManifest serves immutable manifests from cache and revalidates mutable tags.
+// handleManifest proxies manifest requests to upstream.
+// Manifests change when tags are updated, so we proxy these directly.
// Path format: {name}/manifests/{reference}
func (h *ContainerHandler) handleManifest(w http.ResponseWriter, r *http.Request, path string) {
if r.Method != http.MethodGet && r.Method != http.MethodHead {
@@ -172,14 +142,58 @@ func (h *ContainerHandler) handleManifest(w http.ResponseWriter, r *http.Request
return
}
- registryURL, upstreamName, _, ok := h.registryForName(name)
- if !ok {
- h.containerError(w, http.StatusNotFound, "NAME_UNKNOWN", "unknown upstream registry")
+ h.proxy.Logger.Info("container manifest request", "name", name, "reference", reference)
+
+ // Get auth token
+ token, err := h.getAuthToken(r.Context(), name, "pull")
+ if err != nil {
+ h.proxy.Logger.Error("failed to get auth token", "error", err)
+ h.containerError(w, http.StatusUnauthorized, "UNAUTHORIZED", "failed to authenticate")
return
}
- h.proxy.Logger.Info("container manifest request", "name", upstreamName, "reference", reference)
- h.serveManifest(w, r, registryURL, upstreamName, reference)
+ // Proxy to upstream
+ upstreamURL := fmt.Sprintf("%s/v2/%s/manifests/%s", h.registryURL, name, reference)
+
+ req, err := http.NewRequestWithContext(r.Context(), r.Method, upstreamURL, nil)
+ if err != nil {
+ h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create request")
+ return
+ }
+
+ req.Header.Set("Authorization", "Bearer "+token)
+
+ // Forward Accept header for content negotiation
+ if accept := r.Header.Get("Accept"); accept != "" {
+ req.Header.Set("Accept", accept)
+ } else {
+ // Default accept headers for manifests
+ req.Header.Set("Accept", strings.Join([]string{
+ "application/vnd.oci.image.manifest.v1+json",
+ "application/vnd.oci.image.index.v1+json",
+ "application/vnd.docker.distribution.manifest.v2+json",
+ "application/vnd.docker.distribution.manifest.list.v2+json",
+ "application/vnd.docker.distribution.manifest.v1+prettyjws",
+ }, ", "))
+ }
+
+ resp, err := h.proxy.HTTPClient.Do(req)
+ if err != nil {
+ h.proxy.Logger.Error("failed to fetch manifest", "error", err)
+ h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
+ return
+ }
+ defer func() { _ = resp.Body.Close() }()
+
+ // Copy relevant headers
+ for _, header := range []string{"Content-Type", "Content-Length", "Docker-Content-Digest", "ETag"} {
+ if v := resp.Header.Get(header); v != "" {
+ w.Header().Set(header, v)
+ }
+ }
+
+ w.WriteHeader(resp.StatusCode)
+ _, _ = io.Copy(w, resp.Body)
}
// handleTagsList proxies tag list requests to upstream.
@@ -195,13 +209,14 @@ func (h *ContainerHandler) handleTagsList(w http.ResponseWriter, r *http.Request
return
}
- registryURL, upstreamName, _, ok := h.registryForName(name)
- if !ok {
- h.containerError(w, http.StatusNotFound, "NAME_UNKNOWN", "unknown upstream registry")
+ // Get auth token
+ token, err := h.getAuthToken(r.Context(), name, "pull")
+ if err != nil {
+ h.containerError(w, http.StatusUnauthorized, "UNAUTHORIZED", "failed to authenticate")
return
}
- upstreamURL := fmt.Sprintf("%s/v2/%s/tags/list", registryURL, upstreamName)
+ upstreamURL := fmt.Sprintf("%s/v2/%s/tags/list", h.registryURL, name)
if r.URL.RawQuery != "" {
upstreamURL += "?" + r.URL.RawQuery
}
@@ -212,6 +227,8 @@ func (h *ContainerHandler) handleTagsList(w http.ResponseWriter, r *http.Request
return
}
+ req.Header.Set("Authorization", "Bearer "+token)
+
resp, err := h.proxy.HTTPClient.Do(req)
if err != nil {
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
@@ -224,9 +241,46 @@ func (h *ContainerHandler) handleTagsList(w http.ResponseWriter, r *http.Request
_, _ = io.Copy(w, resp.Body)
}
+// getAuthToken gets a bearer token for the specified repository.
+// Docker Hub requires auth even for public images.
+func (h *ContainerHandler) getAuthToken(_ interface{ Done() <-chan struct{} }, repository, action string) (string, error) {
+ // For Docker Hub: https://auth.docker.io/token?service=registry.docker.io&scope=repository:{repo}:pull
+ authURL := fmt.Sprintf("%s/token?service=registry.docker.io&scope=repository:%s:%s",
+ h.authURL, repository, action)
+
+ req, err := http.NewRequest(http.MethodGet, authURL, nil)
+ if err != nil {
+ return "", err
+ }
+
+ resp, err := h.proxy.HTTPClient.Do(req)
+ if err != nil {
+ return "", err
+ }
+ defer func() { _ = resp.Body.Close() }()
+
+ if resp.StatusCode != http.StatusOK {
+ return "", fmt.Errorf("auth failed with status %d", resp.StatusCode)
+ }
+
+ var tokenResp struct {
+ Token string `json:"token"`
+ AccessToken string `json:"access_token"`
+ }
+
+ if err := json.NewDecoder(resp.Body).Decode(&tokenResp); err != nil {
+ return "", err
+ }
+
+ if tokenResp.Token != "" {
+ return tokenResp.Token, nil
+ }
+ return tokenResp.AccessToken, nil
+}
+
// proxyBlobHead handles HEAD requests for blobs.
-func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request, registryURL, name, digest string) {
- upstreamURL := fmt.Sprintf("%s/v2/%s/blobs/%s", registryURL, name, digest)
+func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request, name, digest, token string) {
+ upstreamURL := fmt.Sprintf("%s/v2/%s/blobs/%s", h.registryURL, name, digest)
req, err := http.NewRequestWithContext(r.Context(), http.MethodHead, upstreamURL, nil)
if err != nil {
@@ -234,6 +288,8 @@ func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request,
return
}
+ req.Header.Set("Authorization", "Bearer "+token)
+
resp, err := h.proxy.HTTPClient.Do(req)
if err != nil {
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
@@ -250,24 +306,6 @@ func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request,
w.WriteHeader(resp.StatusCode)
}
-// registryForName resolves a client-visible OCI repository name to an upstream
-// registry and its repository name. Named upstreams use upstream/{name}/ as a
-// reserved prefix; all other names continue to target Docker Hub.
-func (h *ContainerHandler) registryForName(name string) (registryURL, upstreamName, cacheName string, ok bool) {
- parts := strings.SplitN(name, "/", registrySelectorParts)
- if len(parts) >= 2 && parts[0] == "upstream" {
- if len(parts) != registrySelectorParts || parts[2] == "" {
- return "", "", "", false
- }
- registryURL, ok = h.namedRegistries[parts[1]]
- if !ok || registryURL == "" {
- return "", "", "", false
- }
- return registryURL, parts[2], name, true
- }
- return h.registryURL, name, name, true
-}
-
// containerError writes an OCI-compliant error response.
func (h *ContainerHandler) containerError(w http.ResponseWriter, status int, code, message string) {
w.Header().Set("Content-Type", "application/json")
diff --git a/internal/handler/container_manifest.go b/internal/handler/container_manifest.go
deleted file mode 100644
index cf058ba..0000000
--- a/internal/handler/container_manifest.go
+++ /dev/null
@@ -1,251 +0,0 @@
-package handler
-
-import (
- "bytes"
- "context"
- "crypto/sha256"
- "database/sql"
- "encoding/hex"
- "fmt"
- "io"
- "net/http"
- "regexp"
- "strconv"
- "strings"
- "time"
-
- "github.com/git-pkgs/proxy/internal/database"
-)
-
-const (
- containerManifestCacheEcosystem = "oci-manifest"
- containerStaleWarning = `110 - "Response is Stale"`
-)
-
-var manifestDigestReferencePattern = regexp.MustCompile(`^[a-z0-9]+:[a-f0-9]+$`)
-
-type cachedContainerManifest struct {
- body []byte
- contentType string
- contentDigest string
- etag string
- size int64
- fetchedAt time.Time
-}
-
-func (h *ContainerHandler) serveManifest(w http.ResponseWriter, r *http.Request, registryURL, name, reference string) {
- accept := containerManifestAccept(r)
- cacheKey := h.containerManifestCacheKey(registryURL, name, reference, accept)
- cached, err := h.loadContainerManifest(r.Context(), cacheKey)
- if err != nil {
- h.proxy.Logger.Warn("failed to read cached container manifest", "error", err)
- cached = nil
- }
-
- immutable := manifestDigestReferencePattern.MatchString(reference)
- if cached != nil && (immutable || h.containerManifestFresh(cached)) {
- writeContainerManifest(w, r.Method, cached, false)
- return
- }
-
- upstreamURL := fmt.Sprintf("%s/v2/%s/manifests/%s", registryURL, name, reference)
- req, err := http.NewRequestWithContext(r.Context(), r.Method, upstreamURL, nil)
- if err != nil {
- h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create request")
- return
- }
- req.Header.Set("Accept", accept)
- if cached != nil && cached.etag != "" {
- req.Header.Set("If-None-Match", cached.etag)
- }
-
- resp, err := h.proxy.HTTPClient.Do(req)
- if err != nil {
- h.serveStaleManifestOrError(w, r, cached, err)
- return
- }
- defer func() { _ = resp.Body.Close() }()
-
- if resp.StatusCode == http.StatusNotModified && cached != nil {
- cached.fetchedAt = time.Now()
- if err := h.storeContainerManifest(r.Context(), cacheKey, cached); err != nil {
- h.proxy.Logger.Warn("failed to refresh cached container manifest", "error", err)
- }
- writeContainerManifest(w, r.Method, cached, false)
- return
- }
- if resp.StatusCode != http.StatusOK {
- if cached != nil && shouldServeStaleManifest(resp.StatusCode) {
- writeContainerManifest(w, r.Method, cached, true)
- return
- }
- copyContainerManifestHeaders(w.Header(), resp.Header)
- w.WriteHeader(resp.StatusCode)
- _, _ = io.Copy(w, resp.Body)
- return
- }
-
- if r.Method == http.MethodHead {
- copyContainerManifestHeaders(w.Header(), resp.Header)
- w.WriteHeader(http.StatusOK)
- return
- }
-
- body, err := h.proxy.ReadMetadata(resp.Body)
- if err != nil {
- h.serveStaleManifestOrError(w, r, cached, fmt.Errorf("reading manifest: %w", err))
- return
- }
- manifest := &cachedContainerManifest{
- body: body,
- contentType: resp.Header.Get("Content-Type"),
- contentDigest: resp.Header.Get("Docker-Content-Digest"),
- etag: resp.Header.Get("ETag"),
- size: int64(len(body)),
- fetchedAt: time.Now(),
- }
- if manifest.contentDigest == "" {
- manifest.contentDigest = sha256Digest(body)
- }
- if err := h.storeContainerManifest(r.Context(), cacheKey, manifest); err != nil {
- h.proxy.Logger.Warn("failed to cache container manifest", "error", err)
- }
- if manifest.contentDigest != reference && manifestDigestReferencePattern.MatchString(manifest.contentDigest) {
- digestKey := h.containerManifestCacheKey(registryURL, name, manifest.contentDigest, accept)
- if err := h.storeContainerManifest(r.Context(), digestKey, manifest); err != nil {
- h.proxy.Logger.Warn("failed to cache container manifest by digest", "error", err)
- }
- }
- writeContainerManifest(w, r.Method, manifest, false)
-}
-
-func (h *ContainerHandler) serveStaleManifestOrError(w http.ResponseWriter, r *http.Request, cached *cachedContainerManifest, err error) {
- if cached != nil {
- h.proxy.Logger.Warn("upstream manifest fetch failed, serving stale cache", "error", err)
- writeContainerManifest(w, r.Method, cached, true)
- return
- }
- h.proxy.Logger.Error("failed to fetch manifest", "error", err)
- h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
-}
-
-func (h *ContainerHandler) containerManifestFresh(manifest *cachedContainerManifest) bool {
- return h.proxy.MetadataTTL > 0 && !manifest.fetchedAt.IsZero() && time.Since(manifest.fetchedAt) < h.proxy.MetadataTTL
-}
-
-func (h *ContainerHandler) containerManifestCacheKey(registryURL, name, reference, accept string) string {
- identity := strings.Join([]string{registryURL, name, reference, accept}, "\x00")
- sum := sha256.Sum256([]byte(identity))
- return hex.EncodeToString(sum[:])
-}
-
-func (h *ContainerHandler) loadContainerManifest(ctx context.Context, cacheKey string) (*cachedContainerManifest, error) {
- if h.proxy.DB == nil || h.proxy.Storage == nil {
- return nil, nil
- }
- entry, err := h.proxy.DB.GetMetadataCache(containerManifestCacheEcosystem, cacheKey)
- if err != nil || entry == nil {
- return nil, err
- }
- reader, err := h.proxy.Storage.Open(ctx, entry.StoragePath)
- if err != nil {
- return nil, nil
- }
- defer func() { _ = reader.Close() }()
- body, err := h.proxy.ReadMetadata(reader)
- if err != nil {
- return nil, err
- }
-
- manifest := &cachedContainerManifest{body: body, size: int64(len(body))}
- if entry.ContentType.Valid {
- manifest.contentType = entry.ContentType.String
- }
- if entry.ContentDigest.Valid {
- manifest.contentDigest = entry.ContentDigest.String
- } else {
- manifest.contentDigest = sha256Digest(body)
- }
- if entry.ETag.Valid {
- manifest.etag = entry.ETag.String
- }
- if entry.Size.Valid {
- manifest.size = entry.Size.Int64
- }
- if entry.FetchedAt.Valid {
- manifest.fetchedAt = entry.FetchedAt.Time
- }
- return manifest, nil
-}
-
-func (h *ContainerHandler) storeContainerManifest(ctx context.Context, cacheKey string, manifest *cachedContainerManifest) error {
- if h.proxy.DB == nil || h.proxy.Storage == nil {
- return nil
- }
- storagePath := metadataStoragePath(containerManifestCacheEcosystem, cacheKey)
- size, _, err := h.proxy.Storage.Store(ctx, storagePath, bytes.NewReader(manifest.body))
- if err != nil {
- return fmt.Errorf("storing manifest: %w", err)
- }
- manifest.size = size
- return h.proxy.DB.UpsertMetadataCache(&database.MetadataCacheEntry{
- Ecosystem: containerManifestCacheEcosystem,
- Name: cacheKey,
- StoragePath: storagePath,
- ETag: sql.NullString{String: manifest.etag, Valid: manifest.etag != ""},
- ContentType: sql.NullString{String: manifest.contentType, Valid: manifest.contentType != ""},
- ContentDigest: sql.NullString{String: manifest.contentDigest, Valid: manifest.contentDigest != ""},
- Size: sql.NullInt64{Int64: size, Valid: true},
- FetchedAt: sql.NullTime{Time: manifest.fetchedAt, Valid: !manifest.fetchedAt.IsZero()},
- })
-}
-
-func writeContainerManifest(w http.ResponseWriter, method string, manifest *cachedContainerManifest, stale bool) {
- if manifest.contentType != "" {
- w.Header().Set("Content-Type", manifest.contentType)
- }
- w.Header().Set("Content-Length", strconv.FormatInt(manifest.size, 10))
- if manifest.contentDigest != "" {
- w.Header().Set("Docker-Content-Digest", manifest.contentDigest)
- }
- if manifest.etag != "" {
- w.Header().Set("ETag", manifest.etag)
- }
- if stale {
- w.Header().Set("Warning", containerStaleWarning)
- }
- w.WriteHeader(http.StatusOK)
- if method != http.MethodHead {
- _, _ = w.Write(manifest.body)
- }
-}
-
-func containerManifestAccept(r *http.Request) string {
- if accept := r.Header.Get("Accept"); accept != "" {
- return accept
- }
- return strings.Join([]string{
- "application/vnd.oci.image.manifest.v1+json",
- "application/vnd.oci.image.index.v1+json",
- "application/vnd.docker.distribution.manifest.v2+json",
- "application/vnd.docker.distribution.manifest.list.v2+json",
- "application/vnd.docker.distribution.manifest.v1+prettyjws",
- }, ", ")
-}
-
-func copyContainerManifestHeaders(destination, source http.Header) {
- for _, header := range []string{"Content-Type", "Content-Length", "Docker-Content-Digest", "ETag", "WWW-Authenticate"} {
- if value := source.Get(header); value != "" {
- destination.Set(header, value)
- }
- }
-}
-
-func shouldServeStaleManifest(status int) bool {
- return status == http.StatusTooManyRequests || status >= http.StatusInternalServerError
-}
-
-func sha256Digest(body []byte) string {
- digest := sha256.Sum256(body)
- return "sha256:" + hex.EncodeToString(digest[:])
-}
diff --git a/internal/handler/container_test.go b/internal/handler/container_test.go
index 04f00a7..853059e 100644
--- a/internal/handler/container_test.go
+++ b/internal/handler/container_test.go
@@ -1,15 +1,16 @@
package handler
import (
+ "bytes"
+ "context"
"encoding/json"
"io"
+ "log/slog"
"net/http"
"net/http/httptest"
- "strconv"
"testing"
- "time"
- upstreamhttp "github.com/git-pkgs/proxy/internal/httpclient"
+ "github.com/git-pkgs/proxy/internal/database"
"github.com/git-pkgs/registries/fetch"
)
@@ -134,568 +135,90 @@ func TestContainerHandler_parseTagsListPath(t *testing.T) {
}
}
-func TestContainerHandler_NamedOCIRegistryServesHelmArtifacts(t *testing.T) {
- digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd"
- manifest := `{"schemaVersion":2,"config":{"mediaType":"application/vnd.cncf.helm.config.v1+json"},"layers":[{"mediaType":"application/vnd.cncf.helm.chart.content.v1.tar+gzip","digest":"` + digest + `"}]}`
- upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- switch r.URL.Path {
- case "/v2/owner/demo/manifests/1.0.0":
- w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json")
- w.Header().Set("Docker-Content-Digest", digest)
- _, _ = io.WriteString(w, manifest)
- case "/v2/owner/demo/blobs/" + digest:
- w.Header().Set("Content-Type", "application/vnd.cncf.helm.chart.content.v1.tar+gzip")
- _, _ = io.WriteString(w, "chart archive")
- default:
- http.NotFound(w, r)
- }
- }))
- defer upstream.Close()
-
- proxy, _, _, _ := setupTestProxy(t)
- proxy.HTTPClient = upstream.Client()
- fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0))
- proxy.Fetcher = fetcher
- t.Cleanup(func() { _ = fetcher.Close() })
- h := NewContainerHandler(proxy, "http://proxy.example", map[string]string{"ghcr": upstream.URL})
-
- manifestResponse := httptest.NewRecorder()
- h.Routes().ServeHTTP(manifestResponse,
- httptest.NewRequest(http.MethodGet, "/upstream/ghcr/owner/demo/manifests/1.0.0", nil))
- if manifestResponse.Code != http.StatusOK {
- t.Fatalf("manifest status = %d, want 200: %s", manifestResponse.Code, manifestResponse.Body.String())
- }
- if got := manifestResponse.Header().Get("Content-Type"); got != "application/vnd.oci.image.manifest.v1+json" {
- t.Errorf("manifest Content-Type = %q", got)
- }
-
- blobResponse := httptest.NewRecorder()
- h.Routes().ServeHTTP(blobResponse,
- httptest.NewRequest(http.MethodGet, "/upstream/ghcr/owner/demo/blobs/"+digest, nil))
- if blobResponse.Code != http.StatusOK {
- t.Fatalf("blob status = %d, want 200: %s", blobResponse.Code, blobResponse.Body.String())
- }
- if got := blobResponse.Header().Get("Content-Type"); got != "application/vnd.cncf.helm.chart.content.v1.tar+gzip" {
- t.Errorf("blob Content-Type = %q", got)
- }
-}
-
-func TestContainerHandler_BlobDownload_DiscoversBearerChallenge(t *testing.T) {
- digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd"
- registryRequests := 0
- tokenRequests := 0
- var upstream *httptest.Server
- upstream = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- switch r.URL.Path {
- case "/token":
- tokenRequests++
- w.Header().Set("Content-Type", "application/json")
- _ = json.NewEncoder(w).Encode(map[string]any{
- "token": "discovered-token",
- "expires_in": 3600,
- })
- case "/v2/library/nginx/blobs/" + digest:
- registryRequests++
- if r.Header.Get("Authorization") != "Bearer discovered-token" {
- w.Header().Set("WWW-Authenticate", `Bearer realm="`+upstream.URL+`/token",service="registry.test",scope="repository:library/nginx:pull"`)
- http.Error(w, "authentication required", http.StatusUnauthorized)
- return
- }
- w.Header().Set("Content-Type", "application/octet-stream")
- _, _ = io.WriteString(w, "upstream blob")
- default:
- http.NotFound(w, r)
- }
- }))
- defer upstream.Close()
-
- proxy, _, _, _ := setupTestProxy(t)
- authTransport := upstreamhttp.NewTransport(http.DefaultTransport, nil)
- client := &http.Client{Transport: authTransport}
- artifactFetcher := fetch.NewFetcher(
- fetch.WithHTTPClient(client),
- fetch.WithMaxRetries(0),
- )
- t.Cleanup(func() { _ = artifactFetcher.Close() })
- proxy.Fetcher = artifactFetcher
- proxy.HTTPClient = client
-
- h := &ContainerHandler{
- proxy: proxy,
- registryURL: upstream.URL,
- proxyURL: "http://localhost:8080",
- }
-
- for range 2 {
- req := httptest.NewRequest(http.MethodGet, "/library/nginx/blobs/"+digest, nil)
- w := httptest.NewRecorder()
- h.Routes().ServeHTTP(w, req)
- if w.Code != http.StatusOK {
- t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
- }
- if got := w.Body.String(); got != "upstream blob" {
- t.Errorf("body = %q, want %q", got, "upstream blob")
- }
- }
-
- if tokenRequests != 1 {
- t.Errorf("token requests = %d, want 1", tokenRequests)
- }
- if registryRequests != 2 {
- t.Errorf("registry requests = %d, want 2", registryRequests)
- }
-}
-
-func TestContainerHandler_CachedImagePullSurvivesRegistryAndTokenOutages(t *testing.T) {
- digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd"
- manifest := `{"schemaVersion":2,"mediaType":"application/vnd.oci.image.manifest.v1+json"}`
- blob := "cached image blob"
- registryAvailable := true
- tokenAvailable := true
- registryRequests := 0
- tokenRequests := 0
-
- tokenServer := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
- tokenRequests++
- if !tokenAvailable {
- http.Error(w, "token service unavailable", http.StatusServiceUnavailable)
- return
- }
+func TestContainerHandler_BlobDownload_CachesWithAuth(t *testing.T) {
+ // Set up a mock auth server that returns a token
+ authServer := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
- _ = json.NewEncoder(w).Encode(map[string]any{
- "token": "discovered-token",
- "expires_in": 3600,
- })
+ _ = json.NewEncoder(w).Encode(map[string]string{"token": "test-token-123"})
}))
- defer tokenServer.Close()
+ defer authServer.Close()
- registryServer := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- registryRequests++
- if !registryAvailable {
- http.Error(w, "registry unavailable", http.StatusServiceUnavailable)
- return
- }
- if r.Header.Get("Authorization") != "Bearer discovered-token" {
- w.Header().Set("WWW-Authenticate", `Bearer realm="`+tokenServer.URL+`",service="registry.test",scope="repository:library/nginx:pull"`)
- http.Error(w, "authentication required", http.StatusUnauthorized)
- return
- }
-
- switch r.URL.Path {
- case "/v2/library/nginx/manifests/latest":
- w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json")
- w.Header().Set("Docker-Content-Digest", digest)
- _, _ = io.WriteString(w, manifest)
- case "/v2/library/nginx/blobs/" + digest:
- w.Header().Set("Content-Type", "application/octet-stream")
- _, _ = io.WriteString(w, blob)
- default:
- http.NotFound(w, r)
- }
- }))
- defer registryServer.Close()
-
- warmProxy, db, store, _ := setupTestProxy(t)
- warmClient := &http.Client{Transport: upstreamhttp.NewTransport(http.DefaultTransport, nil)}
- warmFetcher := fetch.NewFetcher(
- fetch.WithHTTPClient(warmClient),
- fetch.WithMaxRetries(0),
- )
- t.Cleanup(func() { _ = warmFetcher.Close() })
- warmProxy.Fetcher = warmFetcher
- warmProxy.HTTPClient = warmClient
- warmProxy.MetadataTTL = time.Hour
- warmHandler := (&ContainerHandler{
- proxy: warmProxy,
- registryURL: registryServer.URL,
- proxyURL: "http://localhost:8080",
- }).Routes()
-
- for _, request := range []struct {
- path string
- body string
- }{
- {path: "/library/nginx/manifests/latest", body: manifest},
- {path: "/library/nginx/blobs/" + digest, body: blob},
- } {
- response := httptest.NewRecorder()
- warmHandler.ServeHTTP(response, httptest.NewRequest(http.MethodGet, request.path, nil))
- if response.Code != http.StatusOK {
- t.Fatalf("warming %s: status = %d, want %d; body: %s", request.path, response.Code, http.StatusOK, response.Body.String())
- }
- if got := response.Body.String(); got != request.body {
- t.Fatalf("warming %s: body = %q, want %q", request.path, got, request.body)
- }
+ // Set up mock fetcher that captures headers
+ var capturedHeaders http.Header
+ mf := &mockFetcherWithHeaders{
+ fetchFn: func(_ context.Context, _ string, headers http.Header) (*fetch.Artifact, error) {
+ capturedHeaders = headers
+ return &fetch.Artifact{
+ Body: io.NopCloser(bytes.NewReader([]byte("blob-content"))),
+ Size: 12,
+ ContentType: "application/octet-stream",
+ }, nil
+ },
}
- warmRegistryRequests := registryRequests
- warmTokenRequests := tokenRequests
- registryAvailable = false
- tokenAvailable = false
-
- offlineClient := &http.Client{Transport: upstreamhttp.NewTransport(http.DefaultTransport, nil)}
- offlineFetcher := fetch.NewFetcher(
- fetch.WithHTTPClient(offlineClient),
- fetch.WithMaxRetries(0),
- )
- t.Cleanup(func() { _ = offlineFetcher.Close() })
- offlineProxy := NewProxy(db, store, offlineFetcher, fetch.NewResolver(), warmProxy.Logger)
- offlineProxy.HTTPClient = offlineClient
- offlineProxy.MetadataTTL = time.Hour
- offlineHandler := (&ContainerHandler{
- proxy: offlineProxy,
- registryURL: registryServer.URL,
- proxyURL: "http://localhost:8080",
- }).Routes()
-
- for _, request := range []struct {
- name string
- path string
- body string
- }{
- {name: "tag manifest", path: "/library/nginx/manifests/latest", body: manifest},
- {name: "digest manifest", path: "/library/nginx/manifests/" + digest, body: manifest},
- {name: "blob", path: "/library/nginx/blobs/" + digest, body: blob},
- } {
- t.Run(request.name, func(t *testing.T) {
- response := httptest.NewRecorder()
- offlineHandler.ServeHTTP(response, httptest.NewRequest(http.MethodGet, request.path, nil))
- if response.Code != http.StatusOK {
- t.Fatalf("status = %d, want %d; body: %s", response.Code, http.StatusOK, response.Body.String())
- }
- if got := response.Body.String(); got != request.body {
- t.Errorf("body = %q, want %q", got, request.body)
- }
- if got := response.Header().Get("Docker-Content-Digest"); got != digest {
- t.Errorf("Docker-Content-Digest = %q, want %q", got, digest)
- }
- })
+ dir := t.TempDir()
+ db, err := database.Create(dir + "/test.db")
+ if err != nil {
+ t.Fatalf("failed to create test database: %v", err)
}
+ t.Cleanup(func() { _ = db.Close() })
- if registryRequests != warmRegistryRequests {
- t.Errorf("offline registry requests = %d, want 0", registryRequests-warmRegistryRequests)
+ store := newMockStorage()
+ logger := slog.New(slog.NewTextHandler(io.Discard, nil))
+ proxy := &Proxy{
+ DB: db,
+ Storage: store,
+ Fetcher: mf,
+ Logger: logger,
+ HTTPClient: &http.Client{},
}
- if tokenRequests != warmTokenRequests {
- t.Errorf("offline token requests = %d, want 0", tokenRequests-warmTokenRequests)
- }
-}
-
-func TestContainerHandler_BlobDownload_CacheHitSkipsAuth(t *testing.T) {
- proxy, db, store, fetcher := setupTestProxy(t)
- digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd"
- seedPackage(t, db, store, "oci", "library/nginx", digest, digest, "cached blob")
-
- upstreamRequests := 0
- upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
- upstreamRequests++
- http.Error(w, "upstream unavailable", http.StatusServiceUnavailable)
- }))
- defer upstream.Close()
h := &ContainerHandler{
proxy: proxy,
- registryURL: upstream.URL,
+ registryURL: "https://registry-1.docker.io",
+ authURL: authServer.URL,
proxyURL: "http://localhost:8080",
}
- req := httptest.NewRequest(http.MethodGet, "/library/nginx/blobs/"+digest, nil)
+ handler := h.Routes()
+ req := httptest.NewRequest(http.MethodGet, "/library/nginx/blobs/sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd", nil)
w := httptest.NewRecorder()
- h.Routes().ServeHTTP(w, req)
+ handler.ServeHTTP(w, req)
if w.Code != http.StatusOK {
- t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
+ t.Errorf("got status %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
}
- if got := w.Body.String(); got != "cached blob" {
- t.Errorf("body = %q, want %q", got, "cached blob")
+
+ // Verify auth header was passed to the fetcher
+ if capturedHeaders == nil {
+ t.Fatal("expected headers to be passed to fetcher, got nil")
}
- if upstreamRequests != 0 {
- t.Errorf("upstream requests = %d, want 0", upstreamRequests)
+ auth := capturedHeaders.Get("Authorization")
+ if auth != "Bearer test-token-123" {
+ t.Errorf("Authorization = %q, want %q", auth, "Bearer test-token-123")
}
- if fetcher.fetchCalled {
- t.Error("fetcher should not be called on cache hit")
+
+ // Verify response headers
+ if got := w.Header().Get("Docker-Content-Digest"); got != "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd" {
+ t.Errorf("Docker-Content-Digest = %q, want digest", got)
}
}
-func TestContainerHandler_BlobHead_CacheHitSkipsUpstreamAndAuth(t *testing.T) {
- proxy, db, store, fetcher := setupTestProxy(t)
- digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd"
- seedPackage(t, db, store, "oci", "library/nginx", digest, digest, "cached blob")
-
- upstreamRequests := 0
- upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
- upstreamRequests++
- http.Error(w, "upstream unavailable", http.StatusServiceUnavailable)
- }))
- defer upstream.Close()
- proxy.HTTPClient = upstream.Client()
-
- h := &ContainerHandler{
- proxy: proxy,
- registryURL: upstream.URL,
- proxyURL: "http://localhost:8080",
- }
-
- req := httptest.NewRequest(http.MethodHead, "/library/nginx/blobs/"+digest, nil)
- w := httptest.NewRecorder()
- h.Routes().ServeHTTP(w, req)
-
- if w.Code != http.StatusOK {
- t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
- }
- if got := w.Header().Get("Docker-Content-Digest"); got != digest {
- t.Errorf("Docker-Content-Digest = %q, want %q", got, digest)
- }
- if got := w.Header().Get("Content-Length"); got != "11" {
- t.Errorf("Content-Length = %q, want %q", got, "11")
- }
- if w.Body.Len() != 0 {
- t.Errorf("HEAD response body length = %d, want 0", w.Body.Len())
- }
- if upstreamRequests != 0 {
- t.Errorf("upstream requests = %d, want 0", upstreamRequests)
- }
- if fetcher.fetchCalled {
- t.Error("fetcher should not be called on cache hit")
- }
+// mockFetcherWithHeaders captures headers passed to FetchWithHeaders.
+type mockFetcherWithHeaders struct {
+ fetchFn func(ctx context.Context, url string, headers http.Header) (*fetch.Artifact, error)
}
-func TestContainerHandler_BlobHead_DirectServeRedirects(t *testing.T) {
- proxy, db, store, fetcher := setupTestProxy(t)
- digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd"
- seedPackage(t, db, store, "oci", "library/nginx", digest, digest, "cached blob")
- store.signedURL = "https://storage.example.test/cached-blob?signature=test"
- proxy.DirectServe = true
-
- h := &ContainerHandler{
- proxy: proxy,
- registryURL: "https://registry.example.test",
- proxyURL: "http://localhost:8080",
- }
-
- req := httptest.NewRequest(http.MethodHead, "/library/nginx/blobs/"+digest, nil)
- w := httptest.NewRecorder()
- h.Routes().ServeHTTP(w, req)
-
- if w.Code != http.StatusFound {
- t.Fatalf("status = %d, want %d", w.Code, http.StatusFound)
- }
- if got := w.Header().Get("Location"); got != store.signedURL {
- t.Errorf("Location = %q, want %q", got, store.signedURL)
- }
- wantETag := `"` + sha256Hex("cached blob") + `"`
- if got := w.Header().Get("ETag"); got != wantETag {
- t.Errorf("ETag = %q, want %q", got, wantETag)
- }
- if w.Body.Len() != 0 {
- t.Errorf("HEAD response body length = %d, want 0", w.Body.Len())
- }
- if fetcher.fetchCalled {
- t.Error("fetcher should not be called on cache hit")
- }
+func (f *mockFetcherWithHeaders) Fetch(ctx context.Context, url string) (*fetch.Artifact, error) {
+ return f.FetchWithHeaders(ctx, url, nil)
}
-func TestContainerHandler_ManifestByDigest_CacheHitSkipsUpstream(t *testing.T) {
- digest := "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
- manifest := `{"schemaVersion":2,"mediaType":"application/vnd.oci.image.manifest.v1+json"}`
- upstreamAvailable := true
- upstreamRequests := 0
- upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- upstreamRequests++
- if !upstreamAvailable {
- http.Error(w, "upstream unavailable", http.StatusServiceUnavailable)
- return
- }
- if r.URL.Path != "/v2/library/nginx/manifests/"+digest {
- http.NotFound(w, r)
- return
- }
- w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json")
- w.Header().Set("Docker-Content-Digest", digest)
- w.Header().Set("ETag", `"manifest-etag"`)
- if r.Method != http.MethodHead {
- _, _ = io.WriteString(w, manifest)
- }
- }))
- defer upstream.Close()
-
- proxy, _, _, _ := setupTestProxy(t)
- proxy.HTTPClient = upstream.Client()
- h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"}
-
- first := httptest.NewRecorder()
- h.Routes().ServeHTTP(first, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/"+digest, nil))
- if first.Code != http.StatusOK {
- t.Fatalf("initial status = %d, want %d; body: %s", first.Code, http.StatusOK, first.Body.String())
- }
- if first.Body.String() != manifest {
- t.Fatalf("initial body = %q, want %q", first.Body.String(), manifest)
- }
-
- upstreamAvailable = false
- second := httptest.NewRecorder()
- h.Routes().ServeHTTP(second, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/"+digest, nil))
- if second.Code != http.StatusOK {
- t.Fatalf("cached status = %d, want %d; body: %s", second.Code, http.StatusOK, second.Body.String())
- }
- if second.Body.String() != manifest {
- t.Errorf("cached body = %q, want %q", second.Body.String(), manifest)
- }
- if got := second.Header().Get("Docker-Content-Digest"); got != digest {
- t.Errorf("cached Docker-Content-Digest = %q, want %q", got, digest)
- }
-
- head := httptest.NewRecorder()
- h.Routes().ServeHTTP(head, httptest.NewRequest(http.MethodHead, "/library/nginx/manifests/"+digest, nil))
- if head.Code != http.StatusOK {
- t.Fatalf("cached HEAD status = %d, want %d", head.Code, http.StatusOK)
- }
- wantLength := strconv.Itoa(len(manifest))
- if got := head.Header().Get("Content-Length"); got != wantLength {
- t.Errorf("cached HEAD Content-Length = %q, want %q", got, wantLength)
- }
- if head.Body.Len() != 0 {
- t.Errorf("cached HEAD body length = %d, want 0", head.Body.Len())
- }
- if upstreamRequests != 1 {
- t.Errorf("upstream requests = %d, want 1", upstreamRequests)
- }
+func (f *mockFetcherWithHeaders) FetchWithHeaders(ctx context.Context, url string, headers http.Header) (*fetch.Artifact, error) {
+ return f.fetchFn(ctx, url, headers)
}
-func TestContainerHandler_ManifestByTag_UsesStaleCacheOnUpstreamFailure(t *testing.T) {
- digest := "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
- manifest := `{"schemaVersion":2,"mediaType":"application/vnd.oci.image.index.v1+json"}`
- upstreamAvailable := true
- upstreamRequests := 0
- upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
- upstreamRequests++
- if !upstreamAvailable {
- http.Error(w, "upstream unavailable", http.StatusServiceUnavailable)
- return
- }
- w.Header().Set("Content-Type", "application/vnd.oci.image.index.v1+json")
- w.Header().Set("Docker-Content-Digest", digest)
- _, _ = io.WriteString(w, manifest)
- }))
- defer upstream.Close()
-
- proxy, _, _, _ := setupTestProxy(t)
- proxy.HTTPClient = upstream.Client()
- proxy.MetadataTTL = 0
- h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"}
-
- first := httptest.NewRecorder()
- h.Routes().ServeHTTP(first, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil))
- if first.Code != http.StatusOK {
- t.Fatalf("initial status = %d, want %d; body: %s", first.Code, http.StatusOK, first.Body.String())
- }
-
- upstreamAvailable = false
- second := httptest.NewRecorder()
- h.Routes().ServeHTTP(second, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil))
- if second.Code != http.StatusOK {
- t.Fatalf("stale status = %d, want %d; body: %s", second.Code, http.StatusOK, second.Body.String())
- }
- if second.Body.String() != manifest {
- t.Errorf("stale body = %q, want %q", second.Body.String(), manifest)
- }
- if got := second.Header().Get("Warning"); got != `110 - "Response is Stale"` {
- t.Errorf("Warning = %q, want stale warning", got)
- }
- if got := second.Header().Get("Docker-Content-Digest"); got != digest {
- t.Errorf("stale Docker-Content-Digest = %q, want %q", got, digest)
- }
- if upstreamRequests != 2 {
- t.Errorf("upstream requests = %d, want 2", upstreamRequests)
- }
-}
-
-func TestContainerHandler_ManifestByTag_CachesDigestAlias(t *testing.T) {
- digest := "sha256:cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc"
- manifest := `{"schemaVersion":2,"mediaType":"application/vnd.oci.image.manifest.v1+json"}`
- upstreamAvailable := true
- upstreamRequests := 0
- upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- upstreamRequests++
- if !upstreamAvailable {
- http.Error(w, "upstream unavailable", http.StatusServiceUnavailable)
- return
- }
- if r.URL.Path != "/v2/library/nginx/manifests/latest" {
- http.NotFound(w, r)
- return
- }
- w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json")
- w.Header().Set("Docker-Content-Digest", digest)
- _, _ = io.WriteString(w, manifest)
- }))
- defer upstream.Close()
-
- proxy, _, _, _ := setupTestProxy(t)
- proxy.HTTPClient = upstream.Client()
- h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"}
-
- first := httptest.NewRecorder()
- h.Routes().ServeHTTP(first, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil))
- if first.Code != http.StatusOK {
- t.Fatalf("tag status = %d, want %d; body: %s", first.Code, http.StatusOK, first.Body.String())
- }
-
- upstreamAvailable = false
- byDigest := httptest.NewRecorder()
- h.Routes().ServeHTTP(byDigest, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/"+digest, nil))
- if byDigest.Code != http.StatusOK {
- t.Fatalf("digest status = %d, want %d; body: %s", byDigest.Code, http.StatusOK, byDigest.Body.String())
- }
- if byDigest.Body.String() != manifest {
- t.Errorf("digest body = %q, want %q", byDigest.Body.String(), manifest)
- }
- if got := byDigest.Header().Get("Docker-Content-Digest"); got != digest {
- t.Errorf("Docker-Content-Digest = %q, want %q", got, digest)
- }
- if upstreamRequests != 1 {
- t.Errorf("upstream requests = %d, want 1", upstreamRequests)
- }
-}
-
-func TestContainerHandler_ManifestByTag_StaleHeadChecksUpstream(t *testing.T) {
- oldDigest := "sha256:dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd"
- newDigest := "sha256:eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee"
- currentDigest := oldDigest
- upstreamRequests := 0
- upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- upstreamRequests++
- w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json")
- w.Header().Set("Docker-Content-Digest", currentDigest)
- w.Header().Set("ETag", `"`+currentDigest+`"`)
- if r.Method != http.MethodHead {
- _, _ = io.WriteString(w, `{"schemaVersion":2}`)
- }
- }))
- defer upstream.Close()
-
- proxy, _, _, _ := setupTestProxy(t)
- proxy.HTTPClient = upstream.Client()
- proxy.MetadataTTL = 0
- h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"}
-
- first := httptest.NewRecorder()
- h.Routes().ServeHTTP(first, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil))
- if first.Code != http.StatusOK {
- t.Fatalf("initial status = %d, want %d", first.Code, http.StatusOK)
- }
-
- currentDigest = newDigest
- head := httptest.NewRecorder()
- h.Routes().ServeHTTP(head, httptest.NewRequest(http.MethodHead, "/library/nginx/manifests/latest", nil))
- if head.Code != http.StatusOK {
- t.Fatalf("HEAD status = %d, want %d", head.Code, http.StatusOK)
- }
- if got := head.Header().Get("Docker-Content-Digest"); got != newDigest {
- t.Errorf("Docker-Content-Digest = %q, want %q", got, newDigest)
- }
- if upstreamRequests != 2 {
- t.Errorf("upstream requests = %d, want 2", upstreamRequests)
- }
+func (f *mockFetcherWithHeaders) Head(_ context.Context, _ string) (int64, string, error) {
+ return 0, "", nil
}
func TestContainerHandler_Routes_VersionCheck(t *testing.T) {
diff --git a/internal/handler/cran.go b/internal/handler/cran.go
index 2fc4fab..0ecd2a3 100644
--- a/internal/handler/cran.go
+++ b/internal/handler/cran.go
@@ -72,7 +72,8 @@ func (h *CRANHandler) handleSourceDownload(w http.ResponseWriter, r *http.Reques
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "cran", name, version, filename, upstreamURL)
if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch package")
+ h.proxy.Logger.Error("failed to get artifact", "error", err)
+ http.Error(w, "failed to fetch package", http.StatusBadGateway)
return
}
@@ -106,7 +107,8 @@ func (h *CRANHandler) handleBinaryDownload(w http.ResponseWriter, r *http.Reques
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "cran", name, storageVersion, filename, upstreamURL)
if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch package")
+ h.proxy.Logger.Error("failed to get artifact", "error", err)
+ http.Error(w, "failed to fetch package", http.StatusBadGateway)
return
}
diff --git a/internal/handler/debian.go b/internal/handler/debian.go
index b48f4fc..b767f6d 100644
--- a/internal/handler/debian.go
+++ b/internal/handler/debian.go
@@ -21,13 +21,10 @@ type DebianHandler struct {
}
// NewDebianHandler creates a new Debian/APT protocol handler.
-func NewDebianHandler(proxy *Proxy, proxyURL string, upstreamURL string) *DebianHandler {
- if upstreamURL == "" {
- upstreamURL = debianUpstream
- }
+func NewDebianHandler(proxy *Proxy, proxyURL string) *DebianHandler {
return &DebianHandler{
proxy: proxy,
- upstreamURL: strings.TrimSuffix(upstreamURL, "/"),
+ upstreamURL: debianUpstream,
proxyURL: strings.TrimSuffix(proxyURL, "/"),
}
}
@@ -84,7 +81,8 @@ func (h *DebianHandler) handlePackageDownload(w http.ResponseWriter, r *http.Req
result, err := h.proxy.GetOrFetchArtifactFromURL(
r.Context(), "deb", name, version, filename, downloadURL)
if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch package")
+ h.proxy.Logger.Error("failed to get debian package", "error", err)
+ http.Error(w, "failed to fetch package", http.StatusBadGateway)
return
}
diff --git a/internal/handler/debian_test.go b/internal/handler/debian_test.go
index b086fdf..dfdd326 100644
--- a/internal/handler/debian_test.go
+++ b/internal/handler/debian_test.go
@@ -12,17 +12,12 @@ func TestDebianHandler_parsePoolPath(t *testing.T) {
{"pool/main/libn/libncurses/libncurses6_6.2-1_amd64.deb", "libncurses6", "6.2-1", "amd64"},
{"pool/contrib/v/virtualbox/virtualbox_6.1.38-1_amd64.deb", "virtualbox", "6.1.38-1", "amd64"},
{"pool/main/g/git/git_2.39.2-1_arm64.deb", "git", "2.39.2-1", "arm64"},
- {
- "pool/universe/n/nmap/nmap_7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1_amd64.deb",
- "nmap", "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1", "amd64",
- },
- {"pool/main/o/openssl/openssl_3.0.2-0ubuntu1.15~build1_amd64.deb", "openssl", "3.0.2-0ubuntu1.15~build1", "amd64"},
{"invalid/path", "", "", ""},
{"pool/main/n/nginx/nginx.deb", "", "", ""},
})
}
func TestDebianHandler_Routes(t *testing.T) {
- h := NewDebianHandler(nil, "http://localhost:8080", "")
+ h := NewDebianHandler(nil, "http://localhost:8080")
assertRoutesBasics(t, h.Routes(), "/dists/stable/Release", "/pool/../../../etc/passwd")
}
diff --git a/internal/handler/download_test.go b/internal/handler/download_test.go
index dda3e84..980e234 100644
--- a/internal/handler/download_test.go
+++ b/internal/handler/download_test.go
@@ -49,7 +49,7 @@ func seedPackageWithPURL(t *testing.T, db *database.DB, store *mockStorage, ecos
Filename: filename,
UpstreamURL: "https://example.com/" + filename,
StoragePath: sql.NullString{String: storagePath, Valid: true},
- ContentHash: sql.NullString{String: sha256Hex(content), Valid: true},
+ ContentHash: sql.NullString{String: "abc123", Valid: true},
Size: sql.NullInt64{Int64: int64(len(content)), Valid: true},
ContentType: sql.NullString{String: "application/octet-stream", Valid: true},
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
@@ -1165,7 +1165,7 @@ func TestDebianHandler_DownloadCacheMiss(t *testing.T) {
ContentType: "application/vnd.debian.binary-package",
}
- h := NewDebianHandler(proxy, "http://localhost", "")
+ h := NewDebianHandler(proxy, "http://localhost")
srv := httptest.NewServer(h.Routes())
defer srv.Close()
diff --git a/internal/handler/filename_download.go b/internal/handler/filename_download.go
deleted file mode 100644
index bedec16..0000000
--- a/internal/handler/filename_download.go
+++ /dev/null
@@ -1,39 +0,0 @@
-package handler
-
-import (
- "net/http"
- "strings"
-)
-
-type filenameDownload struct {
- ecosystem string
- suffix string
- parseErr string
- fetchErr string
- parse func(string) (name, version string)
-}
-
-func (p *Proxy) handleFilenameDownload(w http.ResponseWriter, r *http.Request, d filenameDownload) {
- filename := r.PathValue("filename")
- if filename == "" || !strings.HasSuffix(filename, d.suffix) {
- http.Error(w, "invalid filename", http.StatusBadRequest)
- return
- }
-
- name, version := d.parse(filename)
- if name == "" || version == "" {
- http.Error(w, d.parseErr, http.StatusBadRequest)
- return
- }
-
- p.Logger.Info(d.ecosystem+" download request",
- "name", name, "version", version, "filename", filename)
-
- result, err := p.GetOrFetchArtifact(r.Context(), d.ecosystem, name, version, filename)
- if err != nil {
- p.serveArtifactError(w, err, d.fetchErr)
- return
- }
-
- ServeArtifact(w, result)
-}
diff --git a/internal/handler/gem.go b/internal/handler/gem.go
index 260568a..9ec57e3 100644
--- a/internal/handler/gem.go
+++ b/internal/handler/gem.go
@@ -8,6 +8,8 @@ import (
"net/http"
"strings"
"time"
+
+ "github.com/git-pkgs/purl"
)
const (
@@ -58,13 +60,30 @@ func (h *GemHandler) Routes() http.Handler {
// handleDownload serves a gem file, fetching and caching from upstream if needed.
func (h *GemHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
- h.proxy.handleFilenameDownload(w, r, filenameDownload{
- ecosystem: "gem",
- suffix: ".gem",
- parseErr: "could not parse gem filename",
- fetchErr: "failed to fetch gem",
- parse: h.parseGemFilename,
- })
+ filename := r.PathValue("filename")
+ if filename == "" || !strings.HasSuffix(filename, ".gem") {
+ http.Error(w, "invalid filename", http.StatusBadRequest)
+ return
+ }
+
+ // Extract name and version from filename (e.g., "rails-7.1.0.gem")
+ name, version := h.parseGemFilename(filename)
+ if name == "" || version == "" {
+ http.Error(w, "could not parse gem filename", http.StatusBadRequest)
+ return
+ }
+
+ h.proxy.Logger.Info("gem download request",
+ "name", name, "version", version, "filename", filename)
+
+ result, err := h.proxy.GetOrFetchArtifact(r.Context(), "gem", name, version, filename)
+ if err != nil {
+ h.proxy.Logger.Error("failed to get artifact", "error", err)
+ http.Error(w, "failed to fetch gem", http.StatusBadGateway)
+ return
+ }
+
+ ServeArtifact(w, result)
}
// parseGemFilename extracts name and version from a gem filename.
@@ -247,7 +266,7 @@ func (h *GemHandler) fetchFilteredVersions(r *http.Request, name string) (map[st
return nil, err
}
- packagePURL := canonicalPackagePURL("gem", name)
+ packagePURL := purl.MakePURLString("gem", name, "")
filtered := make(map[string]bool)
for _, v := range versions {
diff --git a/internal/handler/go.go b/internal/handler/go.go
index cf40aa1..955a89c 100644
--- a/internal/handler/go.go
+++ b/internal/handler/go.go
@@ -1,12 +1,9 @@
package handler
import (
- "errors"
"fmt"
"net/http"
"strings"
-
- "github.com/git-pkgs/registries/fetch"
)
const (
@@ -103,10 +100,6 @@ func (h *GoHandler) handleDownload(w http.ResponseWriter, r *http.Request, modul
result, err := h.proxy.GetOrFetchArtifact(r.Context(), "golang", decodedModule, version, filename)
if err != nil {
- if errors.Is(err, fetch.ErrNotFound) {
- http.Error(w, "not found", http.StatusNotFound)
- return
- }
h.proxy.Logger.Error("failed to get artifact", "error", err)
http.Error(w, "failed to fetch module", http.StatusBadGateway)
return
diff --git a/internal/handler/go_test.go b/internal/handler/go_test.go
index ae998c9..da4ea63 100644
--- a/internal/handler/go_test.go
+++ b/internal/handler/go_test.go
@@ -1,49 +1,9 @@
package handler
import (
- "errors"
- "net/http"
- "net/http/httptest"
"testing"
-
- "github.com/git-pkgs/registries/fetch"
)
-func TestGoModuleDownloadUpstreamErrors(t *testing.T) {
- tests := []struct {
- name string
- fetchErr error
- wantStatus int
- }{
- {
- name: "module not found",
- fetchErr: fetch.ErrNotFound,
- wantStatus: http.StatusNotFound,
- },
- {
- name: "upstream failure",
- fetchErr: errors.New("connection refused"),
- wantStatus: http.StatusBadGateway,
- },
- }
-
- for _, tt := range tests {
- t.Run(tt.name, func(t *testing.T) {
- proxy, _, _, fetcher := setupTestProxy(t)
- fetcher.fetchErr = tt.fetchErr
- handler := NewGoHandler(proxy, "http://localhost:8080")
-
- req := httptest.NewRequest(http.MethodGet, "/example.com/mod/@v/v1.0.0.zip", nil)
- resp := httptest.NewRecorder()
- handler.Routes().ServeHTTP(resp, req)
-
- if resp.Code != tt.wantStatus {
- t.Fatalf("status = %d, want %d", resp.Code, tt.wantStatus)
- }
- })
- }
-}
-
func TestDecodeGoModule(t *testing.T) {
tests := []struct {
encoded string
diff --git a/internal/handler/handler.go b/internal/handler/handler.go
index 6c65682..d06ca83 100644
--- a/internal/handler/handler.go
+++ b/internal/handler/handler.go
@@ -13,7 +13,6 @@ import (
"net/url"
"strconv"
"strings"
- "sync"
"time"
"github.com/git-pkgs/cooldown"
@@ -49,21 +48,6 @@ func hasDotDotSegment(path string) bool {
const defaultHTTPTimeout = 30 * time.Second
-const artifactCopyBufferSize = 32 << 10
-
-var artifactCopyBufferPool = sync.Pool{ //nolint:gochecknoglobals // shared across artifact responses
- New: func() any {
- buffer := make([]byte, artifactCopyBufferSize)
- return &buffer
- },
-}
-
-// canonicalPackagePURL returns a versionless PURL in canonical form so cooldown
-// lookups match keys produced by config.CooldownConfig.NormalizedPackages.
-func canonicalPackagePURL(ecosystem, name string) string {
- return purl.MakePURLString(ecosystem, name, "")
-}
-
const contentTypeJSON = "application/json"
const headerAcceptEncoding = "Accept-Encoding"
@@ -112,7 +96,6 @@ type Proxy struct {
// storage at an internal one.
DirectServeBaseURL string
HTTPClient *http.Client
- AuthForURL func(string) (headerName, headerValue string)
}
// NewProxy creates a new Proxy with the given dependencies.
@@ -144,59 +127,41 @@ type CacheResult struct {
// GetOrFetchArtifact retrieves an artifact from cache or fetches from upstream.
func (p *Proxy) GetOrFetchArtifact(ctx context.Context, ecosystem, name, version, filename string) (*CacheResult, error) {
- if cached, err := p.GetCachedArtifact(ctx, ecosystem, name, version, filename); err != nil {
+ pkgPURL := purl.MakePURLString(ecosystem, name, "")
+ versionPURL := purl.MakePURLString(ecosystem, name, version)
+
+ if cached, err := p.checkCache(ctx, pkgPURL, versionPURL, filename); err != nil {
return nil, err
} else if cached != nil {
return cached, nil
}
- metrics.RecordCacheMiss(ecosystem)
- pkgPURL := purl.MakePURLString(ecosystem, name, "")
- versionPURL := purl.MakePURLString(ecosystem, name, version)
return p.fetchAndCache(ctx, ecosystem, name, version, filename, pkgPURL, versionPURL)
}
-// GetCachedArtifact retrieves an artifact from cache without contacting an upstream.
-// It returns nil when no usable cache entry exists.
-func (p *Proxy) GetCachedArtifact(ctx context.Context, ecosystem, name, version, filename string) (*CacheResult, error) {
- pkgPURL := purl.MakePURLString(ecosystem, name, "")
- versionPURL := purl.MakePURLString(ecosystem, name, version)
- return p.checkCache(ctx, pkgPURL, versionPURL, filename)
-}
-
-// ClearCachedArtifact removes both an artifact cache record and its stored
-// bytes after an external integrity check fails.
-func (p *Proxy) ClearCachedArtifact(ctx context.Context, ecosystem, name, version, filename string) error {
- if p.DB == nil || p.Storage == nil {
- return nil
- }
- pkgPURL := purl.MakePURLString(ecosystem, name, "")
- versionPURL := purl.MakePURLString(ecosystem, name, version)
- cached, err := p.DB.GetCachedArtifact(pkgPURL, versionPURL, filename)
- if err != nil {
- return fmt.Errorf("looking up cached artifact: %w", err)
- }
- if cached == nil {
- return nil
- }
- if err := p.Storage.Delete(ctx, cached.StoragePath); err != nil {
- return fmt.Errorf("deleting cached artifact: %w", err)
- }
- return p.DB.ClearArtifactCache(versionPURL, filename)
-}
-
// checkCache looks up an artifact in the cache. Returns nil if not cached.
func (p *Proxy) checkCache(ctx context.Context, pkgPURL, versionPURL, filename string) (*CacheResult, error) {
- artifact, err := p.DB.GetCachedArtifact(pkgPURL, versionPURL, filename)
+ pkg, err := p.DB.GetPackageByPURL(pkgPURL)
+ if err != nil {
+ return nil, fmt.Errorf("checking package cache: %w", err)
+ }
+ if pkg == nil {
+ return nil, nil
+ }
+
+ ver, err := p.DB.GetVersionByPURL(versionPURL)
+ if err != nil {
+ return nil, fmt.Errorf("checking version cache: %w", err)
+ }
+ if ver == nil {
+ return nil, nil
+ }
+
+ artifact, err := p.DB.GetArtifact(versionPURL, filename)
if err != nil {
return nil, fmt.Errorf("checking artifact cache: %w", err)
}
- if artifact == nil {
- return nil, nil
- }
- checks, err := newIntegrityChecks(artifact.ContentHash.String, artifact.Integrity.String)
- if err != nil {
- p.rejectUnusableCacheRecord(artifact, versionPURL, filename, err)
+ if artifact == nil || !artifact.IsCached() {
return nil, nil
}
@@ -208,44 +173,39 @@ func (p *Proxy) checkCache(ctx context.Context, pkgPURL, versionPURL, filename s
}
if p.DirectServe {
- signed, err := p.Storage.SignedURL(ctx, artifact.StoragePath, p.DirectServeTTL)
+ signed, err := p.Storage.SignedURL(ctx, artifact.StoragePath.String, p.DirectServeTTL)
if err == nil {
result.RedirectURL = rewriteSignedURLHost(signed, p.DirectServeBaseURL)
- p.recordCacheHit(artifact.Ecosystem, versionPURL, filename)
+ p.recordCacheHit(pkgPURL, versionPURL, filename)
return result, nil
}
if !errors.Is(err, storage.ErrSignedURLUnsupported) {
p.Logger.Warn("failed to sign storage URL, falling back to streaming",
- "path", artifact.StoragePath, "error", err)
+ "path", artifact.StoragePath.String, "error", err)
}
}
start := time.Now()
- reader, err := p.Storage.Open(ctx, artifact.StoragePath)
+ reader, err := p.Storage.Open(ctx, artifact.StoragePath.String)
metrics.RecordStorageOperation("read", time.Since(start))
if err != nil {
metrics.RecordStorageError("read")
p.Logger.Warn("cached artifact missing from storage, will refetch",
- "path", artifact.StoragePath, "error", err)
+ "path", artifact.StoragePath.String, "error", err)
return nil, nil
}
- result.Reader, err = checks.wrap(reader,
+ result.Reader = newVerifyingReader(reader, artifact.ContentHash.String, ver.Integrity.String,
func(reason string) {
p.Logger.Error("cached artifact failed integrity check",
"purl", versionPURL, "filename", filename,
- "path", artifact.StoragePath, "reason", reason)
- metrics.RecordIntegrityFailure(purl.NormalizeEcosystem(artifact.Ecosystem))
+ "path", artifact.StoragePath.String, "reason", reason)
+ metrics.RecordIntegrityFailure(pkg.Ecosystem)
if err := p.DB.ClearArtifactCache(versionPURL, filename); err != nil {
p.Logger.Warn("failed to clear corrupt artifact from cache", "error", err)
}
})
- if err != nil {
- _ = reader.Close()
- p.rejectUnusableCacheRecord(artifact, versionPURL, filename, err)
- return nil, nil
- }
- p.recordCacheHit(artifact.Ecosystem, versionPURL, filename)
+ p.recordCacheHit(pkgPURL, versionPURL, filename)
return result, nil
}
@@ -269,28 +229,20 @@ func rewriteSignedURLHost(signed, baseURL string) string {
return s.String()
}
-func (p *Proxy) recordCacheHit(ecosystem, versionPURL, filename string) {
+func (p *Proxy) recordCacheHit(pkgPURL, versionPURL, filename string) {
_ = p.DB.RecordArtifactHit(versionPURL, filename)
- metrics.RecordCacheHit(ecosystem)
-}
-
-func (p *Proxy) rejectUnusableCacheRecord(artifact *database.CachedArtifact, versionPURL, filename string, cause error) {
- p.Logger.Warn("cached artifact has unusable integrity metadata",
- "purl", versionPURL, "filename", filename,
- "path", artifact.StoragePath, "error", cause)
- metrics.RecordIntegrityFailure(purl.NormalizeEcosystem(artifact.Ecosystem))
- if err := p.DB.ClearArtifactCache(versionPURL, filename); err != nil {
- p.Logger.Warn("failed to clear unusable artifact from cache", "error", err)
+ if parsed, err := purl.Parse(pkgPURL); err == nil {
+ metrics.RecordCacheHit(purl.PURLTypeToEcosystem(parsed.Type))
}
}
func (p *Proxy) fetchAndCache(ctx context.Context, ecosystem, name, version, filename, pkgPURL, versionPURL string) (*CacheResult, error) {
+ // Record cache miss
+ metrics.RecordCacheMiss(ecosystem)
+
// Resolve download URL
info, err := p.Resolver.Resolve(ctx, ecosystem, name, version)
if err != nil {
- if errors.Is(err, fetch.ErrNotFound) {
- return nil, ErrUpstreamNotFound
- }
return nil, fmt.Errorf("resolving download URL: %w", err)
}
@@ -310,9 +262,6 @@ func (p *Proxy) fetchAndCache(ctx context.Context, ecosystem, name, version, fil
if err != nil {
metrics.RecordUpstreamFetch(ecosystem, fetchDuration)
metrics.RecordUpstreamError(ecosystem, "fetch_failed")
- if errors.Is(err, fetch.ErrNotFound) {
- return nil, ErrUpstreamNotFound
- }
return nil, fmt.Errorf("fetching from upstream: %w", err)
}
metrics.RecordUpstreamFetch(ecosystem, fetchDuration)
@@ -399,40 +348,29 @@ func (p *Proxy) updateCacheDB(ecosystem, name, filename, pkgPURL, versionPURL, u
// ServeArtifact writes a CacheResult to an HTTP response.
func ServeArtifact(w http.ResponseWriter, result *CacheResult) {
- serveArtifact(w, http.MethodGet, result)
-}
-
-func serveArtifact(w http.ResponseWriter, method string, result *CacheResult) {
if result.RedirectURL != "" {
if result.Hash != "" {
- w.Header().Set("ETag", `"`+result.Hash+`"`)
+ w.Header().Set("ETag", fmt.Sprintf(`"%s"`, result.Hash))
}
w.Header().Set("Location", result.RedirectURL)
w.WriteHeader(http.StatusFound)
return
}
- if result.Reader != nil {
- defer func() { _ = result.Reader.Close() }()
- }
+ defer func() { _ = result.Reader.Close() }()
if result.ContentType != "" {
w.Header().Set("Content-Type", result.ContentType)
}
- if result.Size > 0 || (method == http.MethodHead && result.Size == 0) {
- w.Header().Set("Content-Length", strconv.FormatInt(result.Size, 10))
+ if result.Size > 0 {
+ w.Header().Set("Content-Length", fmt.Sprintf("%d", result.Size))
}
if result.Hash != "" {
- w.Header().Set("ETag", `"`+result.Hash+`"`)
+ w.Header().Set("ETag", fmt.Sprintf(`"%s"`, result.Hash))
}
w.WriteHeader(http.StatusOK)
- if method != http.MethodHead && result.Reader != nil {
- buffer := artifactCopyBufferPool.Get().(*[]byte)
- defer artifactCopyBufferPool.Put(buffer)
- // Hide optional ReaderFrom methods so io.CopyBuffer uses the pooled buffer.
- _, _ = io.CopyBuffer(struct{ io.Writer }{w}, result.Reader, *buffer)
- }
+ _, _ = io.Copy(w, result.Reader)
}
// ProxyUpstream forwards a request to an upstream URL without caching.
@@ -453,7 +391,6 @@ func (p *Proxy) ProxyUpstream(w http.ResponseWriter, r *http.Request, upstreamUR
req.Header.Set(header, v)
}
}
- p.applyUpstreamAuth(req)
resp, err := p.HTTPClient.Do(req)
if err != nil {
@@ -480,7 +417,6 @@ func (p *Proxy) ProxyFile(w http.ResponseWriter, r *http.Request, upstreamURL st
http.Error(w, "failed to create request", http.StatusInternalServerError)
return
}
- p.applyUpstreamAuth(req)
resp, err := p.HTTPClient.Do(req)
if err != nil {
@@ -507,18 +443,7 @@ func JSONError(w http.ResponseWriter, status int, message string) {
}
// ErrUpstreamNotFound indicates the upstream returned 404.
-var ErrUpstreamNotFound = fmt.Errorf("upstream: %w", fetch.ErrNotFound)
-
-// serveArtifactError writes response for a failed fetch:
-// 404 when upstream reports artifact missing, 502 otherwise.
-func (p *Proxy) serveArtifactError(w http.ResponseWriter, err error, clientMsg string) {
- if errors.Is(err, ErrUpstreamNotFound) {
- http.Error(w, "not found", http.StatusNotFound)
- return
- }
- p.Logger.Error("failed to get artifact", "error", err)
- http.Error(w, clientMsg, http.StatusBadGateway)
-}
+var ErrUpstreamNotFound = fmt.Errorf("upstream: not found")
// errStale304 is returned when upstream sends 304 but the cached file is missing.
var errStale304 = fmt.Errorf("upstream returned 304 but cached file is missing")
@@ -558,14 +483,12 @@ func (p *Proxy) FetchOrCacheMetadata(ctx context.Context, ecosystem, cacheKey, u
if entry.ContentType.Valid {
ct = entry.ContentType.String
}
- metrics.RecordCacheHit(ecosystem)
return data, ct, nil
}
}
// Cache file missing/unreadable, fall through to upstream
}
}
- p.recordMetadataCacheMiss(ecosystem)
accept := contentTypeJSON
if len(acceptHeaders) > 0 && acceptHeaders[0] != "" {
@@ -613,12 +536,6 @@ func (p *Proxy) FetchOrCacheMetadata(ctx context.Context, ecosystem, cacheKey, u
return data, ct, nil
}
-func (p *Proxy) recordMetadataCacheMiss(ecosystem string) {
- if p.CacheMetadata {
- metrics.RecordCacheMiss(ecosystem)
- }
-}
-
// fetchUpstreamMetadata fetches metadata from upstream, using ETag for conditional revalidation.
// Returns the body, content type, ETag, upstream Last-Modified time, and any error.
func (p *Proxy) fetchUpstreamMetadata(ctx context.Context, upstreamURL string, entry *database.MetadataCacheEntry, accept string) ([]byte, string, string, time.Time, error) {
@@ -629,7 +546,6 @@ func (p *Proxy) fetchUpstreamMetadata(ctx context.Context, upstreamURL string, e
return nil, "", "", zeroTime, fmt.Errorf("creating request: %w", err)
}
req.Header.Set("Accept", accept)
- p.applyUpstreamAuth(req)
if entry != nil && entry.ETag.Valid {
req.Header.Set("If-None-Match", entry.ETag.String)
@@ -819,7 +735,6 @@ func (p *Proxy) proxyMetadataStream(w http.ResponseWriter, r *http.Request, upst
accept = acceptHeaders[0]
}
req.Header.Set("Accept", accept)
- p.applyUpstreamAuth(req)
for _, header := range []string{headerAcceptEncoding, "If-Modified-Since", "If-None-Match"} {
if v := r.Header.Get(header); v != "" {
@@ -844,17 +759,6 @@ func (p *Proxy) proxyMetadataStream(w http.ResponseWriter, r *http.Request, upst
_, _ = io.Copy(w, resp.Body)
}
-func (p *Proxy) applyUpstreamAuth(req *http.Request) {
- if p.AuthForURL == nil {
- return
- }
-
- headerName, headerValue := p.AuthForURL(req.URL.String())
- if headerName != "" && headerValue != "" {
- req.Header.Set(headerName, headerValue)
- }
-}
-
// GetOrFetchArtifactFromURL retrieves an artifact from cache or fetches from a specific URL.
// This is useful for registries where download URLs are determined from metadata.
func (p *Proxy) GetOrFetchArtifactFromURL(ctx context.Context, ecosystem, name, version, filename, downloadURL string) (*CacheResult, error) {
@@ -862,17 +766,18 @@ func (p *Proxy) GetOrFetchArtifactFromURL(ctx context.Context, ecosystem, name,
}
// GetOrFetchArtifactFromURLWithHeaders retrieves an artifact from cache or fetches from a URL
-// with additional request-specific HTTP headers.
+// with additional HTTP headers. This is needed for registries that require authentication
+// (e.g. Docker Hub requires a Bearer token even for public images).
func (p *Proxy) GetOrFetchArtifactFromURLWithHeaders(ctx context.Context, ecosystem, name, version, filename, downloadURL string, headers http.Header) (*CacheResult, error) {
- if cached, err := p.GetCachedArtifact(ctx, ecosystem, name, version, filename); err != nil {
+ pkgPURL := purl.MakePURLString(ecosystem, name, "")
+ versionPURL := purl.MakePURLString(ecosystem, name, version)
+
+ if cached, err := p.checkCache(ctx, pkgPURL, versionPURL, filename); err != nil {
return nil, err
} else if cached != nil {
return cached, nil
}
- metrics.RecordCacheMiss(ecosystem)
- pkgPURL := purl.MakePURLString(ecosystem, name, "")
- versionPURL := purl.MakePURLString(ecosystem, name, version)
return p.fetchAndCacheFromURL(ctx, ecosystem, name, version, filename, pkgPURL, versionPURL, downloadURL, headers)
}
@@ -882,9 +787,6 @@ func (p *Proxy) fetchAndCacheFromURL(ctx context.Context, ecosystem, name, versi
artifact, err := p.Fetcher.FetchWithHeaders(ctx, downloadURL, headers)
if err != nil {
- if errors.Is(err, fetch.ErrNotFound) {
- return nil, ErrUpstreamNotFound
- }
return nil, fmt.Errorf("fetching from upstream: %w", err)
}
diff --git a/internal/handler/handler_bench_test.go b/internal/handler/handler_bench_test.go
deleted file mode 100644
index cdbb524..0000000
--- a/internal/handler/handler_bench_test.go
+++ /dev/null
@@ -1,300 +0,0 @@
-package handler
-
-import (
- "bytes"
- "context"
- "crypto/sha256"
- "database/sql"
- "encoding/hex"
- "fmt"
- "io"
- "log/slog"
- "net/http"
- "net/http/httptest"
- "path/filepath"
- "strings"
- "testing"
- "time"
-
- "github.com/git-pkgs/proxy/internal/database"
- "github.com/git-pkgs/proxy/internal/storage"
- "github.com/git-pkgs/purl"
- "github.com/git-pkgs/registries/fetch"
-)
-
-const benchmarkArtifactSize = 64 << 10
-
-const benchmarkMetadataSize = 1 << 20
-
-type benchmarkResponseWriter struct {
- header http.Header
-}
-
-func (w *benchmarkResponseWriter) Header() http.Header {
- return w.header
-}
-
-func (w *benchmarkResponseWriter) Write(p []byte) (int, error) {
- return len(p), nil
-}
-
-func (w *benchmarkResponseWriter) WriteHeader(_ int) {}
-
-func benchmarkCachedProxy(b *testing.B) (*Proxy, *mockStorage) {
- b.Helper()
-
- proxy, db, store, _ := setupTestProxy(b)
- content := strings.Repeat("x", benchmarkArtifactSize)
- seedPackage(b, db, store, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz", content)
-
- artifact, err := db.GetArtifact("pkg:npm/lodash@4.17.21", "lodash-4.17.21.tgz")
- if err != nil {
- b.Fatalf("get seeded artifact: %v", err)
- }
- sum := sha256.Sum256([]byte(content))
- artifact.ContentHash.String = hex.EncodeToString(sum[:])
- if err := db.UpsertArtifact(artifact); err != nil {
- b.Fatalf("update seeded artifact hash: %v", err)
- }
-
- return proxy, store
-}
-
-func BenchmarkArtifactCacheHit(b *testing.B) {
- ctx := context.Background()
-
- b.Run("stream-64KiB", func(b *testing.B) {
- proxy, _ := benchmarkCachedProxy(b)
- w := &benchmarkResponseWriter{header: make(http.Header)}
- b.SetBytes(benchmarkArtifactSize)
- b.ReportAllocs()
- b.ResetTimer()
-
- for b.Loop() {
- result, err := proxy.GetOrFetchArtifact(ctx, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz")
- if err != nil {
- b.Fatal(err)
- }
- ServeArtifact(w, result)
- }
- })
-
- b.Run("direct-serve", func(b *testing.B) {
- proxy, store := benchmarkCachedProxy(b)
- proxy.DirectServe = true
- store.signedURL = "https://storage.example/npm/lodash-4.17.21.tgz?signature=abc"
- w := &benchmarkResponseWriter{header: make(http.Header)}
- b.ReportAllocs()
- b.ResetTimer()
-
- for b.Loop() {
- result, err := proxy.GetOrFetchArtifact(ctx, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz")
- if err != nil {
- b.Fatal(err)
- }
- ServeArtifact(w, result)
- }
- })
-}
-
-func BenchmarkArtifactCacheHitParallel(b *testing.B) {
- proxy, _ := benchmarkCachedProxy(b)
- ctx := context.Background()
- b.SetBytes(benchmarkArtifactSize)
- b.ReportAllocs()
- b.ResetTimer()
-
- b.RunParallel(func(pb *testing.PB) {
- w := &benchmarkResponseWriter{header: make(http.Header)}
- for pb.Next() {
- result, err := proxy.GetOrFetchArtifact(ctx, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz")
- if err != nil {
- b.Error(err)
- return
- }
- ServeArtifact(w, result)
- }
- })
-}
-
-func BenchmarkReadMetadata(b *testing.B) {
- payload := bytes.Repeat([]byte("x"), benchmarkMetadataSize)
- proxy := &Proxy{MetadataMaxSize: benchmarkMetadataSize}
- b.SetBytes(benchmarkMetadataSize)
- b.ReportAllocs()
-
- var data []byte
- for b.Loop() {
- var err error
- data, err = proxy.ReadMetadata(bytes.NewReader(payload))
- if err != nil {
- b.Fatal(err)
- }
- }
- if len(data) != len(payload) {
- b.Fatalf("metadata size = %d, want %d", len(data), len(payload))
- }
-}
-
-func BenchmarkArtifactPURLConstruction(b *testing.B) {
- for _, tc := range []struct {
- name string
- ecosystem string
- packageID string
- }{
- {"npm", "npm", "lodash"},
- {"scoped-npm", "npm", "@scope/package"},
- {"go", "golang", "github.com/git-pkgs/proxy"},
- } {
- b.Run(tc.name, func(b *testing.B) {
- b.ReportAllocs()
- var packagePURL, versionPURL string
- for b.Loop() {
- packagePURL = purl.MakePURLString(tc.ecosystem, tc.packageID, "")
- versionPURL = purl.MakePURLString(tc.ecosystem, tc.packageID, "1.2.3")
- }
- if packagePURL == "" || versionPURL == "" {
- b.Fatal("empty PURL")
- }
- })
- }
-}
-
-type benchmarkNPMServer struct {
- client *http.Client
- requestURL string
- db *database.DB
- versionPURL string
- filename string
-}
-
-func newBenchmarkNPMServer(b *testing.B) *benchmarkNPMServer {
- b.Helper()
-
- ctx := context.Background()
- dir := b.TempDir()
- db, err := database.Create(filepath.Join(dir, "benchmark.db"))
- if err != nil {
- b.Fatalf("create database: %v", err)
- }
- b.Cleanup(func() { _ = db.Close() })
-
- store, err := storage.OpenBucket(ctx, "file://"+filepath.Join(dir, "cache"))
- if err != nil {
- b.Fatalf("open storage: %v", err)
- }
- b.Cleanup(func() { _ = store.Close() })
-
- content := bytes.Repeat([]byte("x"), benchmarkArtifactSize)
- storagePath := storage.ArtifactPath("npm", "", "lodash", "4.17.21", "lodash-4.17.21.tgz")
- size, hash, err := store.Store(ctx, storagePath, bytes.NewReader(content))
- if err != nil {
- b.Fatalf("store artifact: %v", err)
- }
-
- pkg := &database.Package{PURL: "pkg:npm/lodash", Ecosystem: "npm", Name: "lodash"}
- if err := db.UpsertPackage(pkg); err != nil {
- b.Fatalf("seed package: %v", err)
- }
- version := &database.Version{PURL: "pkg:npm/lodash@4.17.21", PackagePURL: pkg.PURL}
- if err := db.UpsertVersion(version); err != nil {
- b.Fatalf("seed version: %v", err)
- }
- artifact := &database.Artifact{
- VersionPURL: version.PURL,
- Filename: "lodash-4.17.21.tgz",
- UpstreamURL: "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz",
- StoragePath: sql.NullString{String: storagePath, Valid: true},
- ContentHash: sql.NullString{String: hash, Valid: true},
- Size: sql.NullInt64{Int64: size, Valid: true},
- ContentType: sql.NullString{String: "application/gzip", Valid: true},
- FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
- }
- if err := db.UpsertArtifact(artifact); err != nil {
- b.Fatalf("seed artifact: %v", err)
- }
-
- logger := slog.New(slog.NewTextHandler(io.Discard, nil))
- proxy := NewProxy(db, store, &mockFetcher{}, fetch.NewResolver(), logger)
- handler := NewNPMHandler(proxy, "http://proxy.example", "https://registry.npmjs.org")
- server := httptest.NewServer(handler.Routes())
- b.Cleanup(server.Close)
- client := server.Client()
- return &benchmarkNPMServer{
- client: client,
- requestURL: server.URL + "/lodash/-/lodash-4.17.21.tgz",
- db: db,
- versionPURL: version.PURL,
- filename: artifact.Filename,
- }
-}
-
-func (s *benchmarkNPMServer) request() error {
- resp, err := s.client.Get(s.requestURL)
- if err != nil {
- return fmt.Errorf("GET cached artifact: %w", err)
- }
- defer func() { _ = resp.Body.Close() }()
- if resp.StatusCode != http.StatusOK {
- return fmt.Errorf("GET cached artifact status = %d, want %d", resp.StatusCode, http.StatusOK)
- }
- n, err := io.Copy(io.Discard, resp.Body)
- if err != nil {
- return fmt.Errorf("read cached artifact: %w", err)
- }
- if n != benchmarkArtifactSize {
- return fmt.Errorf("cached artifact size = %d, want %d", n, benchmarkArtifactSize)
- }
- return nil
-}
-
-func (s *benchmarkNPMServer) hitCount(b *testing.B) int64 {
- b.Helper()
- artifact, err := s.db.GetArtifact(s.versionPURL, s.filename)
- if err != nil {
- b.Fatalf("get artifact hit count: %v", err)
- }
- return artifact.HitCount
-}
-
-func benchmarkNPMArtifactCacheHitHTTP(b *testing.B, parallel bool) {
- server := newBenchmarkNPMServer(b)
- if err := server.request(); err != nil {
- b.Fatal(err)
- }
- startHits := server.hitCount(b)
-
- b.SetBytes(benchmarkArtifactSize)
- b.ReportAllocs()
- b.ResetTimer()
- if parallel {
- b.RunParallel(func(pb *testing.PB) {
- for pb.Next() {
- if err := server.request(); err != nil {
- b.Error(err)
- return
- }
- }
- })
- } else {
- for b.Loop() {
- if err := server.request(); err != nil {
- b.Fatal(err)
- }
- }
- }
- b.StopTimer()
-
- if hitCount := server.hitCount(b) - startHits; hitCount != int64(b.N) {
- b.Fatalf("new artifact hits = %d, want %d", hitCount, b.N)
- }
- b.ReportMetric(float64(b.N)/b.Elapsed().Seconds(), "requests/s")
-}
-
-func BenchmarkNPMArtifactCacheHitHTTP(b *testing.B) {
- benchmarkNPMArtifactCacheHitHTTP(b, false)
-}
-
-func BenchmarkNPMArtifactCacheHitHTTPParallel(b *testing.B) {
- benchmarkNPMArtifactCacheHitHTTP(b, true)
-}
diff --git a/internal/handler/handler_test.go b/internal/handler/handler_test.go
index ec0e300..bbcab72 100644
--- a/internal/handler/handler_test.go
+++ b/internal/handler/handler_test.go
@@ -5,6 +5,7 @@ import (
"context"
"database/sql"
"errors"
+ "fmt"
"io"
"log/slog"
"net/http"
@@ -13,13 +14,9 @@ import (
"testing"
"time"
- "github.com/git-pkgs/proxy/internal/config"
"github.com/git-pkgs/proxy/internal/database"
- "github.com/git-pkgs/proxy/internal/metrics"
"github.com/git-pkgs/proxy/internal/storage"
- "github.com/git-pkgs/purl"
"github.com/git-pkgs/registries/fetch"
- "github.com/prometheus/client_golang/prometheus/testutil"
)
// mockStorage implements storage.Storage for testing.
@@ -44,7 +41,7 @@ func (s *mockStorage) Store(_ context.Context, path string, r io.Reader) (int64,
return 0, "", err
}
s.files[path] = data
- return int64(len(data)), sha256Hex(string(data)), nil
+ return int64(len(data)), "fakehash123", nil
}
func (s *mockStorage) Open(_ context.Context, path string) (io.ReadCloser, error) {
@@ -130,7 +127,7 @@ func (f *mockFetcher) Head(_ context.Context, _ string) (int64, string, error) {
}
// setupTestProxy creates a Proxy with a real DB (SQLite in temp dir) and mock storage/fetcher.
-func setupTestProxy(t testing.TB) (*Proxy, *database.DB, *mockStorage, *mockFetcher) {
+func setupTestProxy(t *testing.T) (*Proxy, *database.DB, *mockStorage, *mockFetcher) {
t.Helper()
dir := t.TempDir()
@@ -150,11 +147,11 @@ func setupTestProxy(t testing.TB) (*Proxy, *database.DB, *mockStorage, *mockFetc
}
// seedPackage creates a package, version, and cached artifact in the test DB and storage.
-func seedPackage(t testing.TB, db *database.DB, store *mockStorage, ecosystem, name, version, filename, content string) {
+func seedPackage(t *testing.T, db *database.DB, store *mockStorage, ecosystem, name, version, filename, content string) {
t.Helper()
pkg := &database.Package{
- PURL: purl.MakePURLString(ecosystem, name, ""),
+ PURL: fmt.Sprintf("pkg:%s/%s", ecosystem, name),
Ecosystem: ecosystem,
Name: name,
}
@@ -162,7 +159,7 @@ func seedPackage(t testing.TB, db *database.DB, store *mockStorage, ecosystem, n
t.Fatalf("failed to upsert package: %v", err)
}
- versionPURL := purl.MakePURLString(ecosystem, name, version)
+ versionPURL := fmt.Sprintf("pkg:%s/%s@%s", ecosystem, name, version)
ver := &database.Version{
PURL: versionPURL,
PackagePURL: pkg.PURL,
@@ -179,7 +176,7 @@ func seedPackage(t testing.TB, db *database.DB, store *mockStorage, ecosystem, n
Filename: filename,
UpstreamURL: "https://example.com/" + filename,
StoragePath: sql.NullString{String: storagePath, Valid: true},
- ContentHash: sql.NullString{String: sha256Hex(content), Valid: true},
+ ContentHash: sql.NullString{String: "abc123", Valid: true},
Size: sql.NullInt64{Int64: int64(len(content)), Valid: true},
ContentType: sql.NullString{String: "application/octet-stream", Valid: true},
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
@@ -268,80 +265,13 @@ func TestGetOrFetchArtifact_CacheHit(t *testing.T) {
if result.ContentType != "application/octet-stream" {
t.Errorf("got content type %q, want %q", result.ContentType, "application/octet-stream")
}
- if result.Hash != sha256Hex("cached content") {
- t.Errorf("got hash %q, want %q", result.Hash, sha256Hex("cached content"))
- }
-}
-
-func TestGetCachedArtifactRejectsMalformedIntegrityMetadata(t *testing.T) {
- tests := []struct {
- name string
- malformedHash string
- malformedIntegrity string
- }{
- {name: "content hash", malformedHash: "abc123"},
- {name: "native integrity", malformedIntegrity: "sha512-abc123"},
- }
- for _, test := range tests {
- t.Run(test.name, func(t *testing.T) {
- assertMalformedCacheRejected(t, test.malformedHash, test.malformedIntegrity)
- })
- }
-}
-
-func assertMalformedCacheRejected(t *testing.T, malformedHash, malformedIntegrity string) {
- t.Helper()
- proxy, db, store, _ := setupTestProxy(t)
- const (
- packageName = "broken"
- version = "1.0.0"
- filename = "broken-1.0.0.tgz"
- )
- seedPackage(t, db, store, "npm", packageName, version, filename, "cached content")
- versionPURL := purl.MakePURLString("npm", packageName, version)
-
- if malformedHash != "" {
- artifact, err := db.GetArtifact(versionPURL, filename)
- if err != nil {
- t.Fatal(err)
- }
- artifact.ContentHash = sql.NullString{String: malformedHash, Valid: true}
- if err := db.UpsertArtifact(artifact); err != nil {
- t.Fatal(err)
- }
- }
- if malformedIntegrity != "" {
- versionRecord := &database.Version{
- PURL: versionPURL,
- PackagePURL: purl.MakePURLString("npm", packageName, ""),
- Integrity: sql.NullString{String: malformedIntegrity, Valid: true},
- }
- if err := db.UpsertVersion(versionRecord); err != nil {
- t.Fatal(err)
- }
- }
-
- proxy.DirectServe = true
- store.signedURL = "https://cache.example/broken"
- result, err := proxy.GetCachedArtifact(context.Background(), "npm", packageName, version, filename)
- if err != nil {
- t.Fatalf("GetCachedArtifact: %v", err)
- }
- if result != nil {
- t.Errorf("GetCachedArtifact = %+v, want nil", result)
- }
- artifact, err := db.GetArtifact(versionPURL, filename)
- if err != nil {
- t.Fatal(err)
- }
- if artifact.StoragePath.Valid {
- t.Error("unusable cache record retained its storage path")
+ if result.Hash != "abc123" {
+ t.Errorf("got hash %q, want %q", result.Hash, "abc123")
}
}
func TestGetOrFetchArtifact_CacheMiss_NoPackage(t *testing.T) {
proxy, _, _, fetcher := setupTestProxy(t)
- missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("npm"))
// The resolver will fail because "nonexistent" isn't a real package,
// but we're testing that it tries to fetch (doesn't return from cache).
@@ -351,10 +281,6 @@ func TestGetOrFetchArtifact_CacheMiss_NoPackage(t *testing.T) {
if err == nil {
t.Fatal("expected error for uncached package")
}
- missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("npm"))
- if diff := missesAfter - missesBefore; diff != 1 {
- t.Errorf("cache misses delta = %.0f, want 1", diff)
- }
}
func TestGetOrFetchArtifactFromURL_CacheMiss_StorageMissing(t *testing.T) {
@@ -370,7 +296,7 @@ func TestGetOrFetchArtifactFromURL_CacheMiss_StorageMissing(t *testing.T) {
Filename: "missing-1.0.0.tgz",
UpstreamURL: "https://example.com/missing.tgz",
StoragePath: sql.NullString{String: "nonexistent/path.tgz", Valid: true},
- ContentHash: sql.NullString{String: sha256Hex("missing content"), Valid: true},
+ ContentHash: sql.NullString{String: "hash", Valid: true},
Size: sql.NullInt64{Int64: 100, Valid: true},
ContentType: sql.NullString{String: "application/octet-stream", Valid: true},
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
@@ -613,7 +539,6 @@ func TestServeArtifact_Stream(t *testing.T) {
func TestGetOrFetchArtifactFromURL_CacheHit(t *testing.T) {
proxy, db, store, fetcher := setupTestProxy(t)
seedPackage(t, db, store, "pypi", "requests", "2.28.0", "requests-2.28.0.tar.gz", "pypi content")
- missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi"))
result, err := proxy.GetOrFetchArtifactFromURL(context.Background(), "pypi", "requests", "2.28.0", "requests-2.28.0.tar.gz", "https://pypi.org/files/requests-2.28.0.tar.gz")
if err != nil {
@@ -627,15 +552,10 @@ func TestGetOrFetchArtifactFromURL_CacheHit(t *testing.T) {
if fetcher.fetchCalled {
t.Error("fetcher should not be called on cache hit")
}
- missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi"))
- if diff := missesAfter - missesBefore; diff != 0 {
- t.Errorf("cache misses delta = %.0f, want 0", diff)
- }
}
func TestGetOrFetchArtifactFromURL_CacheMiss(t *testing.T) {
proxy, _, store, fetcher := setupTestProxy(t)
- missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi"))
fetcher.artifact = &fetch.Artifact{
Body: io.NopCloser(strings.NewReader("fetched content")),
@@ -668,10 +588,6 @@ func TestGetOrFetchArtifactFromURL_CacheMiss(t *testing.T) {
if _, ok := store.files[storagePath]; !ok {
t.Error("artifact was not stored in storage")
}
- missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi"))
- if diff := missesAfter - missesBefore; diff != 1 {
- t.Errorf("cache misses delta = %.0f, want 1", diff)
- }
}
func TestGetOrFetchArtifactFromURL_FetchError(t *testing.T) {
@@ -961,8 +877,6 @@ func TestProxyCached_NoValidators_OmitsHeaders(t *testing.T) {
}
func TestFetchOrCacheMetadata_TTL_ServesFreshFromCache(t *testing.T) {
- hitsBefore := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("test"))
- missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test"))
upstreamHits := 0
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
upstreamHits++
@@ -989,12 +903,6 @@ func TestFetchOrCacheMetadata_TTL_ServesFreshFromCache(t *testing.T) {
if upstreamHits != 1 {
t.Fatalf("expected 1 upstream hit, got %d", upstreamHits)
}
- if diff := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test")) - missesBefore; diff != 1 {
- t.Errorf("cache misses delta after first request = %.0f, want 1", diff)
- }
- if diff := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("test")) - hitsBefore; diff != 0 {
- t.Errorf("cache hits delta after first request = %.0f, want 0", diff)
- }
// Second request within TTL should serve from cache without hitting upstream
body, _, err = proxy.FetchOrCacheMetadata(ctx, "test", "ttl-pkg", upstream.URL+"/pkg")
@@ -1007,16 +915,9 @@ func TestFetchOrCacheMetadata_TTL_ServesFreshFromCache(t *testing.T) {
if upstreamHits != 1 {
t.Errorf("expected upstream to still be hit only once, got %d", upstreamHits)
}
- if diff := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("test")) - hitsBefore; diff != 1 {
- t.Errorf("cache hits delta after second request = %.0f, want 1", diff)
- }
- if diff := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test")) - missesBefore; diff != 1 {
- t.Errorf("cache misses delta after second request = %.0f, want 1", diff)
- }
}
func TestFetchOrCacheMetadata_TTL_Zero_AlwaysRevalidates(t *testing.T) {
- missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test"))
upstreamHits := 0
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
upstreamHits++
@@ -1045,40 +946,6 @@ func TestFetchOrCacheMetadata_TTL_Zero_AlwaysRevalidates(t *testing.T) {
if upstreamHits != 2 {
t.Errorf("expected 2 upstream hits with TTL=0, got %d", upstreamHits)
}
- missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test"))
- if diff := missesAfter - missesBefore; diff != 2 {
- t.Errorf("cache misses delta = %.0f, want 2", diff)
- }
-}
-
-func TestFetchOrCacheMetadata_CacheDisabledDoesNotRecordMetrics(t *testing.T) {
- const ecosystem = "metadata-disabled"
-
- upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- w.Header().Set("Content-Type", "application/json")
- _, _ = w.Write([]byte(`{"v":1}`))
- }))
- t.Cleanup(upstream.Close)
-
- proxy, _, _, _ := setupTestProxy(t)
- proxy.HTTPClient = upstream.Client()
-
- hitsBefore := testutil.ToFloat64(metrics.CacheHits.WithLabelValues(ecosystem))
- missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues(ecosystem))
-
- _, _, err := proxy.FetchOrCacheMetadata(context.Background(), ecosystem, "pkg", upstream.URL+"/pkg")
- if err != nil {
- t.Fatalf("fetch metadata: %v", err)
- }
-
- hitsAfter := testutil.ToFloat64(metrics.CacheHits.WithLabelValues(ecosystem))
- missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues(ecosystem))
- if diff := hitsAfter - hitsBefore; diff != 0 {
- t.Errorf("cache hits delta = %.0f, want 0", diff)
- }
- if diff := missesAfter - missesBefore; diff != 0 {
- t.Errorf("cache misses delta = %.0f, want 0", diff)
- }
}
func TestProxyCached_StaleWarningHeader(t *testing.T) {
@@ -1143,33 +1010,3 @@ func TestProxyCached_FreshResponse_NoWarningHeader(t *testing.T) {
t.Errorf("Warning should be empty for fresh response, got %q", got)
}
}
-
-// TestCanonicalPackagePURLMatchesConfig ensures the runtime cooldown lookup key
-// agrees with config.CooldownConfig.NormalizedPackages for the same package,
-// so a configured override is actually found regardless of how the user wrote it.
-func TestCanonicalPackagePURLMatchesConfig(t *testing.T) {
- tests := []struct {
- ecosystem string
- requestName string
- configKey string
- }{
- {"npm", "@babel/core", "pkg:npm/@babel/core"},
- {"npm", "@babel/core", "pkg:npm/%40babel/core"},
- {"npm", "@typescript/typescript-darwin-arm64", "pkg:npm/@typescript/typescript-darwin-arm64"},
- {"pypi", "Django", "pkg:pypi/Django"},
- {"pypi", "django", "pkg:pypi/Django"},
- {"composer", "symfony/console", "pkg:composer/Symfony/Console"},
- {"cargo", "serde", "pkg:cargo/serde"},
- }
- for _, tt := range tests {
- t.Run(tt.ecosystem+"/"+tt.requestName+"<="+tt.configKey, func(t *testing.T) {
- cfg := config.CooldownConfig{Packages: map[string]string{tt.configKey: "1d"}}
- normalized := cfg.NormalizedPackages()
-
- lookup := canonicalPackagePURL(tt.ecosystem, tt.requestName)
- if _, ok := normalized[lookup]; !ok {
- t.Errorf("lookup key %q not found in normalized config %v", lookup, normalized)
- }
- })
- }
-}
diff --git a/internal/handler/helm.go b/internal/handler/helm.go
deleted file mode 100644
index f91ba58..0000000
--- a/internal/handler/helm.go
+++ /dev/null
@@ -1,364 +0,0 @@
-package handler
-
-import (
- "crypto/sha256"
- "encoding/hex"
- "errors"
- "fmt"
- "net/http"
- "net/url"
- "path"
- "strings"
- "time"
-
- "gopkg.in/yaml.v3"
-)
-
-const (
- helmMetadataEcosystem = "helm"
- helmIndexFilename = "index.yaml"
- sha256HexLength = 64
-)
-
-// HelmHandler serves read-only HTTP Helm chart repositories. Each configured
-// repository is mounted at /helm/{repository}/.
-type HelmHandler struct {
- proxy *Proxy
- proxyURL string
- repositories map[string]string
-}
-
-// NewHelmHandler creates a Helm chart repository protocol handler.
-func NewHelmHandler(proxy *Proxy, proxyURL string, repositories map[string]string) *HelmHandler {
- h := &HelmHandler{
- proxyURL: strings.TrimSuffix(proxyURL, "/"),
- repositories: make(map[string]string, len(repositories)),
- proxy: proxy,
- }
- for name, repositoryURL := range repositories {
- h.repositories[name] = strings.TrimSuffix(repositoryURL, "/")
- }
- return h
-}
-
-// Routes returns the HTTP handler for Helm chart repository requests.
-func (h *HelmHandler) Routes() http.Handler {
- mux := http.NewServeMux()
- mux.HandleFunc("GET /{repository}/index.yaml", h.handleIndex)
- mux.HandleFunc("GET /{repository}/charts/{digest}/{filename}", h.handleChart)
- return mux
-}
-
-func (h *HelmHandler) handleIndex(w http.ResponseWriter, r *http.Request) {
- repository, upstreamURL, ok := h.repositoryForRequest(r)
- if !ok {
- http.NotFound(w, r)
- return
- }
-
- body, contentType, err := h.fetchIndex(r, repository, upstreamURL)
- if err != nil {
- h.serveIndexError(w, err)
- return
- }
-
- rewritten, err := h.rewriteIndex(repository, upstreamURL, body)
- if err != nil {
- h.proxy.Logger.Warn("failed to rewrite Helm index", "repository", repository, "error", err)
- http.Error(w, "invalid Helm repository index", http.StatusBadGateway)
- return
- }
-
- h.proxy.writeMetadataCachedResponse(w, r, helmMetadataEcosystem, h.indexCacheKey(repository, upstreamURL), rewritten, contentType)
-}
-
-func (h *HelmHandler) handleChart(w http.ResponseWriter, r *http.Request) {
- repository, upstreamURL, ok := h.repositoryForRequest(r)
- if !ok {
- http.NotFound(w, r)
- return
- }
-
- digest, ok := normalizeHelmDigest(r.PathValue("digest"))
- filename := r.PathValue("filename")
- if !ok || filename == "" || strings.Contains(filename, "/") || containsPathTraversal(filename) {
- http.Error(w, "invalid chart request", http.StatusBadRequest)
- return
- }
-
- cached, err := h.proxy.GetCachedArtifact(r.Context(), helmMetadataEcosystem, repository, digest, filename)
- if err != nil {
- h.proxy.Logger.Error("failed to check Helm chart cache", "error", err)
- http.Error(w, "failed to check chart cache", http.StatusInternalServerError)
- return
- }
- if cached != nil {
- h.serveChart(w, r, repository, digest, filename, cached)
- return
- }
-
- body, _, err := h.fetchIndex(r, repository, upstreamURL)
- if err != nil {
- h.serveIndexError(w, err)
- return
- }
-
- downloadURL, err := h.findChartDownload(upstreamURL, body, digest, filename)
- if err != nil {
- if errors.Is(err, errHelmChartNotFound) {
- http.NotFound(w, r)
- return
- }
- h.proxy.Logger.Warn("failed to read Helm index", "repository", repository, "error", err)
- http.Error(w, "invalid Helm repository index", http.StatusBadGateway)
- return
- }
-
- result, err := h.proxy.GetOrFetchArtifactFromURL(
- r.Context(), helmMetadataEcosystem, repository, digest, filename, downloadURL)
- if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch chart")
- return
- }
- h.serveChart(w, r, repository, digest, filename, result)
-}
-
-func (h *HelmHandler) serveChart(w http.ResponseWriter, r *http.Request, repository, digest, filename string, result *CacheResult) {
- if !strings.EqualFold(result.Hash, digest) {
- if result.Reader != nil {
- _ = result.Reader.Close()
- }
- if clearErr := h.proxy.ClearCachedArtifact(r.Context(), helmMetadataEcosystem, repository, digest, filename); clearErr != nil {
- h.proxy.Logger.Warn("failed to clear Helm chart with invalid digest", "error", clearErr)
- }
- http.Error(w, "chart digest verification failed", http.StatusBadGateway)
- return
- }
-
- if result.ContentType == "" {
- w.Header().Set("Content-Type", "application/gzip")
- }
- ServeArtifact(w, result)
-}
-
-func (h *HelmHandler) repositoryForRequest(r *http.Request) (name, upstreamURL string, ok bool) {
- name = r.PathValue("repository")
- upstreamURL, ok = h.repositories[name]
- return name, upstreamURL, ok
-}
-
-func (h *HelmHandler) fetchIndex(r *http.Request, repository, upstreamURL string) ([]byte, string, error) {
- return h.proxy.FetchOrCacheMetadata(
- r.Context(),
- helmMetadataEcosystem,
- h.indexCacheKey(repository, upstreamURL),
- upstreamURL+"/"+helmIndexFilename,
- "application/x-yaml, text/yaml;q=0.9, */*;q=0.1",
- )
-}
-
-func (h *HelmHandler) indexCacheKey(repository, upstreamURL string) string {
- identity := repository + "\x00" + upstreamURL
- digest := sha256.Sum256([]byte(identity))
- return hex.EncodeToString(digest[:])
-}
-
-func (h *HelmHandler) serveIndexError(w http.ResponseWriter, err error) {
- if errors.Is(err, ErrUpstreamNotFound) {
- http.Error(w, "Helm repository not found", http.StatusNotFound)
- return
- }
- h.proxy.Logger.Error("failed to fetch Helm index", "error", err)
- http.Error(w, "failed to fetch Helm repository index", http.StatusBadGateway)
-}
-
-func (h *HelmHandler) rewriteIndex(repository, upstreamURL string, body []byte) ([]byte, error) {
- document, entries, err := parseHelmIndex(body)
- if err != nil {
- return nil, err
- }
-
- for i := 0; i < len(entries.Content); i += 2 {
- chartName := entries.Content[i].Value
- releases := entries.Content[i+1]
- if releases.Kind != yaml.SequenceNode {
- return nil, fmt.Errorf("chart %q releases must be a sequence", chartName)
- }
-
- filtered := make([]*yaml.Node, 0, len(releases.Content))
- for _, release := range releases.Content {
- chart, err := h.parseChartRelease(chartName, upstreamURL, release)
- if err != nil {
- return nil, err
- }
- if h.chartOnCooldown(chartName, chart.created) {
- continue
- }
- for _, download := range chart.downloads {
- download.node.Value = h.chartProxyURL(repository, chart.digest, download.filename)
- }
- filtered = append(filtered, release)
- }
- releases.Content = filtered
- }
-
- return yaml.Marshal(document)
-}
-
-func (h *HelmHandler) findChartDownload(upstreamURL string, body []byte, digest, filename string) (string, error) {
- _, entries, err := parseHelmIndex(body)
- if err != nil {
- return "", err
- }
-
- for i := 0; i < len(entries.Content); i += 2 {
- chartName := entries.Content[i].Value
- releases := entries.Content[i+1]
- if releases.Kind != yaml.SequenceNode {
- return "", fmt.Errorf("chart %q releases must be a sequence", chartName)
- }
- for _, release := range releases.Content {
- chart, err := h.parseChartRelease(chartName, upstreamURL, release)
- if err != nil {
- return "", err
- }
- if chart.digest != digest || h.chartOnCooldown(chartName, chart.created) {
- continue
- }
- for _, download := range chart.downloads {
- if download.filename == filename {
- return download.url, nil
- }
- }
- }
- }
-
- return "", errHelmChartNotFound
-}
-
-func (h *HelmHandler) chartOnCooldown(chartName string, created time.Time) bool {
- return !created.IsZero() && h.proxy.Cooldown != nil && h.proxy.Cooldown.Enabled() &&
- !h.proxy.Cooldown.IsAllowed(helmMetadataEcosystem, canonicalPackagePURL(helmMetadataEcosystem, chartName), created)
-}
-
-type helmChartDownload struct {
- node *yaml.Node
- url string
- filename string
-}
-
-type helmChartRelease struct {
- created time.Time
- digest string
- downloads []helmChartDownload
-}
-
-var errHelmChartNotFound = errors.New("chart not found in Helm index")
-
-func (h *HelmHandler) parseChartRelease(chartName, upstreamURL string, release *yaml.Node) (helmChartRelease, error) {
- digestNode := helmMappingValue(release, "digest")
- urlsNode := helmMappingValue(release, "urls")
- if digestNode == nil || urlsNode == nil || urlsNode.Kind != yaml.SequenceNode || len(urlsNode.Content) == 0 {
- return helmChartRelease{}, fmt.Errorf("chart %q has no digest or URLs", chartName)
- }
- digest, ok := normalizeHelmDigest(digestNode.Value)
- if !ok {
- return helmChartRelease{}, fmt.Errorf("chart %q has invalid digest", chartName)
- }
-
- baseURL, err := url.Parse(upstreamURL + "/" + helmIndexFilename)
- if err != nil {
- return helmChartRelease{}, fmt.Errorf("parsing Helm repository URL: %w", err)
- }
-
- chart := helmChartRelease{digest: digest}
- if createdNode := helmMappingValue(release, "created"); createdNode != nil && createdNode.Value != "" {
- chart.created, err = time.Parse(time.RFC3339Nano, createdNode.Value)
- if err != nil {
- return helmChartRelease{}, fmt.Errorf("chart %q has invalid creation time: %w", chartName, err)
- }
- }
-
- for _, urlNode := range urlsNode.Content {
- if urlNode.Kind != yaml.ScalarNode {
- return helmChartRelease{}, fmt.Errorf("chart %q has invalid URL", chartName)
- }
- reference, err := url.Parse(urlNode.Value)
- if err != nil {
- return helmChartRelease{}, fmt.Errorf("parsing chart %q URL: %w", chartName, err)
- }
- downloadURL := baseURL.ResolveReference(reference)
- if (downloadURL.Scheme != "http" && downloadURL.Scheme != "https") || downloadURL.Host == "" {
- return helmChartRelease{}, fmt.Errorf("chart %q URL must be HTTP(S)", chartName)
- }
- filename := path.Base(downloadURL.Path)
- if filename == "." || filename == "/" || filename == "" || !strings.HasSuffix(filename, ".tgz") {
- return helmChartRelease{}, fmt.Errorf("chart %q URL must point to a .tgz file", chartName)
- }
- chart.downloads = append(chart.downloads, helmChartDownload{
- node: urlNode,
- url: downloadURL.String(),
- filename: filename,
- })
- }
- return chart, nil
-}
-
-func (h *HelmHandler) chartProxyURL(repository, digest, filename string) string {
- return fmt.Sprintf("%s/helm/%s/charts/%s/%s", h.proxyURL,
- url.PathEscape(repository), digest, url.PathEscape(filename))
-}
-
-func parseHelmIndex(body []byte) (*yaml.Node, *yaml.Node, error) {
- var document yaml.Node
- if err := yaml.Unmarshal(body, &document); err != nil {
- return nil, nil, fmt.Errorf("parsing Helm index: %w", err)
- }
- entries, err := helmIndexEntries(&document)
- if err != nil {
- return nil, nil, err
- }
- return &document, entries, nil
-}
-
-func helmIndexEntries(document *yaml.Node) (*yaml.Node, error) {
- if document == nil {
- return nil, errors.New("helm index is empty")
- }
- if len(document.Content) != 1 || document.Content[0].Kind != yaml.MappingNode {
- return nil, errors.New("helm index must be a mapping")
- }
- entries := helmMappingValue(document.Content[0], "entries")
- if entries == nil || entries.Kind != yaml.MappingNode {
- return nil, errors.New("helm index has no entries mapping")
- }
- if len(entries.Content)%2 != 0 {
- return nil, errors.New("helm index entries mapping has an incomplete key-value pair")
- }
- return entries, nil
-}
-
-func helmMappingValue(mapping *yaml.Node, key string) *yaml.Node {
- if mapping == nil || mapping.Kind != yaml.MappingNode {
- return nil
- }
- for i := 0; i+1 < len(mapping.Content); i += 2 {
- if mapping.Content[i].Value == key {
- return mapping.Content[i+1]
- }
- }
- return nil
-}
-
-func normalizeHelmDigest(value string) (string, bool) {
- digest := strings.TrimPrefix(strings.ToLower(value), "sha256:")
- if len(digest) != sha256HexLength {
- return "", false
- }
- for _, char := range digest {
- if (char < '0' || char > '9') && (char < 'a' || char > 'f') {
- return "", false
- }
- }
- return digest, true
-}
diff --git a/internal/handler/helm_test.go b/internal/handler/helm_test.go
deleted file mode 100644
index ec8d4a5..0000000
--- a/internal/handler/helm_test.go
+++ /dev/null
@@ -1,337 +0,0 @@
-package handler
-
-import (
- "crypto/sha256"
- "encoding/hex"
- "fmt"
- "net/http"
- "net/http/httptest"
- "strings"
- "sync/atomic"
- "testing"
- "time"
-
- "github.com/git-pkgs/cooldown"
- upstreamhttp "github.com/git-pkgs/proxy/internal/httpclient"
- "github.com/git-pkgs/proxy/internal/storage"
- "github.com/git-pkgs/registries/fetch"
- "gopkg.in/yaml.v3"
-)
-
-func TestHelmHandler_RewritesIndexAndCachesChart(t *testing.T) {
- chart := []byte("a Helm chart")
- digest := helmSHA256Hex(chart)
- var available atomic.Bool
- available.Store(true)
- var indexRequests atomic.Int32
- var chartRequests atomic.Int32
-
- var upstream *httptest.Server
- upstream = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- if !available.Load() {
- http.Error(w, "unavailable", http.StatusServiceUnavailable)
- return
- }
- switch r.URL.Path {
- case "/charts/index.yaml":
- indexRequests.Add(1)
- w.Header().Set("Content-Type", "application/x-yaml")
- _, _ = fmt.Fprintf(w, `apiVersion: v1
-entries:
- demo:
- - annotations:
- example.com/retained: "true"
- created: 2020-01-02T03:04:05Z
- digest: %s
- name: demo
- urls:
- - demo-1.0.0.tgz
- - %s/charts/mirror/demo-1.0.0.tgz
- version: 1.0.0
-generated: 2020-01-02T03:04:05Z
-`, digest, upstream.URL)
- case "/charts/demo-1.0.0.tgz", "/charts/mirror/demo-1.0.0.tgz":
- chartRequests.Add(1)
- w.Header().Set("Content-Type", "application/gzip")
- _, _ = w.Write(chart)
- default:
- http.NotFound(w, r)
- }
- }))
- defer upstream.Close()
-
- proxy, _, _, _ := setupTestProxy(t)
- proxy.CacheMetadata = true
- proxy.MetadataTTL = time.Hour
- proxy.HTTPClient = upstream.Client()
- fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0))
- proxy.Fetcher = fetcher
- t.Cleanup(func() { _ = fetcher.Close() })
-
- h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"stable": upstream.URL + "/charts"})
-
- indexResponse := serveHelmRequest(h, "/stable/index.yaml")
- if indexResponse.Code != http.StatusOK {
- t.Fatalf("index status = %d, want 200: %s", indexResponse.Code, indexResponse.Body.String())
- }
- if got := indexResponse.Header().Get("Content-Type"); got != "application/x-yaml" {
- t.Errorf("index Content-Type = %q, want application/x-yaml", got)
- }
- if strings.Contains(indexResponse.Body.String(), upstream.URL) {
- t.Errorf("rewritten index contains upstream URL: %s", indexResponse.Body.String())
- }
- if !strings.Contains(indexResponse.Body.String(), "example.com/retained") {
- t.Errorf("rewritten index lost an unrelated field: %s", indexResponse.Body.String())
- }
-
- var index map[string]any
- if err := yaml.Unmarshal(indexResponse.Body.Bytes(), &index); err != nil {
- t.Fatalf("parse rewritten index: %v", err)
- }
- entries := index["entries"].(map[string]any)
- release := entries["demo"].([]any)[0].(map[string]any)
- urls := release["urls"].([]any)
- wantURL := "http://proxy.example/helm/stable/charts/" + digest + "/demo-1.0.0.tgz"
- for _, rawURL := range urls {
- if rawURL != wantURL {
- t.Errorf("rewritten URL = %q, want %q", rawURL, wantURL)
- }
- }
-
- firstChart := serveHelmRequest(h, "/stable/charts/"+digest+"/demo-1.0.0.tgz")
- if firstChart.Code != http.StatusOK {
- t.Fatalf("chart status = %d, want 200: %s", firstChart.Code, firstChart.Body.String())
- }
- if got := firstChart.Body.String(); got != string(chart) {
- t.Errorf("chart body = %q, want %q", got, chart)
- }
- if got := firstChart.Header().Get("Content-Type"); got != "application/gzip" {
- t.Errorf("chart Content-Type = %q, want application/gzip", got)
- }
-
- // Artifact cache availability must not depend on metadata caching or a
- // reachable index upstream.
- proxy.CacheMetadata = false
- available.Store(false)
- cachedChart := serveHelmRequest(h, "/stable/charts/"+digest+"/demo-1.0.0.tgz")
- if cachedChart.Code != http.StatusOK {
- t.Fatalf("cached chart status = %d, want 200: %s", cachedChart.Code, cachedChart.Body.String())
- }
- if got := cachedChart.Body.String(); got != string(chart) {
- t.Errorf("cached chart body = %q, want %q", got, chart)
- }
- if got := indexRequests.Load(); got != 1 {
- t.Errorf("index requests = %d, want 1", got)
- }
- if got := chartRequests.Load(); got != 1 {
- t.Errorf("chart requests = %d, want 1", got)
- }
-}
-
-func TestHelmHandler_RejectsChartDigestMismatch(t *testing.T) {
- chart := []byte("tampered chart")
- digest := helmSHA256Hex([]byte("expected chart"))
- requests := 0
-
- upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- switch r.URL.Path {
- case "/index.yaml":
- _, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", digest)
- case "/demo.tgz":
- requests++
- _, _ = w.Write(chart)
- default:
- http.NotFound(w, r)
- }
- }))
- defer upstream.Close()
-
- proxy, _, store, _ := setupTestProxy(t)
- proxy.CacheMetadata = true
- proxy.MetadataTTL = time.Hour
- proxy.HTTPClient = upstream.Client()
- fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0))
- proxy.Fetcher = fetcher
- t.Cleanup(func() { _ = fetcher.Close() })
- h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"test": upstream.URL})
-
- for range 2 {
- response := serveHelmRequest(h, "/test/charts/"+digest+"/demo.tgz")
- if response.Code != http.StatusBadGateway {
- t.Errorf("status = %d, want 502: %s", response.Code, response.Body.String())
- }
- }
- if requests != 2 {
- t.Errorf("chart requests = %d, want 2 after invalid cache entry is cleared", requests)
- }
- storagePath := storage.ArtifactPath(helmMetadataEcosystem, "", "test", digest, "demo.tgz")
- if exists, err := store.Exists(t.Context(), storagePath); err != nil {
- t.Fatalf("checking rejected chart storage: %v", err)
- } else if exists {
- t.Errorf("rejected chart remains in storage at %q", storagePath)
- }
-}
-
-func TestHelmHandler_IndexCacheChangesWithUpstreamURL(t *testing.T) {
- firstDigest := strings.Repeat("a", sha256HexLength)
- secondDigest := strings.Repeat("b", sha256HexLength)
- firstRequests := 0
- secondRequests := 0
- first := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- firstRequests++
- _, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", firstDigest)
- }))
- defer first.Close()
- second := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- secondRequests++
- _, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", secondDigest)
- }))
- defer second.Close()
-
- proxy, db, store, _ := setupTestProxy(t)
- proxy.CacheMetadata = true
- proxy.MetadataTTL = time.Hour
- proxy.HTTPClient = first.Client()
- firstHandler := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"stable": first.URL})
- if response := serveHelmRequest(firstHandler, "/stable/index.yaml"); response.Code != http.StatusOK {
- t.Fatalf("first index status = %d, want 200: %s", response.Code, response.Body.String())
- }
-
- // Model a restarted server with the same database and storage but a changed
- // repository URL. Its cache key must not reuse the previous index or ETag.
- restartedProxy := NewProxy(db, store, &mockFetcher{}, fetch.NewResolver(), nil)
- restartedProxy.CacheMetadata = true
- restartedProxy.MetadataTTL = time.Hour
- restartedProxy.HTTPClient = second.Client()
- secondHandler := NewHelmHandler(restartedProxy, "http://proxy.example", map[string]string{"stable": second.URL})
- response := serveHelmRequest(secondHandler, "/stable/index.yaml")
- if response.Code != http.StatusOK {
- t.Fatalf("second index status = %d, want 200: %s", response.Code, response.Body.String())
- }
- if !strings.Contains(response.Body.String(), secondDigest) {
- t.Errorf("second index did not use the new upstream: %s", response.Body.String())
- }
- if firstRequests != 1 {
- t.Errorf("first upstream requests = %d, want 1", firstRequests)
- }
- if secondRequests != 1 {
- t.Errorf("second upstream requests = %d, want 1", secondRequests)
- }
-}
-
-func TestHelmHandler_UsesConfiguredUpstreamAuthentication(t *testing.T) {
- chart := []byte("private Helm chart")
- digest := helmSHA256Hex(chart)
- upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- if r.Header.Get("Authorization") != "Bearer private-token" {
- http.Error(w, "unauthorized", http.StatusUnauthorized)
- return
- }
- switch r.URL.Path {
- case "/index.yaml":
- _, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", digest)
- case "/demo.tgz":
- _, _ = w.Write(chart)
- default:
- http.NotFound(w, r)
- }
- }))
- defer upstream.Close()
-
- proxy, _, _, _ := setupTestProxy(t)
- proxy.CacheMetadata = true
- proxy.MetadataTTL = time.Hour
- authClient := &http.Client{Transport: upstreamhttp.NewTransport(http.DefaultTransport,
- upstreamhttp.AuthFunc(func(string) (string, string) {
- return "Authorization", "Bearer private-token"
- }))}
- proxy.HTTPClient = authClient
- fetcher := fetch.NewFetcher(fetch.WithHTTPClient(authClient), fetch.WithMaxRetries(0))
- proxy.Fetcher = fetcher
- t.Cleanup(func() { _ = fetcher.Close() })
- h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"private": upstream.URL})
-
- response := serveHelmRequest(h, "/private/charts/"+digest+"/demo.tgz")
- if response.Code != http.StatusOK {
- t.Fatalf("status = %d, want 200: %s", response.Code, response.Body.String())
- }
- if got := response.Body.String(); got != string(chart) {
- t.Errorf("body = %q, want %q", got, chart)
- }
-}
-
-func TestHelmHandler_FiltersNewChartsFromIndex(t *testing.T) {
- oldDigest := strings.Repeat("a", 64)
- newDigest := strings.Repeat("b", 64)
- proxy := &Proxy{Cooldown: &cooldown.Config{Default: "3d"}}
- h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"test": "https://charts.example"})
-
- body := fmt.Sprintf(`apiVersion: v1
-entries:
- demo:
- - created: %s
- digest: %s
- urls: [demo-old.tgz]
- - created: %s
- digest: %s
- urls: [demo-new.tgz]
-`, time.Now().Add(-10*24*time.Hour).Format(time.RFC3339), oldDigest,
- time.Now().Add(-time.Hour).Format(time.RFC3339), newDigest)
-
- rewritten, err := h.rewriteIndex("test", "https://charts.example", []byte(body))
- if err != nil {
- t.Fatalf("rewriteIndex() error = %v", err)
- }
- if strings.Contains(string(rewritten), newDigest) {
- t.Errorf("rewritten index includes a chart still in cooldown: %s", rewritten)
- }
- if !strings.Contains(string(rewritten), oldDigest) {
- t.Errorf("rewritten index omitted an old chart: %s", rewritten)
- }
-}
-
-func TestNormalizeHelmDigest(t *testing.T) {
- digest := strings.Repeat("a", 64)
- for _, input := range []string{digest, "sha256:" + digest, "SHA256:" + strings.ToUpper(digest)} {
- if got, ok := normalizeHelmDigest(input); !ok || got != digest {
- t.Errorf("normalizeHelmDigest(%q) = %q, %t; want %q, true", input, got, ok, digest)
- }
- }
- if _, ok := normalizeHelmDigest("bad"); ok {
- t.Error("normalizeHelmDigest accepted an invalid digest")
- }
-}
-
-func TestHelmIndexEntriesRejectsIncompleteMapping(t *testing.T) {
- entries := &yaml.Node{
- Kind: yaml.MappingNode,
- Content: []*yaml.Node{
- {Kind: yaml.ScalarNode, Value: "demo"},
- },
- }
- document := &yaml.Node{
- Kind: yaml.DocumentNode,
- Content: []*yaml.Node{{
- Kind: yaml.MappingNode,
- Content: []*yaml.Node{
- {Kind: yaml.ScalarNode, Value: "entries"},
- entries,
- },
- }},
- }
-
- if _, err := helmIndexEntries(document); err == nil {
- t.Fatal("helmIndexEntries() error = nil, want incomplete mapping error")
- }
-}
-
-func serveHelmRequest(h *HelmHandler, target string) *httptest.ResponseRecorder {
- w := httptest.NewRecorder()
- h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodGet, target, nil))
- return w
-}
-
-func helmSHA256Hex(data []byte) string {
- digest := sha256.Sum256(data)
- return hex.EncodeToString(digest[:])
-}
diff --git a/internal/handler/hex.go b/internal/handler/hex.go
index 2ff4f0f..0f0c72e 100644
--- a/internal/handler/hex.go
+++ b/internal/handler/hex.go
@@ -10,6 +10,7 @@ import (
"strings"
"time"
+ "github.com/git-pkgs/purl"
"google.golang.org/protobuf/encoding/protowire"
)
@@ -53,13 +54,30 @@ func (h *HexHandler) Routes() http.Handler {
// handleDownload serves a package tarball, fetching and caching from upstream if needed.
func (h *HexHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
- h.proxy.handleFilenameDownload(w, r, filenameDownload{
- ecosystem: "hex",
- suffix: ".tar",
- parseErr: "could not parse tarball filename",
- fetchErr: "failed to fetch package",
- parse: h.parseTarballFilename,
- })
+ filename := r.PathValue("filename")
+ if filename == "" || !strings.HasSuffix(filename, ".tar") {
+ http.Error(w, "invalid filename", http.StatusBadRequest)
+ return
+ }
+
+ // Extract name and version from filename (e.g., "phoenix-1.7.10.tar")
+ name, version := h.parseTarballFilename(filename)
+ if name == "" || version == "" {
+ http.Error(w, "could not parse tarball filename", http.StatusBadRequest)
+ return
+ }
+
+ h.proxy.Logger.Info("hex download request",
+ "name", name, "version", version, "filename", filename)
+
+ result, err := h.proxy.GetOrFetchArtifact(r.Context(), "hex", name, version, filename)
+ if err != nil {
+ h.proxy.Logger.Error("failed to get artifact", "error", err)
+ http.Error(w, "failed to fetch package", http.StatusBadGateway)
+ return
+ }
+
+ ServeArtifact(w, result)
}
// parseTarballFilename extracts name and version from a hex tarball filename.
@@ -219,7 +237,7 @@ func (h *HexHandler) fetchFilteredVersions(r *http.Request, name string) (map[st
return nil, err
}
- packagePURL := canonicalPackagePURL("hex", name)
+ packagePURL := purl.MakePURLString("hex", name, "")
filtered := make(map[string]bool)
for _, release := range pkg.Releases {
diff --git a/internal/handler/integrity.go b/internal/handler/integrity.go
index 07963b9..bb29a21 100644
--- a/internal/handler/integrity.go
+++ b/internal/handler/integrity.go
@@ -1,100 +1,140 @@
package handler
import (
+ "crypto/sha256"
+ "crypto/sha512"
+ "crypto/subtle"
+ "encoding/base64"
+ "encoding/hex"
"fmt"
+ "hash"
"io"
-
- "github.com/git-pkgs/integrity"
+ "strings"
)
-type integrityChecks struct {
- contentHash integrity.SRI
- native integrity.SRI
- algorithms []integrity.Algorithm
-}
-
-func newIntegrityChecks(contentHash, native string) (integrityChecks, error) {
- checks := integrityChecks{}
-
- if contentHash != "" {
- digest, err := integrity.ParseHex(integrity.SHA256, contentHash)
- if err != nil {
- return integrityChecks{}, fmt.Errorf("parse content_hash: %w", err)
- }
- checks.contentHash = integrity.SRI{digest}
- checks.algorithms = append(checks.algorithms, integrity.SHA256)
+// parseSRI parses a Subresource Integrity string (e.g. "sha512-abc==") into
+// an algorithm name and raw digest bytes. Returns ok=false for empty,
+// malformed, or unsupported entries. Only the first hash in a multi-hash
+// SRI string is considered.
+func parseSRI(s string) (algo string, digest []byte, ok bool) {
+ s = strings.TrimSpace(s)
+ if s == "" {
+ return "", nil, false
}
-
- if native != "" {
- digests, err := integrity.ParseSRI(native)
- if err != nil {
- return integrityChecks{}, fmt.Errorf("parse integrity: %w", err)
- }
- checks.native = digests
- for _, digest := range digests {
- checks.algorithms = append(checks.algorithms, digest.Algorithm())
- }
+ if i := strings.IndexByte(s, ' '); i >= 0 {
+ s = s[:i]
}
-
- return checks, nil
-}
-
-func (c integrityChecks) wrap(source io.ReadCloser, onMismatch func(string)) (io.ReadCloser, error) {
- if len(c.algorithms) == 0 {
- return source, nil
+ algo, b64, found := strings.Cut(s, "-")
+ if !found {
+ return "", nil, false
}
- reader, err := integrity.NewReader(source, c.algorithms...)
+ d, err := base64.StdEncoding.DecodeString(b64)
if err != nil {
- return nil, fmt.Errorf("create integrity reader: %w", err)
+ return "", nil, false
+ }
+ switch algo {
+ case "sha256", "sha384", "sha512":
+ return algo, d, true
+ default:
+ return "", nil, false
}
- return &verifyingReader{
- source: source,
- reader: reader,
- checks: c,
- onMismatch: onMismatch,
- }, nil
}
-// verifyingReader forwards Close to its source and reports completed digest
-// mismatches after its shared integrity reader observes EOF.
+func newSRIHash(algo string) hash.Hash {
+ switch algo {
+ case "sha256":
+ return sha256.New()
+ case "sha384":
+ return sha512.New384()
+ case "sha512":
+ return sha512.New()
+ }
+ return nil
+}
+
+// verifyingReader wraps an io.ReadCloser and computes SHA256 (and optionally
+// a second SRI hash) as bytes are read. When the underlying reader reaches
+// EOF it compares the digests against the expected values and calls
+// onMismatch for each failure. Verification is skipped if the stream was
+// not fully consumed (e.g. client disconnect) to avoid false positives.
type verifyingReader struct {
- source io.ReadCloser
- reader *integrity.Reader
- checks integrityChecks
+ r io.ReadCloser
+ sha256 hash.Hash
+ wantSHA256 string
+ sri hash.Hash
+ sriAlgo string
+ wantSRI []byte
onMismatch func(reason string)
+ eof bool
verified bool
}
-func (r *verifyingReader) Read(p []byte) (int, error) {
- n, err := r.reader.Read(p)
+func newVerifyingReader(r io.ReadCloser, contentHash, sri string, onMismatch func(string)) io.ReadCloser {
+ if contentHash == "" && sri == "" {
+ return r
+ }
+ v := &verifyingReader{
+ r: r,
+ onMismatch: onMismatch,
+ }
+ if contentHash != "" {
+ v.sha256 = sha256.New()
+ v.wantSHA256 = contentHash
+ }
+ if algo, digest, ok := parseSRI(sri); ok {
+ v.sri = newSRIHash(algo)
+ v.sriAlgo = algo
+ v.wantSRI = digest
+ }
+ if v.sha256 == nil && v.sri == nil {
+ return r
+ }
+ return v
+}
+
+func (v *verifyingReader) Read(p []byte) (int, error) {
+ n, err := v.r.Read(p)
+ if n > 0 {
+ if v.sha256 != nil {
+ v.sha256.Write(p[:n])
+ }
+ if v.sri != nil {
+ v.sri.Write(p[:n])
+ }
+ }
if err == io.EOF {
- r.verify()
+ v.eof = true
+ v.verify()
}
return n, err
}
-func (r *verifyingReader) Close() error {
- return r.source.Close()
+func (v *verifyingReader) Close() error {
+ if v.eof {
+ v.verify()
+ }
+ return v.r.Close()
}
-func (r *verifyingReader) verify() {
- if r.verified {
- return
- }
- r.verified = true
- result := r.reader.Result()
- if !result.Complete {
+func (v *verifyingReader) verify() {
+ if v.verified {
return
}
+ v.verified = true
- if len(r.checks.contentHash) > 0 {
- if err := result.Verify(r.checks.contentHash); err != nil {
- r.onMismatch("content_hash: " + err.Error())
+ if v.sha256 != nil {
+ got := hex.EncodeToString(v.sha256.Sum(nil))
+ if subtle.ConstantTimeCompare([]byte(got), []byte(v.wantSHA256)) != 1 {
+ v.onMismatch(fmt.Sprintf("content_hash mismatch: stored=%s computed=%s", v.wantSHA256, got))
}
}
- if len(r.checks.native) > 0 {
- if err := result.Verify(r.checks.native); err != nil {
- r.onMismatch("integrity: " + err.Error())
+ if v.sri != nil {
+ got := v.sri.Sum(nil)
+ if subtle.ConstantTimeCompare(got, v.wantSRI) != 1 {
+ v.onMismatch(fmt.Sprintf("integrity mismatch: %s expected=%s computed=%s",
+ v.sriAlgo,
+ base64.StdEncoding.EncodeToString(v.wantSRI),
+ base64.StdEncoding.EncodeToString(got)))
}
}
}
diff --git a/internal/handler/integrity_test.go b/internal/handler/integrity_test.go
index 95992c0..93c448c 100644
--- a/internal/handler/integrity_test.go
+++ b/internal/handler/integrity_test.go
@@ -5,7 +5,6 @@ import (
"crypto/sha512"
"encoding/base64"
"encoding/hex"
- "errors"
"io"
"strings"
"testing"
@@ -16,68 +15,42 @@ func sha256Hex(data string) string {
return hex.EncodeToString(sum[:])
}
-func sha256SRI(data string) string {
- sum := sha256.Sum256([]byte(data))
- return "sha256-" + base64.StdEncoding.EncodeToString(sum[:])
-}
-
-func sha384SRI(data string) string {
- sum := sha512.Sum384([]byte(data))
- return "sha384-" + base64.StdEncoding.EncodeToString(sum[:])
-}
-
func sha512SRI(data string) string {
sum := sha512.Sum512([]byte(data))
return "sha512-" + base64.StdEncoding.EncodeToString(sum[:])
}
-func wrapIntegrityReader(t *testing.T, source io.ReadCloser, contentHash, native string, onMismatch func(string)) io.ReadCloser {
- t.Helper()
- checks, err := newIntegrityChecks(contentHash, native)
- if err != nil {
- t.Fatalf("newIntegrityChecks: %v", err)
- }
- reader, err := checks.wrap(source, onMismatch)
- if err != nil {
- t.Fatalf("wrap: %v", err)
- }
- return reader
-}
-
-func TestNewIntegrityChecksCollectsAlgorithms(t *testing.T) {
- checks, err := newIntegrityChecks(
- sha256Hex("hello"),
- strings.Join([]string{sha256SRI("first"), sha512SRI("second"), sha384SRI("third"), sha512SRI("alternative")}, " "),
- )
- if err != nil {
- t.Fatal(err)
- }
- if len(checks.algorithms) != 5 {
- t.Fatalf("algorithms = %v, want 5 entries", checks.algorithms)
- }
- if len(checks.native) != 4 {
- t.Errorf("native digests = %d, want 4", len(checks.native))
- }
-}
-
-func TestNewIntegrityChecksRejectsMalformedMetadata(t *testing.T) {
+func TestParseSRI(t *testing.T) {
tests := []struct {
- name string
- contentHash string
- native string
+ name string
+ input string
+ algo string
+ ok bool
}{
- {name: "short content hash", contentHash: "abc123"},
- {name: "non-hex content hash", contentHash: strings.Repeat("z", sha256.Size*2)},
- {name: "missing SRI separator", native: "sha512"},
- {name: "malformed SRI base64", native: "sha512-not!base64"},
- {name: "wrong SRI length", native: "sha512-" + base64.StdEncoding.EncodeToString([]byte("short"))},
- {name: "unsupported SRI algorithm", native: "md5-1B2M2Y8AsgTpgAmY7PhCfg=="},
- {name: "invalid SRI alternative", native: sha512SRI("valid") + " sha384-nope"},
+ {"sha512", sha512SRI("hello"), "sha512", true},
+ {"sha256", "sha256-" + base64.StdEncoding.EncodeToString([]byte("0123456789012345678901234567890123456789")), "sha256", true},
+ {"empty", "", "", false},
+ {"no dash", "sha512abc", "", false},
+ {"bad base64", "sha512-not!base64", "", false},
+ {"unsupported algo", "md5-" + base64.StdEncoding.EncodeToString([]byte("x")), "", false},
+ {"multi hash takes first", sha512SRI("a") + " " + sha512SRI("b"), "sha512", true},
+ {"whitespace", " " + sha512SRI("x") + " ", "sha512", true},
}
- for _, test := range tests {
- t.Run(test.name, func(t *testing.T) {
- if _, err := newIntegrityChecks(test.contentHash, test.native); err == nil {
- t.Fatal("newIntegrityChecks returned nil error")
+
+ for _, tt := range tests {
+ t.Run(tt.name, func(t *testing.T) {
+ algo, digest, ok := parseSRI(tt.input)
+ if ok != tt.ok {
+ t.Fatalf("ok = %v, want %v", ok, tt.ok)
+ }
+ if !tt.ok {
+ return
+ }
+ if algo != tt.algo {
+ t.Errorf("algo = %q, want %q", algo, tt.algo)
+ }
+ if len(digest) == 0 {
+ t.Error("digest is empty")
}
})
}
@@ -94,156 +67,69 @@ func TestVerifyingReader(t *testing.T) {
sri string
wantCalls int
}{
- {name: "both match", hash: goodSHA, sri: goodSRI},
- {name: "SHA-256 only match", hash: goodSHA},
- {name: "SRI only match", sri: goodSRI},
- {name: "SHA-256 mismatch", hash: sha256Hex("other"), wantCalls: 1},
- {name: "SRI mismatch", sri: sha512SRI("other"), wantCalls: 1},
- {name: "both mismatch", hash: sha256Hex("other"), sri: sha512SRI("other"), wantCalls: 2},
- {name: "no checks"},
+ {"both match", goodSHA, goodSRI, 0},
+ {"sha256 only match", goodSHA, "", 0},
+ {"sri only match", "", goodSRI, 0},
+ {"sha256 mismatch", sha256Hex("other"), "", 1},
+ {"sri mismatch", "", sha512SRI("other"), 1},
+ {"both mismatch", sha256Hex("other"), sha512SRI("other"), 2},
+ {"no checks", "", "", 0},
+ {"unparseable sri ignored", goodSHA, "garbage", 0},
}
- for _, test := range tests {
- t.Run(test.name, func(t *testing.T) {
+ for _, tt := range tests {
+ t.Run(tt.name, func(t *testing.T) {
var calls []string
- reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader(data)), test.hash, test.sri,
+ r := newVerifyingReader(io.NopCloser(strings.NewReader(data)), tt.hash, tt.sri,
func(reason string) { calls = append(calls, reason) })
- got, err := io.ReadAll(reader)
+ got, err := io.ReadAll(r)
if err != nil {
t.Fatalf("ReadAll: %v", err)
}
if string(got) != data {
t.Errorf("data corrupted: got %q", got)
}
- if err := reader.Close(); err != nil {
+ if err := r.Close(); err != nil {
t.Fatalf("Close: %v", err)
}
- if len(calls) != test.wantCalls {
- t.Errorf("onMismatch called %d times, want %d: %v", len(calls), test.wantCalls, calls)
+
+ if len(calls) != tt.wantCalls {
+ t.Errorf("onMismatch called %d times, want %d: %v", len(calls), tt.wantCalls, calls)
}
})
}
}
-func TestVerifyingReaderUsesStrongestNativeAlgorithm(t *testing.T) {
- const data = "artifact"
- tests := []struct {
- name string
- native string
- wantCalls int
- }{
- {
- name: "weaker match does not override stronger mismatch",
- native: sha256SRI(data) + " " + sha512SRI("other"),
- wantCalls: 1,
- },
- {
- name: "stronger match ignores weaker mismatch",
- native: sha256SRI("other") + " " + sha512SRI(data),
- },
- {
- name: "same algorithm alternative matches",
- native: sha512SRI("other") + " " + sha512SRI(data),
- },
- }
- for _, test := range tests {
- t.Run(test.name, func(t *testing.T) {
- var calls int
- reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader(data)), "", test.native, func(string) { calls++ })
- if _, err := io.Copy(io.Discard, reader); err != nil {
- t.Fatal(err)
- }
- if calls != test.wantCalls {
- t.Errorf("onMismatch called %d times, want %d", calls, test.wantCalls)
- }
- })
- }
-}
-
-func TestVerifyingReaderMismatchMessages(t *testing.T) {
- const data = "actual"
- wantHash := sha256Hex("expected")
- wantSRI := sha512SRI("expected")
- var reasons []string
- reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader(data)), wantHash, wantSRI,
- func(reason string) { reasons = append(reasons, reason) })
- if _, err := io.Copy(io.Discard, reader); err != nil {
- t.Fatal(err)
- }
- if len(reasons) != 2 {
- t.Fatalf("reasons = %v, want two", reasons)
- }
- wantContentReason := "content_hash: integrity mismatch: expected " + sha256SRI("expected") + ", calculated " + sha256SRI(data)
- if reasons[0] != wantContentReason {
- t.Errorf("content reason = %q, want %q", reasons[0], wantContentReason)
- }
- wantNativeReason := "integrity: integrity mismatch: expected " + wantSRI + ", calculated " + sha512SRI(data)
- if reasons[1] != wantNativeReason {
- t.Errorf("native reason = %q, want %q", reasons[1], wantNativeReason)
- }
-}
-
func TestVerifyingReaderPassthrough(t *testing.T) {
- source := io.NopCloser(strings.NewReader("x"))
- reader := wrapIntegrityReader(t, source, "", "", func(string) { t.Fatal("should not be called") })
- if reader != source {
- t.Error("expected passthrough when no hashes were provided")
+ src := io.NopCloser(strings.NewReader("x"))
+ r := newVerifyingReader(src, "", "", func(string) { t.Fatal("should not be called") })
+ if r != src {
+ t.Error("expected passthrough when no hashes provided")
}
}
-type closeTrackingReader struct {
- io.Reader
- closed bool
-}
-
-func (r *closeTrackingReader) Close() error {
- r.closed = true
- return nil
-}
-
func TestVerifyingReaderPartialRead(t *testing.T) {
- source := &closeTrackingReader{Reader: strings.NewReader("hello world")}
var calls int
- reader := wrapIntegrityReader(t, source, sha256Hex("other"), "", func(string) { calls++ })
+ r := newVerifyingReader(io.NopCloser(strings.NewReader("hello world")),
+ sha256Hex("hello world"), "", func(string) { calls++ })
- buffer := make([]byte, 5)
- _, _ = reader.Read(buffer)
- _ = reader.Close()
+ buf := make([]byte, 5)
+ _, _ = r.Read(buf)
+ _ = r.Close()
if calls != 0 {
t.Errorf("onMismatch called %d times for partial read, want 0", calls)
}
- if !source.closed {
- t.Error("Close was not forwarded to the source")
- }
-}
-
-func TestVerifyingReaderNonEOFError(t *testing.T) {
- var calls int
- reader := wrapIntegrityReader(t, io.NopCloser(errorFixtureReader{}), sha256Hex("data"), "", func(string) { calls++ })
- if _, err := io.ReadAll(reader); !errors.Is(err, errIntegrityReadFixture) {
- t.Fatalf("ReadAll error = %v", err)
- }
- if calls != 0 {
- t.Errorf("onMismatch called %d times after non-EOF error", calls)
- }
-}
-
-var errIntegrityReadFixture = errors.New("integrity read fixture")
-
-type errorFixtureReader struct{}
-
-func (errorFixtureReader) Read(p []byte) (int, error) {
- return copy(p, "data"), errIntegrityReadFixture
}
func TestVerifyingReaderVerifyOnce(t *testing.T) {
var calls int
- reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader("x")), sha256Hex("y"), "", func(string) { calls++ })
- _, _ = io.ReadAll(reader)
- _ = reader.Close()
- _ = reader.Close()
+ r := newVerifyingReader(io.NopCloser(strings.NewReader("x")), sha256Hex("y"), "",
+ func(string) { calls++ })
+ _, _ = io.ReadAll(r)
+ _ = r.Close()
+ _ = r.Close()
if calls != 1 {
t.Errorf("onMismatch called %d times, want 1", calls)
}
diff --git a/internal/handler/julia.go b/internal/handler/julia.go
index 0fed8c9..08b1fdf 100644
--- a/internal/handler/julia.go
+++ b/internal/handler/julia.go
@@ -90,7 +90,8 @@ func (h *JuliaHandler) handleRegistry(w http.ResponseWriter, r *http.Request) {
upstreamURL := h.upstreamURL + r.URL.Path
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "julia", juliaRegistryName, hash, hash+".tar.gz", upstreamURL)
if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch registry")
+ h.proxy.Logger.Error("failed to get registry", "error", err)
+ http.Error(w, "failed to fetch registry", http.StatusBadGateway)
return
}
@@ -118,7 +119,8 @@ func (h *JuliaHandler) handlePackage(w http.ResponseWriter, r *http.Request) {
upstreamURL := h.upstreamURL + r.URL.Path
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "julia", name, hash, hash+".tar.gz", upstreamURL)
if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch package")
+ h.proxy.Logger.Error("failed to get package", "error", err)
+ http.Error(w, "failed to fetch package", http.StatusBadGateway)
return
}
@@ -139,7 +141,8 @@ func (h *JuliaHandler) handleArtifact(w http.ResponseWriter, r *http.Request) {
upstreamURL := h.upstreamURL + r.URL.Path
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "julia", juliaArtifactName, hash, hash+".tar.gz", upstreamURL)
if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch artifact")
+ h.proxy.Logger.Error("failed to get artifact", "error", err)
+ http.Error(w, "failed to fetch artifact", http.StatusBadGateway)
return
}
diff --git a/internal/handler/maven.go b/internal/handler/maven.go
index 10e551e..c423645 100644
--- a/internal/handler/maven.go
+++ b/internal/handler/maven.go
@@ -130,7 +130,12 @@ func (h *MavenHandler) handleDownload(w http.ResponseWriter, r *http.Request, ur
}
}
if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch artifact")
+ if errors.Is(err, ErrUpstreamNotFound) {
+ http.Error(w, "not found", http.StatusNotFound)
+ return
+ }
+ h.proxy.Logger.Error("failed to get artifact", "error", err)
+ http.Error(w, "failed to fetch artifact", http.StatusBadGateway)
return
}
diff --git a/internal/handler/notfound_ecosystems_test.go b/internal/handler/notfound_ecosystems_test.go
deleted file mode 100644
index 44c4486..0000000
--- a/internal/handler/notfound_ecosystems_test.go
+++ /dev/null
@@ -1,139 +0,0 @@
-package handler
-
-import (
- "net/http"
- "net/http/httptest"
- "strings"
- "testing"
-
- "github.com/git-pkgs/registries/fetch"
-)
-
-func TestArtifactDownloadUpstreamNotFoundReturns404(t *testing.T) {
- tests := []struct {
- name string
- path string
- handler func(p *Proxy) http.Handler
- }{
- {"debian", "/pool/main/n/nginx/nginx_1.18.0-6_amd64.deb",
- func(p *Proxy) http.Handler { return NewDebianHandler(p, "http://localhost", "").Routes() }},
- {"rpm", "/releases/39/Everything/x86_64/os/Packages/n/nginx-1.24.0-1.fc39.x86_64.rpm",
- func(p *Proxy) http.Handler { return NewRPMHandler(p, "http://localhost").Routes() }},
- {"nuget", "/v3-flatcontainer/newtonsoft.json/13.0.3/newtonsoft.json.13.0.3.nupkg",
- func(p *Proxy) http.Handler { return NewNuGetHandler(p, "http://localhost").Routes() }},
- {"pypi", "/packages/packages/ab/cd/ef0123456789/requests-2.31.0-py3-none-any.whl",
- func(p *Proxy) http.Handler { return NewPyPIHandler(p, "http://localhost").Routes() }},
- {"cran", "/src/contrib/ggplot2_3.4.4.tar.gz",
- func(p *Proxy) http.Handler { return NewCRANHandler(p, "http://localhost").Routes() }},
- {"conda", "/conda-forge/linux-64/numpy-1.26.0-py311_0.tar.bz2",
- func(p *Proxy) http.Handler { return NewCondaHandler(p, "http://localhost").Routes() }},
- {"conan", "/v1/files/zlib/1.3.1/_/_/0/recipe/conan_sources.tgz",
- func(p *Proxy) http.Handler { return NewConanHandler(p, "http://localhost").Routes() }},
- {"gem", "/gems/rails-7.1.0.gem",
- func(p *Proxy) http.Handler { return NewGemHandler(p, "http://localhost").Routes() }},
- {"hex", "/tarballs/phoenix-1.7.10.tar",
- func(p *Proxy) http.Handler { return NewHexHandler(p, "http://localhost").Routes() }},
- }
-
- for _, tt := range tests {
- t.Run(tt.name, func(t *testing.T) {
- proxy, _, _, fetcher := setupTestProxy(t)
- fetcher.fetchErr = fetch.ErrNotFound
-
- srv := httptest.NewServer(tt.handler(proxy))
- defer srv.Close()
-
- resp, err := http.Get(srv.URL + tt.path)
- if err != nil {
- t.Fatalf("request failed: %v", err)
- }
- defer func() { _ = resp.Body.Close() }()
-
- if resp.StatusCode != http.StatusNotFound {
- t.Errorf("want 404 for missing upstream artifact, got %d", resp.StatusCode)
- }
- })
- }
-}
-
-func TestJuliaPackageUpstreamNotFoundReturns404(t *testing.T) {
- proxy, _, _, fetcher := setupTestProxy(t)
- fetcher.fetchErr = fetch.ErrNotFound
-
- dead := httptest.NewServer(http.NotFoundHandler())
- defer dead.Close()
-
- h := NewJuliaHandler(proxy, "http://localhost")
- h.upstreamURL = dead.URL
-
- srv := httptest.NewServer(h.Routes())
- defer srv.Close()
-
- resp, err := http.Get(srv.URL +
- "/package/7876af07-990d-54b4-ab0e-23690620f79a/0123456789abcdef0123456789abcdef01234567")
- if err != nil {
- t.Fatalf("request failed: %v", err)
- }
- defer func() { _ = resp.Body.Close() }()
-
- if resp.StatusCode != http.StatusNotFound {
- t.Errorf("want 404 for missing upstream package, got %d", resp.StatusCode)
- }
-}
-
-func TestComposerDownloadUpstreamNotFoundReturns404(t *testing.T) {
- proxy, _, _, fetcher := setupTestProxy(t)
- fetcher.fetchErr = fetch.ErrNotFound
-
- meta := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- if r.URL.Path == "/p2/monolog/monolog.json" {
- _, _ = w.Write([]byte(`{
- "packages": {
- "monolog/monolog": [
- {"version": "2.9.1", "dist": {"url": "https://example.com/monolog-2.9.1.zip", "type": "zip"}}
- ]
- }
- }`))
- return
- }
- http.NotFound(w, r)
- }))
- defer meta.Close()
-
- h := &ComposerHandler{proxy: proxy, repoURL: meta.URL, proxyURL: "http://localhost"}
- srv := httptest.NewServer(h.Routes())
- defer srv.Close()
-
- resp, err := http.Get(srv.URL + "/files/monolog/monolog/2.9.1/monolog-2.9.1.zip")
- if err != nil {
- t.Fatalf("request failed: %v", err)
- }
- defer func() { _ = resp.Body.Close() }()
-
- if resp.StatusCode != http.StatusNotFound {
- t.Errorf("want 404 for missing upstream dist, got %d", resp.StatusCode)
- }
-}
-
-func TestContainerBlobUpstreamNotFoundReturns404(t *testing.T) {
- proxy, _, _, fetcher := setupTestProxy(t)
- fetcher.fetchErr = fetch.ErrNotFound
-
- h := &ContainerHandler{
- proxy: proxy,
- registryURL: "https://registry-1.docker.io",
- proxyURL: "http://localhost:8080",
- }
-
- req := httptest.NewRequest(http.MethodGet,
- "/library/nginx/blobs/sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd", nil)
- w := httptest.NewRecorder()
- h.Routes().ServeHTTP(w, req)
-
- if w.Code != http.StatusNotFound {
- t.Errorf("want 404 for missing upstream blob, got %d; body: %s", w.Code, w.Body.String())
- }
- if !strings.Contains(w.Body.String(), "BLOB_UNKNOWN") {
- t.Errorf("want BLOB_UNKNOWN error code in body, got: %s", w.Body.String())
- }
-}
diff --git a/internal/handler/notfound_test.go b/internal/handler/notfound_test.go
deleted file mode 100644
index 9ea38ac..0000000
--- a/internal/handler/notfound_test.go
+++ /dev/null
@@ -1,83 +0,0 @@
-package handler
-
-import (
- "context"
- "errors"
- "io"
- "net/http"
- "net/http/httptest"
- "strings"
- "testing"
-
- "github.com/git-pkgs/registries/fetch"
-)
-
-func TestErrUpstreamNotFoundWrapsFetchErrNotFound(t *testing.T) {
- if !errors.Is(ErrUpstreamNotFound, fetch.ErrNotFound) {
- t.Fatal("ErrUpstreamNotFound does not wrap fetch.ErrNotFound")
- }
-}
-
-func TestGetOrFetchArtifactFromURL_NotFound(t *testing.T) {
- proxy, _, _, fetcher := setupTestProxy(t)
- fetcher.fetchErr = fetch.ErrNotFound
-
- _, err := proxy.GetOrFetchArtifactFromURL(context.Background(),
- "maven", "org.example:missing", "1.0", "missing-1.0.jar",
- "http://upstream.test/org/example/missing/1.0/missing-1.0.jar")
-
- if !errors.Is(err, ErrUpstreamNotFound) {
- t.Fatalf("want ErrUpstreamNotFound, got %v", err)
- }
-}
-
-func TestMavenHandler_UpstreamNotFoundReturns404(t *testing.T) {
- proxy, _, _, fetcher := setupTestProxy(t)
- fetcher.fetchErr = fetch.ErrNotFound
-
- h := NewMavenHandler(proxy, "http://localhost", "http://upstream.test", "http://portal.test")
- srv := httptest.NewServer(h.Routes())
- defer srv.Close()
-
- resp, err := http.Get(srv.URL + "/org/example/missing/1.0/missing-1.0.jar")
- if err != nil {
- t.Fatalf("request failed: %v", err)
- }
- defer func() { _ = resp.Body.Close() }()
-
- if resp.StatusCode != http.StatusNotFound {
- t.Errorf("want 404 for missing upstream artifact, got %d", resp.StatusCode)
- }
-}
-
-func TestMavenHandler_PluginPortalFallback(t *testing.T) {
- proxy, _, _, fetcher := setupTestProxy(t)
- fetcher.fetchErrByURL = map[string]error{
- "http://upstream.test/org/example/plugin/1.0/plugin-1.0.jar": fetch.ErrNotFound,
- }
- fetcher.artifact = &fetch.Artifact{
- Body: io.NopCloser(strings.NewReader("portal artifact")),
- ContentType: "application/java-archive",
- }
-
- h := NewMavenHandler(proxy, "http://localhost", "http://upstream.test", "http://portal.test")
- srv := httptest.NewServer(h.Routes())
- defer srv.Close()
-
- resp, err := http.Get(srv.URL + "/org/example/plugin/1.0/plugin-1.0.jar")
- if err != nil {
- t.Fatalf("request failed: %v", err)
- }
- defer func() { _ = resp.Body.Close() }()
-
- if resp.StatusCode != http.StatusOK {
- t.Fatalf("want 200 via plugin portal fallback, got %d", resp.StatusCode)
- }
- body, _ := io.ReadAll(resp.Body)
- if string(body) != "portal artifact" {
- t.Errorf("want portal artifact body, got %q", body)
- }
- if fetcher.fetchedURL != "http://portal.test/org/example/plugin/1.0/plugin-1.0.jar" {
- t.Errorf("fallback did not hit plugin portal, last URL: %s", fetcher.fetchedURL)
- }
-}
diff --git a/internal/handler/npm.go b/internal/handler/npm.go
index b7d96a3..0585eda 100644
--- a/internal/handler/npm.go
+++ b/internal/handler/npm.go
@@ -9,11 +9,13 @@ import (
"sort"
"strings"
"time"
+
+ "github.com/git-pkgs/purl"
)
const (
npmUpstream = "https://registry.npmjs.org"
- npmAcceptDefault = "application/vnd.npm.install-v1+json;q=1.0, application/json;q=0.8"
+ npmAbbreviatedCT = "application/vnd.npm.install-v1+json"
scopedParts = 2 // scope + name in scoped packages
)
@@ -25,14 +27,10 @@ type NPMHandler struct {
}
// NewNPMHandler creates a new npm protocol handler.
-func NewNPMHandler(proxy *Proxy, proxyURL, upstreamURL string) *NPMHandler {
- if strings.TrimSpace(upstreamURL) == "" {
- upstreamURL = npmUpstream
- }
-
+func NewNPMHandler(proxy *Proxy, proxyURL string) *NPMHandler {
return &NPMHandler{
proxy: proxy,
- upstreamURL: strings.TrimSuffix(upstreamURL, "/"),
+ upstreamURL: npmUpstream,
proxyURL: strings.TrimSuffix(proxyURL, "/"),
}
}
@@ -71,12 +69,9 @@ func (h *NPMHandler) handlePackageMetadata(w http.ResponseWriter, r *http.Reques
upstreamURL := fmt.Sprintf("%s/%s", h.upstreamURL, url.PathEscape(packageName))
- // Prefer the smaller abbreviated packument format but include application/json
- // as a fallback so upstreams that reject the abbreviated type (e.g. JFrog
- // Artifactory, which returns 406) can still respond with full metadata.
- // When cooldown is enabled we must use full metadata exclusively because the
- // abbreviated format omits the "time" map required for version age filtering.
- accept := npmAcceptDefault
+ // Use abbreviated metadata when cooldown is disabled — it's much smaller
+ // (e.g. drizzle-orm: 4MB vs 92MB) but lacks the time map needed for cooldown.
+ accept := npmAbbreviatedCT
if h.proxy.Cooldown != nil && h.proxy.Cooldown.Enabled() {
accept = contentTypeJSON
}
@@ -139,7 +134,7 @@ func (h *NPMHandler) applyCooldownFiltering(metadata map[string]any, versions ma
return
}
- packagePURL := canonicalPackagePURL("npm", packageName)
+ packagePURL := purl.MakePURLString("npm", packageName, "")
for version := range versions {
publishedStr, ok := timeMap[version].(string)
@@ -268,27 +263,8 @@ func (h *NPMHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
h.proxy.Logger.Info("npm download request",
"package", packageName, "version", version, "filename", filename)
- if h.versionInCooldown(r, packageName, version) {
- h.proxy.Logger.Info("cooldown: withholding npm tarball",
- "package", packageName, "version", version)
- JSONError(w, http.StatusNotFound, "version not found")
- return
- }
-
- downloadURL := fmt.Sprintf(
- "%s/%s/-/%s",
- h.upstreamURL,
- escapeNPMDownloadPackage(packageName),
- url.PathEscape(filename),
- )
- result, err := h.proxy.GetOrFetchArtifactFromURL(
- r.Context(), "npm", packageName, version, filename, downloadURL,
- )
+ result, err := h.proxy.GetOrFetchArtifact(r.Context(), "npm", packageName, version, filename)
if err != nil {
- if errors.Is(err, ErrUpstreamNotFound) {
- JSONError(w, http.StatusNotFound, "package not found")
- return
- }
h.proxy.Logger.Error("failed to get artifact", "error", err)
JSONError(w, http.StatusBadGateway, "failed to fetch package")
return
@@ -297,58 +273,6 @@ func (h *NPMHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
ServeArtifact(w, result)
}
-// versionInCooldown reports whether a version is still inside the cooldown
-// window. Filtering the packument is not enough on its own: tarball URLs are
-// predictable and lockfiles record them directly, so `npm ci` reaches the
-// download path without ever requesting metadata.
-//
-// The packument is served from the metadata cache, so this normally costs no
-// extra upstream request. A version with no usable publish time is allowed
-// through, matching how applyCooldownFiltering treats it.
-func (h *NPMHandler) versionInCooldown(r *http.Request, packageName, version string) bool {
- if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() {
- return false
- }
-
- upstreamURL := fmt.Sprintf("%s/%s", h.upstreamURL, url.PathEscape(packageName))
-
- body, _, err := h.proxy.FetchOrCacheMetadata(r.Context(), "npm", packageName, upstreamURL, contentTypeJSON)
- if err != nil {
- h.proxy.Logger.Warn("cooldown: could not fetch npm metadata for download check",
- "package", packageName, "version", version, "error", err)
- return false
- }
-
- var metadata struct {
- Time map[string]string `json:"time"`
- }
- if err := json.Unmarshal(body, &metadata); err != nil {
- h.proxy.Logger.Warn("cooldown: could not parse npm metadata for download check",
- "package", packageName, "version", version, "error", err)
- return false
- }
-
- published, ok := metadata.Time[version]
- if !ok {
- return false
- }
-
- publishedAt, err := time.Parse(time.RFC3339, published)
- if err != nil {
- return false
- }
-
- return !h.proxy.Cooldown.IsAllowed("npm", canonicalPackagePURL("npm", packageName), publishedAt)
-}
-
-func escapeNPMDownloadPackage(packageName string) string {
- scope, name, scoped := strings.Cut(packageName, "/")
- if scoped && strings.HasPrefix(scope, "@") && len(scope) > 1 && name != "" && !strings.Contains(name, "/") {
- return url.PathEscape(scope) + "/" + url.PathEscape(name)
- }
- return url.PathEscape(packageName)
-}
-
// extractPackageName extracts the package name from the request path.
// Handles both scoped (@scope/name) and unscoped (name) packages.
func (h *NPMHandler) extractPackageName(r *http.Request) string {
diff --git a/internal/handler/npm_test.go b/internal/handler/npm_test.go
index 07da9c3..bc1edde 100644
--- a/internal/handler/npm_test.go
+++ b/internal/handler/npm_test.go
@@ -2,16 +2,13 @@ package handler
import (
"encoding/json"
- "io"
"log/slog"
"net/http"
"net/http/httptest"
- "strings"
"testing"
"time"
"github.com/git-pkgs/cooldown"
- "github.com/git-pkgs/registries/fetch"
)
const testVersion100 = "1.0.0"
@@ -49,86 +46,6 @@ func TestNPMExtractVersionFromFilename(t *testing.T) {
}
}
-func TestNPMHandlerUsesConfiguredUpstream(t *testing.T) {
- t.Run("metadata", func(t *testing.T) {
- var requestPath, authHeader string
- upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- requestPath = r.URL.Path
- authHeader = r.Header.Get("Authorization")
- if authHeader != "Bearer npm-token" {
- w.WriteHeader(http.StatusUnauthorized)
- return
- }
- w.Header().Set("Content-Type", "application/json")
- _, _ = io.WriteString(w, `{"versions":{}}`)
- }))
- defer upstream.Close()
-
- proxy, _, _, _ := setupTestProxy(t)
- proxy.HTTPClient = upstream.Client()
- proxy.AuthForURL = func(string) (string, string) {
- return "Authorization", "Bearer npm-token"
- }
- h := NewNPMHandler(proxy, "http://proxy.test", upstream.URL+"/root/")
-
- req := httptest.NewRequest(http.MethodGet, "/testpkg", nil)
- w := httptest.NewRecorder()
- h.Routes().ServeHTTP(w, req)
-
- if w.Code != http.StatusOK {
- t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
- }
- if requestPath != "/root/testpkg" {
- t.Errorf("upstream path = %q, want %q", requestPath, "/root/testpkg")
- }
- if authHeader != "Bearer npm-token" {
- t.Errorf("Authorization = %q, want %q", authHeader, "Bearer npm-token")
- }
- })
-
- t.Run("download", func(t *testing.T) {
- proxy, _, _, artifactFetcher := setupTestProxy(t)
- artifactFetcher.artifact = &fetch.Artifact{
- Body: io.NopCloser(strings.NewReader("package")),
- ContentType: "application/gzip",
- }
- h := NewNPMHandler(proxy, "http://proxy.test", "https://npm.example.test/root/")
-
- req := httptest.NewRequest(http.MethodGet, "/testpkg/-/testpkg-1.0.0.tgz", nil)
- w := httptest.NewRecorder()
- h.Routes().ServeHTTP(w, req)
-
- if w.Code != http.StatusOK {
- t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
- }
- want := "https://npm.example.test/root/testpkg/-/testpkg-1.0.0.tgz"
- if artifactFetcher.fetchedURL != want {
- t.Errorf("fetched URL = %q, want %q", artifactFetcher.fetchedURL, want)
- }
- })
-
- t.Run("scoped download", func(t *testing.T) {
- proxy, _, _, artifactFetcher := setupTestProxy(t)
- artifactFetcher.artifact = &fetch.Artifact{
- Body: io.NopCloser(strings.NewReader("package")),
- ContentType: "application/gzip",
- }
- h := NewNPMHandler(proxy, "http://proxy.test", "https://npm.example.test/root/")
-
- req := httptest.NewRequest(http.MethodGet, "/@scope/name/-/name-1.0.0.tgz", nil)
- w := httptest.NewRecorder()
- h.Routes().ServeHTTP(w, req)
-
- if w.Code != http.StatusOK {
- t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
- }
- want := "https://npm.example.test/root/@scope/name/-/name-1.0.0.tgz"
- if artifactFetcher.fetchedURL != want {
- t.Errorf("fetched URL = %q, want %q", artifactFetcher.fetchedURL, want)
- }
- })
-}
-
func TestNPMRewriteMetadata(t *testing.T) {
h := &NPMHandler{
proxy: testProxy(),
@@ -396,7 +313,7 @@ func TestNPMHandlerUsesAbbreviatedMetadata(t *testing.T) {
}))
defer upstream.Close()
- t.Run("no cooldown uses combined accept header", func(t *testing.T) {
+ t.Run("no cooldown uses abbreviated metadata", func(t *testing.T) {
h := &NPMHandler{
proxy: testProxy(),
upstreamURL: upstream.URL,
@@ -407,12 +324,12 @@ func TestNPMHandlerUsesAbbreviatedMetadata(t *testing.T) {
w := httptest.NewRecorder()
h.handlePackageMetadata(w, req)
- if gotAccept != npmAcceptDefault {
- t.Errorf("Accept = %q, want %q", gotAccept, npmAcceptDefault)
+ if gotAccept != npmAbbreviatedCT {
+ t.Errorf("Accept = %q, want abbreviated metadata header", gotAccept)
}
})
- t.Run("cooldown enabled uses full metadata only", func(t *testing.T) {
+ t.Run("cooldown enabled uses full metadata", func(t *testing.T) {
proxy := testProxy()
proxy.Cooldown = &cooldown.Config{Default: "3d"}
@@ -426,8 +343,8 @@ func TestNPMHandlerUsesAbbreviatedMetadata(t *testing.T) {
w := httptest.NewRecorder()
h.handlePackageMetadata(w, req)
- if gotAccept != contentTypeJSON {
- t.Errorf("Accept = %q, want %q (cooldown requires full metadata)", gotAccept, contentTypeJSON)
+ if gotAccept == npmAbbreviatedCT {
+ t.Error("cooldown enabled should use full metadata, not abbreviated")
}
})
}
@@ -454,81 +371,3 @@ func TestNPMHandlerMetadataNotFound(t *testing.T) {
t.Errorf("status = %d, want %d", w.Code, http.StatusNotFound)
}
}
-
-func TestNPMDownloadCooldown(t *testing.T) {
- now := time.Now()
- packument := `{
- "name": "leftpad",
- "dist-tags": {"latest": "2.0.0"},
- "time": {
- "1.0.0": "` + now.Add(-30*24*time.Hour).Format(time.RFC3339) + `",
- "2.0.0": "` + now.Add(-1*time.Hour).Format(time.RFC3339) + `"
- },
- "versions": {"1.0.0": {}, "2.0.0": {}}
- }`
-
- upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
- w.Header().Set("Content-Type", contentTypeJSON)
- _, _ = io.WriteString(w, packument)
- }))
- defer upstream.Close()
-
- tests := []struct {
- name string
- version string
- wantStatus int
- }{
- {"published before the window serves the tarball", testVersion100, http.StatusOK},
- {"published inside the window is withheld", "2.0.0", http.StatusNotFound},
- }
-
- for _, tt := range tests {
- t.Run(tt.name, func(t *testing.T) {
- proxy, _, _, fetcher := setupTestProxy(t)
- proxy.HTTPClient = upstream.Client()
- proxy.Cooldown = &cooldown.Config{Default: "7d"}
- fetcher.artifact = &fetch.Artifact{
- Body: io.NopCloser(strings.NewReader("tarball data")),
- ContentType: "application/octet-stream",
- }
-
- h := NewNPMHandler(proxy, "http://proxy.test", upstream.URL)
- srv := httptest.NewServer(h.Routes())
- defer srv.Close()
-
- resp, err := http.Get(srv.URL + "/leftpad/-/leftpad-" + tt.version + ".tgz")
- if err != nil {
- t.Fatalf("request failed: %v", err)
- }
- defer func() { _ = resp.Body.Close() }()
-
- if resp.StatusCode != tt.wantStatus {
- t.Errorf("status = %d, want %d", resp.StatusCode, tt.wantStatus)
- }
- if tt.wantStatus == http.StatusNotFound && fetcher.fetchCalled {
- t.Error("fetched a version that is still inside the cooldown window")
- }
- })
- }
-}
-
-func TestNPMDownloadCooldownDisabled(t *testing.T) {
- upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
- t.Error("metadata must not be fetched when cooldown is disabled")
- w.WriteHeader(http.StatusInternalServerError)
- }))
- defer upstream.Close()
-
- proxy, _, _, fetcher := setupTestProxy(t)
- proxy.HTTPClient = upstream.Client()
- fetcher.artifact = &fetch.Artifact{
- Body: io.NopCloser(strings.NewReader("tarball data")),
- ContentType: "application/octet-stream",
- }
-
- h := NewNPMHandler(proxy, "http://proxy.test", upstream.URL)
-
- if h.versionInCooldown(httptest.NewRequest(http.MethodGet, "/", nil), "leftpad", testVersion100) {
- t.Error("versionInCooldown = true, want false when cooldown is not configured")
- }
-}
diff --git a/internal/handler/nuget.go b/internal/handler/nuget.go
index 4785e40..40b8b5f 100644
--- a/internal/handler/nuget.go
+++ b/internal/handler/nuget.go
@@ -8,6 +8,8 @@ import (
"net/http"
"strings"
"time"
+
+ "github.com/git-pkgs/purl"
)
const (
@@ -269,7 +271,7 @@ func (h *NuGetHandler) applyCooldownFiltering(body []byte) ([]byte, error) {
}
}
- packagePURL := canonicalPackagePURL("nuget", strings.ToLower(id))
+ packagePURL := purl.MakePURLString("nuget", strings.ToLower(id), "")
if !h.proxy.Cooldown.IsAllowed("nuget", packagePURL, publishedAt) {
h.proxy.Logger.Info("cooldown: filtering nuget version",
@@ -314,7 +316,8 @@ func (h *NuGetHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "nuget", name, version, filename, upstreamURL)
if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch package")
+ h.proxy.Logger.Error("failed to get artifact", "error", err)
+ http.Error(w, "failed to fetch package", http.StatusBadGateway)
return
}
diff --git a/internal/handler/pub.go b/internal/handler/pub.go
index e5ca199..60bbbad 100644
--- a/internal/handler/pub.go
+++ b/internal/handler/pub.go
@@ -7,6 +7,8 @@ import (
"net/http"
"strings"
"time"
+
+ "github.com/git-pkgs/purl"
)
const (
@@ -67,7 +69,8 @@ func (h *PubHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
result, err := h.proxy.GetOrFetchArtifact(r.Context(), "pub", name, version, filename)
if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch package")
+ h.proxy.Logger.Error("failed to get artifact", "error", err)
+ http.Error(w, "failed to fetch package", http.StatusBadGateway)
return
}
@@ -124,7 +127,7 @@ func (h *PubHandler) rewriteMetadata(name string, body []byte) ([]byte, error) {
return body, nil
}
- packagePURL := canonicalPackagePURL("pub", name)
+ packagePURL := purl.MakePURLString("pub", name, "")
filtered := h.filterAndRewriteVersions(name, packagePURL, versions)
metadata["versions"] = filtered
diff --git a/internal/handler/pypi.go b/internal/handler/pypi.go
index 10a3a13..3021d2b 100644
--- a/internal/handler/pypi.go
+++ b/internal/handler/pypi.go
@@ -12,6 +12,8 @@ import (
"regexp"
"strings"
"time"
+
+ "github.com/git-pkgs/purl"
)
const (
@@ -19,14 +21,7 @@ const (
minWheelParts = 5 // name + version + python + abi + platform
minSubmatchParts = 2 // full match + first capture group
minPyPIPathParts = 3 // hash_prefix + hash + filename
- minEggParts = 3 // name + version + python tag
-
- // PyPIMetadataSuffix is the PEP 658 core-metadata sidecar suffix that pip
- // appends to a distribution URL when the index advertises core metadata.
- // A sidecar resolves to the same name and version as the distribution it
- // describes, so it is cached alongside it; consumers that expect an openable
- // archive must skip these.
- PyPIMetadataSuffix = ".metadata"
+ minPythonTagLen = 2 // minimum length for a python tag (e.g., "py")
)
// PyPIHandler handles PyPI registry protocol requests.
@@ -110,14 +105,24 @@ func (h *PyPIHandler) handleSimplePackage(w http.ResponseWriter, r *http.Request
// that should be filtered out due to cooldown.
func (h *PyPIHandler) fetchFilteredVersions(r *http.Request, name string) map[string]bool {
jsonURL := fmt.Sprintf("%s/pypi/%s/json", h.upstreamURL, name)
-
- body, _, err := h.proxy.FetchOrCacheMetadata(r.Context(), "pypi", name+"/json", jsonURL)
+ req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, jsonURL, nil)
if err != nil {
return nil
}
+ req.Header.Set("Accept", "application/json")
+
+ resp, err := h.proxy.HTTPClient.Do(req)
+ if err != nil {
+ return nil
+ }
+ defer func() { _ = resp.Body.Close() }()
+
+ if resp.StatusCode != http.StatusOK {
+ return nil
+ }
var metadata map[string]any
- if err := json.Unmarshal(body, &metadata); err != nil {
+ if err := json.NewDecoder(resp.Body).Decode(&metadata); err != nil {
return nil
}
@@ -126,7 +131,7 @@ func (h *PyPIHandler) fetchFilteredVersions(r *http.Request, name string) map[st
return nil
}
- packagePURL := canonicalPackagePURL("pypi", name)
+ packagePURL := purl.MakePURLString("pypi", name, "")
filtered := make(map[string]bool)
for version, files := range releases {
@@ -257,7 +262,7 @@ func (h *PyPIHandler) rewriteJSONMetadata(body []byte) ([]byte, error) {
packageName, _ := extractPyPIName(metadata)
packagePURL := ""
if packageName != "" {
- packagePURL = canonicalPackagePURL("pypi", packageName)
+ packagePURL = purl.MakePURLString("pypi", packageName, "")
}
h.filterAndRewriteReleases(metadata, packageName, packagePURL)
@@ -301,21 +306,6 @@ func (h *PyPIHandler) shouldFilterRelease(packagePURL string, files any) bool {
return !publishedAt.IsZero() && !h.proxy.Cooldown.IsAllowed("pypi", packagePURL, publishedAt)
}
-// versionInCooldown reports whether a version is still inside the cooldown
-// window. Filtering the simple index is not enough on its own: file URLs are
-// recorded in lockfiles and requirements pins, so pip can reach the download
-// path without ever reading the index.
-//
-// A release whose upload time cannot be determined is allowed through, matching
-// how fetchFilteredVersions treats it.
-func (h *PyPIHandler) versionInCooldown(r *http.Request, name, version string) bool {
- if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() {
- return false
- }
-
- return h.fetchFilteredVersions(r, name)[version]
-}
-
// rewriteFileEntries rewrites URLs in a list of file entries.
func (h *PyPIHandler) rewriteFileEntries(files any) {
filesArr, ok := files.([]any)
@@ -422,13 +412,6 @@ func (h *PyPIHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
filename := parts[len(parts)-1]
name, version := h.parseFilename(filename)
- if name != "" && h.versionInCooldown(r, name, version) {
- h.proxy.Logger.Info("cooldown: withholding pypi file",
- "name", name, "version", version, "filename", filename)
- http.Error(w, "not found", http.StatusNotFound)
- return
- }
-
if name == "" {
// Can't determine name/version, use hash as identifier
name = fmt.Sprintf("_hash_%s", hashPath(path))
@@ -445,170 +428,64 @@ func (h *PyPIHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
result, err := h.proxy.GetOrFetchArtifactFromURL(r.Context(), "pypi", name, version, filename, upstreamURL)
if err != nil {
- h.proxy.serveArtifactError(w, err, "failed to fetch package")
+ h.proxy.Logger.Error("failed to get artifact", "error", err)
+ http.Error(w, "failed to fetch package", http.StatusBadGateway)
return
}
ServeArtifact(w, result)
}
-// archiveExtensions are sdist formats of the form {name}-{version}{ext}. They
-// carry no trailing tags, but legacy sdist names may contain hyphens.
-var archiveExtensions = []string{".tar.gz", ".tar.bz2", ".tar.xz", ".tar.Z", ".tgz", ".tar", ".zip"}
-
-// windowsInstallerExtensions are the legacy distutils bdist_wininst and
-// bdist_msi formats, which share a filename layout.
-var windowsInstallerExtensions = []string{".exe", ".msi"}
-
// parseFilename extracts package name and version from a PyPI filename.
-// Handles wheels, sdists and legacy bdist formats:
+// Handles both wheels and sdists:
// - requests-2.31.0-py3-none-any.whl
// - requests-2.31.0.tar.gz
-// - numpy-1.8.0-py2.7-macosx-10.9-x86_64.egg
-// - numpy-1.8.0.win32-py2.7.exe
func (h *PyPIHandler) parseFilename(filename string) (name, version string) {
- // PEP 658/714 core-metadata sidecars are the distribution filename plus
- // ".metadata"; they describe the same name and version. Without this, pip's
- // metadata-only fetches fall back to a hash-derived package identifier.
- filename = strings.TrimSuffix(filename, PyPIMetadataSuffix)
-
- switch {
- case strings.HasSuffix(filename, ".whl"):
- return parseWheelFilename(strings.TrimSuffix(filename, ".whl"))
- case strings.HasSuffix(filename, ".egg"):
- return parseEggFilename(strings.TrimSuffix(filename, ".egg"))
- }
-
- for _, ext := range windowsInstallerExtensions {
- if strings.HasSuffix(filename, ext) {
- return parseWindowsInstallerFilename(strings.TrimSuffix(filename, ext))
+ // Try wheel format first: {name}-{version}(-{build})?-{python}-{abi}-{platform}.whl
+ if strings.HasSuffix(filename, ".whl") {
+ base := strings.TrimSuffix(filename, ".whl")
+ parts := strings.Split(base, "-")
+ if len(parts) >= minWheelParts {
+ // Find where version ends (version followed by python tag)
+ for i := 1; i < len(parts)-2; i++ {
+ // Check if this looks like a python tag (py2, py3, cp39, etc)
+ if isPythonTag(parts[i]) {
+ name = strings.Join(parts[:i-1], "-")
+ version = parts[i-1]
+ return
+ }
+ }
}
}
- for _, ext := range archiveExtensions {
+ // Try sdist formats: {name}-{version}.tar.gz, {name}-{version}.zip
+ for _, ext := range []string{".tar.gz", ".tar.bz2", ".zip", ".tar"} {
if strings.HasSuffix(filename, ext) {
- return splitNameVersion(strings.TrimSuffix(filename, ext))
+ base := strings.TrimSuffix(filename, ext)
+ // Find last hyphen followed by version
+ for i := len(base) - 1; i >= 0; i-- {
+ if base[i] == '-' && i+1 < len(base) && isVersionStart(base[i+1]) {
+ return base[:i], base[i+1:]
+ }
+ }
}
}
return "", ""
}
-// parseWheelFilename parses the PEP 427 layout
-// {name}-{version}(-{build})?-{python}-{abi}-{platform}, base being the
-// filename without its ".whl" suffix. The spec escapes every hyphen in the name
-// and version to '_', so the first two fields are authoritative even when the
-// optional build tag is present.
-func parseWheelFilename(base string) (name, version string) {
- parts := strings.Split(base, "-")
- if len(parts) < minWheelParts {
- return "", ""
- }
-
- return parts[0], parts[1]
-}
-
-// parseEggFilename parses the setuptools bdist_egg layout
-// {name}-{version}-py{X.Y}(-{platform})?, base being the filename without its
-// ".egg" suffix. setuptools escapes hyphens in the name and version to '_', but
-// eggs built by other tooling do not always, so the version is located relative
-// to the interpreter field rather than assumed to be the second field.
-func parseEggFilename(base string) (name, version string) {
- parts := strings.Split(base, "-")
- // Scan from the end: the trailing platform fields never look like an
- // interpreter tag, so the last match is the real one even when the package
- // name itself carries a "py{N}" component. Stop before index 1, since a tag
- // any earlier would leave no room for both a name and a version.
- for i := len(parts) - 1; i >= minEggParts-1; i-- {
- if !isEggPythonTag(parts[i]) || !isVersionField(parts[i-1]) {
- continue
- }
-
- return strings.Join(parts[:i-1], "-"), parts[i-1]
- }
-
- // No interpreter field: {name}-{version}.
- return splitNameVersion(base)
-}
-
-// parseWindowsInstallerFilename parses the distutils bdist_wininst and
-// bdist_msi layout {name}-{version}.{platform}(-py{X.Y})?, base being the
-// filename without its ".exe" or ".msi" suffix. The platform is joined to the
-// version with a '.' rather than a '-' and may itself contain a hyphen
-// ("win-amd64"), so both trailing fields are stripped before the name and
-// version are split apart.
-func parseWindowsInstallerFilename(base string) (name, version string) {
- if i := strings.LastIndex(base, "-py"); i >= 0 && isDottedNumber(base[i+len("-py"):]) {
- base = base[:i]
- }
-
- // The platform is the final '.'-separated field. Requiring it to start with
- // a non-digit keeps a dotted version from being truncated when a filename
- // carries no platform tag.
- i := strings.LastIndex(base, ".")
- if i < 0 || i+1 >= len(base) || isVersionStart(base[i+1]) {
- return "", ""
- }
-
- return splitFullname(base[:i])
-}
-
-// splitFullname splits the distutils fullname {name}-{version} that precedes a
-// Windows installer's platform field. Unlike an sdist, a wininst fullname may
-// carry a trailing build variant ("cx_Oracle-5.1.2-11g"), which belongs to
-// neither the name nor the version, so the first purely numeric field wins and
-// anything after it is discarded.
-func splitFullname(fullname string) (name, version string) {
- parts := strings.Split(fullname, "-")
- for i := 1; i < len(parts); i++ {
- if isDottedNumber(parts[i]) {
- return strings.Join(parts[:i], "-"), parts[i]
- }
- }
-
- // No purely numeric field, e.g. a prerelease version like "1.0b1".
- return splitNameVersion(fullname)
-}
-
-// splitNameVersion splits a {name}-{version} pair at the last hyphen that
-// starts a version, leaving hyphens inside the name intact.
-func splitNameVersion(base string) (name, version string) {
- for i := len(base) - 1; i >= 0; i-- {
- if base[i] == '-' && i+1 < len(base) && isVersionStart(base[i+1]) {
- return base[:i], base[i+1:]
- }
- }
-
- return "", ""
-}
-
-// isEggPythonTag reports whether field is the py{X.Y} interpreter field that
-// setuptools places directly after the version in an egg filename.
-func isEggPythonTag(field string) bool {
- const prefix = "py"
-
- return len(field) > len(prefix) && strings.HasPrefix(field, prefix) && isVersionStart(field[len(prefix)])
-}
-
-// isVersionField reports whether field can be a version, i.e. it is non-empty
-// and starts with a digit as every PEP 440 release segment does.
-func isVersionField(field string) bool {
- return field != "" && isVersionStart(field[0])
-}
-
-// isDottedNumber reports whether s is a dotted numeric version such as "2.7".
-func isDottedNumber(s string) bool {
- if s == "" || !isVersionStart(s[0]) {
+func isPythonTag(s string) bool {
+ if len(s) < minPythonTagLen {
return false
}
-
- for i := range len(s) {
- if !isVersionStart(s[i]) && s[i] != '.' {
- return false
+ // Python tags start with py, cp, pp, ip, jy
+ prefixes := []string{"py", "cp", "pp", "ip", "jy"}
+ for _, p := range prefixes {
+ if strings.HasPrefix(s, p) {
+ return true
}
}
-
- return true
+ return false
}
func isVersionStart(c byte) bool {
diff --git a/internal/handler/pypi_test.go b/internal/handler/pypi_test.go
index a416b44..2b58960 100644
--- a/internal/handler/pypi_test.go
+++ b/internal/handler/pypi_test.go
@@ -7,7 +7,6 @@ import (
"net/http"
"net/http/httptest"
"strings"
- "sync/atomic"
"testing"
"time"
@@ -29,58 +28,13 @@ func TestPyPIParseFilename(t *testing.T) {
{"aws-sdk-1.0.0.tar.gz", "aws-sdk", "1.0.0"},
{"zipp-3.17.0.zip", "zipp", "3.17.0"},
- // Additional sdist archive formats
- {"lxml-4.9.3.tar.xz", "lxml", "4.9.3"},
- {"docutils-0.20.1.tgz", "docutils", "0.20.1"},
- {"psycopg2-2.9.9.tar.bz2", "psycopg2", "2.9.9"},
-
// Wheel formats
{"requests-2.31.0-py3-none-any.whl", "requests", "2.31.0"},
{"numpy-1.26.2-cp311-cp311-manylinux_2_17_x86_64.whl", "numpy", "1.26.2"},
{"cryptography-41.0.5-cp37-abi3-manylinux_2_28_x86_64.whl", "cryptography", "41.0.5"},
- // Wheels with a build tag must not fold the tag into the version
- {"foo-1.0-1-py3-none-any.whl", "foo", "1.0"},
- {"tensorflow-2.15.0-2-cp311-cp311-manylinux_2_17_x86_64.whl", "tensorflow", "2.15.0"},
-
- // PEP 658 core-metadata sidecars resolve to the distribution they describe
- {"backports_asyncio_runner-1.2.0-py3-none-any.whl.metadata", "backports_asyncio_runner", "1.2.0"},
- {"requests-2.31.0-py3-none-any.whl.metadata", "requests", "2.31.0"},
- {"requests-2.31.0.tar.gz.metadata", "requests", "2.31.0"},
-
- // Eggs: {name}-{version}-py{X.Y}(-{platform})?.egg. Unescaped hyphens in
- // the name must not be mistaken for the field separator before the version.
- {"numpy-1.8.0-py2.7-macosx-10.9-x86_64.egg", "numpy", "1.8.0"},
- {"aws-sdk-1.0.0-py3.11.egg", "aws-sdk", "1.0.0"},
- {"aws-sdk-1.0.0-py2.7-macosx-10.9-x86_64.egg", "aws-sdk", "1.0.0"},
- {"aws-sdk-1.0.0.egg", "aws-sdk", "1.0.0"},
- // A "py{N}" component inside the name is not the interpreter field, so
- // the interpreter must be located from the end of the filename.
- {"django-rest-py3-1.0-py3.6.egg", "django-rest-py3", "1.0"},
-
- // Windows installers: {name}-{version}.{platform}(-py{X.Y})?.{exe,msi}.
- // The platform is not part of the version, and may contain a hyphen.
- {"foo-1.0.win32-py2.0.exe", "foo", "1.0"},
- {"pywin32-223.win32-py2.7.exe", "pywin32", "223"},
- {"numpy-1.8.0.win-amd64-py2.7.exe", "numpy", "1.8.0"},
- {"aws-sdk-1.0.0.win32-py2.7.exe", "aws-sdk", "1.0.0"},
- {"pywin32-223.win32.exe", "pywin32", "223"},
- {"cx_Oracle-5.1.2.win32-py2.7.msi", "cx_Oracle", "5.1.2"},
- {"numpy-1.8.0.win-amd64.msi", "numpy", "1.8.0"},
- // A trailing build variant belongs to neither the name nor the version.
- {"cx_Oracle-5.1.2-11g.win32-py2.7.exe", "cx_Oracle", "5.1.2"},
- // A prerelease version has no purely numeric field to anchor on.
- {"foo-1.0b1.win32-py2.7.exe", "foo", "1.0b1"},
-
// Invalid
{"invalid", "", ""},
- {"invalid.metadata", "", ""},
- {"backports.ssl_match_hostname-3.4.0.2-py2.7.whl", "", ""},
- {"invalid.exe", "", ""},
- {"foo-1.0.exe", "", ""},
- // An egg with an interpreter field but no version must not promote the
- // trailing component of a hyphenated name to the version.
- {"aws-sdk-py2.7.egg", "", ""},
}
for _, tt := range tests {
@@ -140,24 +94,25 @@ func TestPyPIRewriteJSONMetadataCooldown(t *testing.T) {
}
}
-// TestPyPIParseFilenameNoHashFallback guards the identifier used for caching:
-// a filename that parses to an empty name makes handleDownload fall back to a
-// "_hash_
- proxy {{.BuildInfo.Version}}{{if .BuildInfo.Commit}} ({{.BuildInfo.Commit}}){{end}} -
- {{end}}