diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index bb3d87d..cd4058f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -13,7 +13,6 @@ jobs: strategy: matrix: os: [ubuntu-latest, macos-latest, windows-latest] - go-version: ['1.25'] runs-on: ${{ matrix.os }} steps: @@ -24,7 +23,7 @@ jobs: - name: Set up Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: - go-version: ${{ matrix.go-version }} + go-version-file: go.mod - name: Build run: go build -v ./... @@ -42,7 +41,7 @@ jobs: - name: Set up Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: - go-version: '1.25' + go-version-file: go.mod - name: golangci-lint run: go tool golangci-lint run ./... diff --git a/.github/workflows/swagger.yml b/.github/workflows/swagger.yml index 625f944..38c42c3 100644 --- a/.github/workflows/swagger.yml +++ b/.github/workflows/swagger.yml @@ -19,7 +19,7 @@ jobs: - name: Set up Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: - go-version: '1.25' + go-version-file: go.mod - name: Install swag run: go install github.com/swaggo/swag/cmd/swag@latest diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 88ad1cb..68a6acf 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -39,7 +39,7 @@ proxy/ │ │ └── queries.go # CRUD operations │ ├── storage/ # Artifact file storage │ │ ├── storage.go # Storage interface -│ │ └── filesystem.go # Local filesystem impl +│ │ └── blob.go # gocloud.dev/blob backends (file, S3, Azure) │ ├── upstream/ # Upstream registry clients │ │ ├── fetcher.go # HTTP artifact fetching │ │ └── resolver.go # Download URL resolution @@ -72,7 +72,7 @@ Key types: ### `internal/storage` -Artifact file storage abstraction. Currently implements local filesystem storage. Designed to allow future backends (S3, GCS). +Artifact file storage abstraction backed by `gocloud.dev/blob`. Supports local filesystem (`file://`), S3 (`s3://`), and Azure (`azblob://`) URLs. Interface: ```go diff --git a/Dockerfile b/Dockerfile index 9c51d30..9a64c5a 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM --platform=$BUILDPLATFORM golang:1.26.5-alpine AS builder +FROM --platform=$BUILDPLATFORM golang:1.26.6-alpine AS builder WORKDIR /src diff --git a/README.md b/README.md index 01012e2..320a737 100644 --- a/README.md +++ b/README.md @@ -362,6 +362,39 @@ Or pull images directly: docker pull localhost:8080/library/nginx:latest ``` +### Helm + +Configure each HTTP chart repository with a name, then add the matching proxy +URL to Helm: + +```yaml +upstream: + helm: + bitnami: "https://charts.bitnami.com/bitnami" +``` + +```bash +helm repo add bitnami http://localhost:8080/helm/bitnami +helm repo update +helm pull bitnami/nginx +``` + +The proxy caches `index.yaml` using the normal metadata-cache settings and +caches chart archives after verifying their SHA-256 digest from the index. + +For charts stored in an OCI registry, configure a named OCI upstream and add +the reserved `upstream/{name}` prefix to the chart reference: + +```yaml +upstream: + oci: + ghcr: "https://ghcr.io" +``` + +```bash +helm pull oci://localhost:8080/upstream/ghcr/owner/charts/mychart --version 1.0.0 --plain-http +``` + ### Debian / APT Configure APT to use the proxy in `/etc/apt/sources.list.d/proxy.list`: @@ -423,6 +456,7 @@ The proxy can be configured via: -database-url string PostgreSQL connection URL -log-level string Log level: debug, info, warn, error (default "info") -log-format string Log format: text, json (default "text") +-access-log string Path to the JSONL access log -version Print version and exit ``` @@ -438,6 +472,7 @@ PROXY_DATABASE_PATH=./cache/proxy.db PROXY_DATABASE_URL=postgres://user:pass@localhost/proxy?sslmode=disable PROXY_LOG_LEVEL=info PROXY_LOG_FORMAT=text +PROXY_ACCESS_LOG_PATH=/var/log/proxy/access.jsonl ``` ### Configuration File @@ -458,6 +493,9 @@ log: level: "info" format: "text" +access_log: + path: "/var/log/proxy/access.jsonl" # Optional JSONL activity log + # Optional: override upstream URLs upstream: npm: "https://registry.npmjs.org" @@ -631,6 +669,7 @@ Recently cached: | `GET /conda/*` | Conda/Anaconda protocol | | `GET /cran/*` | CRAN (R) protocol | | `GET /julia/*` | Julia Pkg server protocol | +| `GET /helm/{repository}/*` | HTTP Helm chart repository protocol | | `GET /v2/*` | OCI/Docker registry protocol | | `GET /debian/*` | Debian/APT repository protocol | | `GET /rpm/*` | RPM/Yum repository protocol | @@ -844,6 +883,8 @@ The proxy exposes Prometheus metrics at `GET /metrics`. All metric names are pre | Metric | Type | Labels | Description | |--------|------|--------|-------------| +| `proxy_requests_total` | counter | `ecosystem`, `status` | Proxy responses by package ecosystem and HTTP status | +| `proxy_request_duration_seconds` | histogram | `ecosystem`, `status` | Proxy request duration | | `proxy_cache_hits_total` | counter | `ecosystem` | Cache hits | | `proxy_cache_misses_total` | counter | `ecosystem` | Cache misses | | `proxy_cache_size_bytes` | gauge | | Total size of cached artifacts | @@ -1024,7 +1065,7 @@ The proxy will recreate the database on next start. Requirements: -- Go 1.25 or later +- Go (the project version is declared in `go.mod`) ```bash git clone https://github.com/git-pkgs/proxy.git diff --git a/cmd/proxy/main.go b/cmd/proxy/main.go index 15a71c0..c5549ad 100644 --- a/cmd/proxy/main.go +++ b/cmd/proxy/main.go @@ -40,6 +40,8 @@ // Log level: debug, info, warn, error (default "info") // -log-format string // Log format: text, json (default "text") +// -access-log string +// Path to the JSONL access log (disabled by default) // // Stats Flags: // @@ -72,6 +74,7 @@ // PROXY_DATABASE_URL - PostgreSQL connection URL // PROXY_LOG_LEVEL - Log level // PROXY_LOG_FORMAT - Log format +// PROXY_ACCESS_LOG_PATH - JSONL access log path // PROXY_UPSTREAM_MAVEN - Maven repository upstream URL // PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL - Gradle Plugin Portal upstream URL // PROXY_GRADLE_BUILD_CACHE_READ_ONLY - Disable Gradle PUT uploads @@ -184,6 +187,7 @@ func runServe() { databaseURL := fs.String("database-url", "", "PostgreSQL connection URL") logLevel := fs.String("log-level", "", "Log level: debug, info, warn, error") logFormat := fs.String("log-format", "", "Log format: text, json") + accessLogPath := fs.String("access-log", "", "Path to the JSONL access log") version := fs.Bool("version", false, "Print version and exit") fs.Usage = func() { @@ -201,6 +205,7 @@ func runServe() { fmt.Fprintf(os.Stderr, " PROXY_DATABASE_URL PostgreSQL connection URL\n") fmt.Fprintf(os.Stderr, " PROXY_LOG_LEVEL Log level\n") fmt.Fprintf(os.Stderr, " PROXY_LOG_FORMAT Log format\n") + fmt.Fprintf(os.Stderr, " PROXY_ACCESS_LOG_PATH JSONL access log path\n") fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_MAVEN Maven repository upstream URL\n") fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL Gradle Plugin Portal upstream URL\n") fmt.Fprintf(os.Stderr, " PROXY_GRADLE_BUILD_CACHE_READ_ONLY Disable Gradle PUT uploads\n") @@ -256,6 +261,9 @@ func runServe() { if *logFormat != "" { cfg.Log.Format = *logFormat } + if *accessLogPath != "" { + cfg.AccessLog.Path = *accessLogPath + } // Validate configuration if err := cfg.Validate(); err != nil { @@ -267,7 +275,10 @@ func runServe() { logger := setupLogger(cfg.Log.Level, cfg.Log.Format) // Create and start server - srv, err := server.New(cfg, logger) + srv, err := server.New(cfg, logger, server.BuildInfo{ + Version: Version, + Commit: Commit, + }) if err != nil { logger.Error("failed to create server", "error", err) os.Exit(1) diff --git a/config.example.yaml b/config.example.yaml index 7ada017..1df95b3 100644 --- a/config.example.yaml +++ b/config.example.yaml @@ -78,6 +78,10 @@ log: # Log format: "text" or "json" format: "text" +# JSONL access log. Leave path empty to disable it. +access_log: + path: "" + # Upstream registry URLs and authentication upstream: # npm registry URL @@ -98,6 +102,15 @@ upstream: # Debian/APT repository URL (used by /debian endpoint) debian: "http://deb.debian.org/debian" + # Named HTTP Helm chart repositories (used by /helm/{name}/) + # helm: + # bitnami: "https://charts.bitnami.com/bitnami" + + # Named OCI registries. Use the upstream/{name}/ repository prefix, e.g. + # oci://proxy.example.com/upstream/ghcr/owner/chart. + # oci: + # ghcr: "https://ghcr.io" + # Authentication for upstream registries # Keys are absolute URL scopes. Scheme, host, effective port, and path # segment boundaries must match; the longest matching scope wins. diff --git a/docs/configuration.md b/docs/configuration.md index 1e5a1c7..3b8b935 100644 --- a/docs/configuration.md +++ b/docs/configuration.md @@ -108,6 +108,30 @@ log: | `log.level` | `PROXY_LOG_LEVEL` | `-log-level` | `debug`, `info`, `warn`, `error` | | `log.format` | `PROXY_LOG_FORMAT` | `-log-format` | `text`, `json` | +## Access Log + +The optional access log records client requests and each HTTP exchange with an upstream registry. It is always written as JSONL, with one JSON object per line. Records for the same client request share a `request_id`. + +```yaml +access_log: + path: "/var/log/proxy/access.jsonl" +``` + +| Config | Environment | Flag | Description | +|--------|-------------|------|-------------| +| `access_log.path` | `PROXY_ACCESS_LOG_PATH` | `-access-log` | File to append JSONL records to; empty disables the log | + +The parent directory must exist and be writable when the proxy starts. A newly created log file is readable and writable only by the proxy process owner. + +A request that receives a rate limit response from an upstream can produce records like these: + +```json +{"time":"2026-08-16T12:00:00Z","event":"upstream","request_id":"host/example-000001","method":"GET","url":"https://registry.example/packages/example","status_code":429,"duration_ms":42} +{"time":"2026-08-16T12:00:00Z","event":"request","request_id":"host/example-000001","method":"GET","path":"/npm/example","status_code":502,"duration_ms":43,"remote_addr":"192.0.2.10:41234"} +``` + +Upstream retries and OCI authentication calls are separate `upstream` records, so the log preserves every status returned over the wire. Network failures have an `error` field and no `status_code`. URL credentials, query strings, and fragments are omitted from both upstream URLs and client paths. + ## Upstream Registries Override default upstream registry URLs: @@ -119,8 +143,28 @@ upstream: gradle_plugin_portal: "https://plugins.gradle.org/m2" cargo: "https://index.crates.io" cargo_download: "https://static.crates.io/crates" + + # Named HTTP Helm chart repositories, served at /helm/{name}/. + helm: + bitnami: "https://charts.bitnami.com/bitnami" + + # Named OCI registries. Select one with the repository prefix + # upstream/{name}/, e.g. oci://proxy.example.com/upstream/ghcr/owner/chart. + oci: + ghcr: "https://ghcr.io" ``` +Helm HTTP repositories are read-only. The proxy fetches and rewrites each +repository's `index.yaml` so chart archives are downloaded through the proxy. +Chart archives are retained only when their SHA-256 digest matches the digest +listed in the index. Relative and absolute chart URLs are both supported. + +Named OCI registries preserve the existing unprefixed Docker Hub mirror. A +reference such as `oci://proxy.example.com/upstream/ghcr/owner/chart` is sent +to the registry configured as `ghcr` with `owner/chart` as its repository. +When the proxy uses plain HTTP (for example `localhost:8080`), pass +`--plain-http` to Helm OCI commands. + ## Authentication Configure authentication for private upstream registries. The same authentication-aware client is used for metadata and artifact downloads, and credentials can reference environment variables using `${VAR_NAME}` syntax. diff --git a/go.mod b/go.mod index 0c5861f..d95ee13 100644 --- a/go.mod +++ b/go.mod @@ -1,6 +1,8 @@ module github.com/git-pkgs/proxy -go 1.25.6 +go 1.26.0 + +toolchain go1.26.6 require ( github.com/BurntSushi/toml v1.6.0 @@ -8,9 +10,10 @@ require ( github.com/git-pkgs/archives v0.5.1 github.com/git-pkgs/cooldown v0.1.1 github.com/git-pkgs/enrichment v0.6.5 + github.com/git-pkgs/integrity v0.1.1 github.com/git-pkgs/magic v0.2.0 - github.com/git-pkgs/purl v0.1.16 - github.com/git-pkgs/registries v0.7.0 + github.com/git-pkgs/purl v0.1.17 + github.com/git-pkgs/registries v0.8.1 github.com/git-pkgs/spdx v0.3.1 github.com/git-pkgs/vers v0.3.1 github.com/git-pkgs/vulns v0.2.2 @@ -29,45 +32,48 @@ require ( ) require ( - 4d63.com/gocheckcompilerdirectives v1.3.0 // indirect + 4d63.com/gocheckcompilerdirectives v1.4.0 // indirect 4d63.com/gochecknoglobals v0.2.2 // indirect - cloud.google.com/go/auth v0.18.2 // indirect + charm.land/lipgloss/v2 v2.0.6 // indirect + cloud.google.com/go/auth v0.21.0 // indirect cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect cloud.google.com/go/compute/metadata v0.9.0 // indirect codeberg.org/chavacava/garif v0.2.0 // indirect codeberg.org/polyfloyd/go-errorlint v1.9.0 // indirect dev.gaijin.team/go/exhaustruct/v4 v4.0.0 // indirect - dev.gaijin.team/go/golib v0.6.0 // indirect + dev.gaijin.team/go/exhaustruct/v5 v5.0.3 // indirect + dev.gaijin.team/go/golib v0.8.1 // indirect github.com/4meepo/tagalign v1.4.3 // indirect - github.com/Abirdcfly/dupword v0.1.7 // indirect + github.com/Abirdcfly/dupword v0.1.8 // indirect github.com/AdminBenni/iota-mixing v1.0.0 // indirect - github.com/AlwxSin/noinlineerr v1.0.5 // indirect - github.com/Antonboom/errname v1.1.1 // indirect - github.com/Antonboom/nilnil v1.1.1 // indirect + github.com/AlwxSin/noinlineerr v1.0.6 // indirect + github.com/Antonboom/errname v1.1.2 // indirect + github.com/Antonboom/nilnil v1.1.2 // indirect github.com/Antonboom/testifylint v1.6.4 // indirect github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0 // indirect github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1 // indirect github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2 // indirect github.com/Azure/azure-sdk-for-go/sdk/storage/azblob v1.6.4 // indirect github.com/AzureAD/microsoft-authentication-library-for-go v1.7.0 // indirect + github.com/ClickHouse/clickhouse-go-linter v1.2.1 // indirect github.com/Djarvur/go-err113 v0.1.1 // indirect github.com/KyleBanks/depth v1.2.1 // indirect - github.com/Masterminds/semver/v3 v3.4.0 // indirect - github.com/MirrexOne/unqueryvet v1.5.3 // indirect + github.com/Masterminds/semver/v3 v3.5.0 // indirect + github.com/MirrexOne/unqueryvet v1.5.4 // indirect github.com/OpenPeeDeeP/depguard/v2 v2.2.1 // indirect github.com/PuerkitoBio/purell v1.1.1 // indirect github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 // indirect - github.com/alecthomas/chroma/v2 v2.23.1 // indirect + github.com/alecthomas/chroma/v2 v2.27.0 // indirect github.com/alecthomas/go-check-sumtype v0.3.1 // indirect github.com/alexkohler/nakedret/v2 v2.0.6 // indirect - github.com/alexkohler/prealloc v1.0.2 // indirect + github.com/alexkohler/prealloc v1.1.0 // indirect github.com/alfatraining/structtag v1.0.0 // indirect github.com/alingse/asasalint v0.0.11 // indirect github.com/alingse/nilnesserr v0.2.0 // indirect github.com/anchore/go-struct-converter v0.1.0 // indirect github.com/apapsch/go-jsonmerge/v2 v2.0.0 // indirect - github.com/ashanbrown/forbidigo/v2 v2.3.0 // indirect - github.com/ashanbrown/makezero/v2 v2.1.0 // indirect + github.com/ashanbrown/forbidigo/v2 v2.3.1 // indirect + github.com/ashanbrown/makezero/v2 v2.2.1 // indirect github.com/aws/aws-sdk-go-v2 v1.41.9 // indirect github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.11 // indirect github.com/aws/aws-sdk-go-v2/config v1.32.20 // indirect @@ -87,48 +93,49 @@ require ( github.com/aws/aws-sdk-go-v2/service/ssooidc v1.36.2 // indirect github.com/aws/aws-sdk-go-v2/service/sts v1.42.3 // indirect github.com/aws/smithy-go v1.26.0 // indirect - github.com/aymanbagabas/go-osc52/v2 v2.0.1 // indirect github.com/beorn7/perks v1.0.1 // indirect github.com/bkielbasa/cyclop v1.2.3 // indirect github.com/blizzy78/varnamelen v0.8.0 // indirect github.com/bombsimon/wsl/v4 v4.7.0 // indirect - github.com/bombsimon/wsl/v5 v5.6.0 // indirect + github.com/bombsimon/wsl/v5 v5.9.0 // indirect github.com/breml/bidichk v0.3.3 // indirect github.com/breml/errchkjson v0.4.1 // indirect - github.com/butuzov/ireturn v0.4.0 // indirect - github.com/butuzov/mirror v1.3.0 // indirect + github.com/butuzov/ireturn v0.4.1 // indirect + github.com/butuzov/mirror v1.3.3 // indirect github.com/catenacyber/perfsprint v0.10.1 // indirect github.com/ccojocar/zxcvbn-go v1.0.4 // indirect github.com/cenk/backoff v2.2.1+incompatible // indirect github.com/cespare/xxhash/v2 v2.3.0 // indirect github.com/charithe/durationcheck v0.0.11 // indirect - github.com/charmbracelet/colorprofile v0.2.3-0.20250311203215-f60798e515dc // indirect - github.com/charmbracelet/lipgloss v1.1.0 // indirect - github.com/charmbracelet/x/ansi v0.10.1 // indirect - github.com/charmbracelet/x/cellbuf v0.0.13-0.20250311204145-2c3ea96c31dd // indirect - github.com/charmbracelet/x/term v0.2.1 // indirect + github.com/charmbracelet/colorprofile v0.4.3 // indirect + github.com/charmbracelet/ultraviolet v0.0.0-20260811164956-006e29f97886 // indirect + github.com/charmbracelet/x/ansi v0.11.8 // indirect + github.com/charmbracelet/x/term v0.2.2 // indirect + github.com/charmbracelet/x/termios v0.1.1 // indirect + github.com/charmbracelet/x/windows v0.2.2 // indirect github.com/ckaznocha/intrange v0.3.1 // indirect + github.com/clipperhouse/displaywidth v0.11.0 // indirect + github.com/clipperhouse/uax29/v2 v2.7.0 // indirect github.com/cpuguy83/go-md2man/v2 v2.0.6 // indirect github.com/curioswitch/go-reassign v0.3.0 // indirect github.com/daixiang0/gci v0.13.7 // indirect github.com/dave/dst v0.27.3 // indirect - github.com/davecgh/go-spew v1.1.1 // indirect github.com/denis-tingaikin/go-header v0.5.0 // indirect - github.com/dlclark/regexp2 v1.11.5 // indirect + github.com/dlclark/regexp2/v2 v2.2.1 // indirect github.com/dustin/go-humanize v1.0.1 // indirect github.com/ecosyste-ms/ecosystems-go v0.4.0 // indirect github.com/ettle/strcase v0.2.0 // indirect github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a // indirect - github.com/fatih/color v1.18.0 // indirect + github.com/fatih/color v1.19.0 // indirect github.com/fatih/structtag v1.2.0 // indirect - github.com/firefart/nonamedreturns v1.0.6 // indirect + github.com/firefart/nonamedreturns v1.0.8 // indirect github.com/fsnotify/fsnotify v1.9.0 // indirect github.com/fzipp/gocyclo v0.6.0 // indirect - github.com/ghostiam/protogetter v0.3.20 // indirect + github.com/ghostiam/protogetter v0.3.21 // indirect github.com/git-pkgs/packageurl-go v0.3.1 // indirect github.com/git-pkgs/pom v0.1.5 // indirect github.com/github/go-spdx/v2 v2.7.0 // indirect - github.com/go-critic/go-critic v0.14.3 // indirect + github.com/go-critic/go-critic v0.14.4 // indirect github.com/go-logr/logr v1.4.3 // indirect github.com/go-logr/stdr v1.2.2 // indirect github.com/go-openapi/jsonpointer v0.19.5 // indirect @@ -149,83 +156,82 @@ require ( github.com/gofrs/flock v0.13.0 // indirect github.com/golang-jwt/jwt/v5 v5.3.1 // indirect github.com/golangci/asciicheck v0.5.0 // indirect - github.com/golangci/dupl v0.0.0-20250308024227-f665c8d69b32 // indirect + github.com/golangci/dupl v0.0.0-20260401084720-c99c5cf5c202 // indirect github.com/golangci/go-printf-func-name v0.1.1 // indirect - github.com/golangci/gofmt v0.0.0-20250106114630-d62b90e6713d // indirect - github.com/golangci/golangci-lint/v2 v2.10.1 // indirect + github.com/golangci/gofmt v0.0.0-20260820135601-e84e05053792 // indirect + github.com/golangci/golangci-lint/v2 v2.13.1 // indirect github.com/golangci/golines v0.15.0 // indirect github.com/golangci/misspell v0.8.0 // indirect github.com/golangci/plugin-module-register v0.1.2 // indirect github.com/golangci/revgrep v0.8.0 // indirect + github.com/golangci/rowserrcheck v0.0.0-20260419091836-c5f79b8a11ba // indirect github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e // indirect github.com/golangci/unconvert v0.0.0-20250410112200-a129a6e6413e // indirect github.com/google/go-cmp v0.7.0 // indirect github.com/google/s2a-go v0.1.9 // indirect github.com/google/uuid v1.6.0 // indirect github.com/google/wire v0.7.0 // indirect - github.com/googleapis/enterprise-certificate-proxy v0.3.14 // indirect - github.com/googleapis/gax-go/v2 v2.19.0 // indirect + github.com/googleapis/enterprise-certificate-proxy v0.3.18 // indirect + github.com/googleapis/gax-go/v2 v2.23.0 // indirect github.com/gordonklaus/ineffassign v0.2.0 // indirect github.com/gostaticanalysis/analysisutil v0.7.1 // indirect github.com/gostaticanalysis/comment v1.5.0 // indirect github.com/gostaticanalysis/forcetypeassert v0.2.0 // indirect github.com/gostaticanalysis/nilerr v0.1.2 // indirect github.com/hashicorp/go-immutable-radix/v2 v2.1.0 // indirect - github.com/hashicorp/go-version v1.8.0 // indirect + github.com/hashicorp/go-version v1.9.0 // indirect github.com/hashicorp/golang-lru/v2 v2.0.7 // indirect github.com/hashicorp/hcl v1.0.0 // indirect github.com/hexops/gotextdiff v1.0.3 // indirect github.com/inconshreveable/mousetrap v1.1.0 // indirect - github.com/jgautheron/goconst v1.8.2 // indirect - github.com/jingyugao/rowserrcheck v1.1.1 // indirect + github.com/jgautheron/goconst v1.11.0 // indirect github.com/jjti/go-spancheck v0.6.5 // indirect github.com/josharian/intern v1.0.0 // indirect github.com/julz/importas v0.2.0 // indirect github.com/karamaru-alpha/copyloopvar v1.2.2 // indirect - github.com/kisielk/errcheck v1.9.0 // indirect + github.com/kisielk/errcheck v1.20.0 // indirect github.com/kkHAIKE/contextcheck v1.1.6 // indirect github.com/kulti/thelper v0.7.1 // indirect github.com/kunwardeep/paralleltest v1.0.15 // indirect github.com/kylelemons/godebug v1.1.0 // indirect github.com/lasiar/canonicalheader v1.1.2 // indirect github.com/ldez/exptostd v0.4.5 // indirect - github.com/ldez/gomoddirectives v0.8.0 // indirect + github.com/ldez/gomoddirectives v0.9.0 // indirect github.com/ldez/grignotin v0.10.1 // indirect github.com/ldez/structtags v0.6.1 // indirect github.com/ldez/tagliatelle v0.7.2 // indirect github.com/ldez/usetesting v0.5.0 // indirect github.com/leonklingele/grouper v1.1.2 // indirect - github.com/lucasb-eyer/go-colorful v1.2.0 // indirect + github.com/lucasb-eyer/go-colorful v1.4.1 // indirect github.com/macabu/inamedparam v0.2.0 // indirect github.com/magiconair/properties v1.8.6 // indirect github.com/mailru/easyjson v0.7.7 // indirect github.com/manuelarte/embeddedstructfieldcheck v0.4.0 // indirect - github.com/manuelarte/funcorder v0.5.0 // indirect + github.com/manuelarte/funcorder v0.6.0 // indirect github.com/maratori/testableexamples v1.0.1 // indirect github.com/maratori/testpackage v1.1.2 // indirect github.com/matoous/godox v1.1.0 // indirect - github.com/mattn/go-colorable v0.1.14 // indirect + github.com/mattn/go-colorable v0.1.15 // indirect github.com/mattn/go-isatty v0.0.24 // indirect - github.com/mattn/go-runewidth v0.0.16 // indirect - github.com/mgechev/revive v1.14.0 // indirect + github.com/mattn/go-runewidth v0.0.24 // indirect + github.com/mgechev/revive v1.15.0 // indirect github.com/mitchellh/go-homedir v1.1.0 // indirect github.com/mitchellh/mapstructure v1.5.0 // indirect github.com/moricho/tparallel v0.3.2 // indirect - github.com/muesli/termenv v0.16.0 // indirect + github.com/muesli/cancelreader v0.2.2 // indirect github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect github.com/nakabonne/nestif v0.3.1 // indirect github.com/ncruces/go-strftime v1.0.0 // indirect github.com/nishanths/exhaustive v0.12.0 // indirect github.com/nishanths/predeclared v0.2.2 // indirect - github.com/nunnatsa/ginkgolinter v0.23.0 // indirect + github.com/nunnatsa/ginkgolinter v0.24.0 // indirect github.com/oapi-codegen/nullable v1.2.0 // indirect github.com/oapi-codegen/runtime v1.6.0 // indirect github.com/package-url/packageurl-go v0.1.6 // indirect github.com/pandatix/go-cvss v0.6.2 // indirect github.com/pelletier/go-toml v1.9.5 // indirect - github.com/pelletier/go-toml/v2 v2.2.4 // indirect + github.com/pelletier/go-toml/v2 v2.4.3 // indirect github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect - github.com/pmezard/go-difflib v1.0.0 // indirect github.com/prometheus/common v0.70.1 // indirect github.com/prometheus/procfs v0.21.1 // indirect github.com/quasilyte/go-ruleguard v0.4.5 // indirect @@ -233,24 +239,25 @@ require ( github.com/quasilyte/gogrep v0.5.0 // indirect github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727 // indirect github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567 // indirect - github.com/raeperd/recvcheck v0.2.0 // indirect + github.com/raeperd/recvcheck v0.3.0 // indirect github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect github.com/rivo/uniseg v0.4.7 // indirect - github.com/rogpeppe/go-internal v1.14.1 // indirect + github.com/rogpeppe/go-internal v1.16.0 // indirect github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529 // indirect github.com/rubyist/circuitbreaker v2.2.1+incompatible // indirect github.com/russross/blackfriday/v2 v2.1.0 // indirect github.com/ryancurrah/gomodguard v1.4.1 // indirect - github.com/ryanrolds/sqlclosecheck v0.5.1 // indirect + github.com/ryancurrah/gomodguard/v2 v2.1.3 // indirect + github.com/ryanrolds/sqlclosecheck v0.6.0 // indirect github.com/sanposhiho/wastedassign/v2 v2.1.0 // indirect - github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 // indirect + github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 // indirect github.com/sashamelentyev/interfacebloat v1.1.0 // indirect github.com/sashamelentyev/usestdlibvars v1.29.0 // indirect - github.com/securego/gosec/v2 v2.23.0 // indirect - github.com/sirupsen/logrus v1.9.4 // indirect + github.com/securego/gosec/v2 v2.28.0 // indirect + github.com/sirupsen/logrus v1.10.1 // indirect github.com/sivchari/containedctx v1.0.3 // indirect - github.com/sonatard/noctx v0.4.0 // indirect - github.com/sourcegraph/go-diff v0.7.0 // indirect + github.com/sonatard/noctx v0.5.1 // indirect + github.com/sourcegraph/go-diff v0.8.0 // indirect github.com/spf13/afero v1.15.0 // indirect github.com/spf13/cast v1.5.0 // indirect github.com/spf13/cobra v1.10.2 // indirect @@ -259,11 +266,11 @@ require ( github.com/spf13/viper v1.12.0 // indirect github.com/ssgreg/nlreturn/v2 v2.2.1 // indirect github.com/stbenjam/no-sprintf-host-port v0.3.1 // indirect - github.com/stretchr/objx v0.5.2 // indirect - github.com/stretchr/testify v1.11.1 // indirect + github.com/stretchr/objx v0.5.3 // indirect + github.com/stretchr/testify v1.12.1 // indirect github.com/subosito/gotenv v1.4.1 // indirect - github.com/tetafro/godot v1.5.4 // indirect - github.com/timakin/bodyclose v0.0.0-20241222091800-1db5c5ca4d67 // indirect + github.com/tetafro/godot v1.5.6 // indirect + github.com/timakin/bodyclose v0.0.0-20260129054331-73d1f95b84b4 // indirect github.com/timonwong/loggercheck v0.11.0 // indirect github.com/tomarrell/wrapcheck/v2 v2.12.0 // indirect github.com/tommy-muehle/go-mnd/v2 v2.5.1 // indirect @@ -271,8 +278,8 @@ require ( github.com/ultraware/funlen v0.2.0 // indirect github.com/ultraware/whitespace v0.2.0 // indirect github.com/urfave/cli/v2 v2.3.0 // indirect - github.com/uudashr/gocognit v1.2.0 // indirect - github.com/uudashr/iface v1.4.1 // indirect + github.com/uudashr/gocognit v1.2.1 // indirect + github.com/uudashr/iface v1.5.0 // indirect github.com/xen0n/gosmopolitan v1.3.0 // indirect github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e // indirect github.com/yagipy/maintidx v1.0.0 // indirect @@ -280,9 +287,9 @@ require ( github.com/ykadowak/zerologlint v0.1.5 // indirect gitlab.com/bosi/decorder v0.4.2 // indirect go-simpler.org/musttag v0.14.0 // indirect - go-simpler.org/sloglint v0.11.1 // indirect + go-simpler.org/sloglint v0.12.0 // indirect go.augendre.info/arangolint v0.4.0 // indirect - go.augendre.info/fatcontext v0.9.0 // indirect + go.augendre.info/fatcontext v0.10.0 // indirect go.opentelemetry.io/auto/sdk v1.2.1 // indirect go.opentelemetry.io/otel v1.44.0 // indirect go.opentelemetry.io/otel/metric v1.44.0 // indirect @@ -292,28 +299,28 @@ require ( go.uber.org/multierr v1.11.0 // indirect go.uber.org/zap v1.27.1 // indirect go.yaml.in/yaml/v2 v2.4.4 // indirect - go.yaml.in/yaml/v3 v3.0.4 // indirect - golang.org/x/crypto v0.54.0 // indirect + go.yaml.in/yaml/v3 v3.0.5 // indirect + golang.org/x/crypto v0.55.0 // indirect golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa // indirect - golang.org/x/exp/typeparams v0.0.0-20260209203927-2842357ff358 // indirect - golang.org/x/mod v0.37.0 // indirect - golang.org/x/net v0.57.0 // indirect + golang.org/x/exp/typeparams v0.0.0-20260811152304-ee035b5b010f // indirect + golang.org/x/mod v0.40.0 // indirect + golang.org/x/net v0.58.0 // indirect golang.org/x/oauth2 v0.36.0 // indirect golang.org/x/sys v0.47.0 // indirect - golang.org/x/text v0.40.0 // indirect - golang.org/x/tools v0.47.0 // indirect + golang.org/x/text v0.41.0 // indirect + golang.org/x/tools v0.49.0 // indirect golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect - google.golang.org/api v0.272.0 // indirect - google.golang.org/genproto/googleapis/rpc v0.0.0-20260414002931-afd174a4e478 // indirect + google.golang.org/api v0.288.0 // indirect + google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800 // indirect google.golang.org/grpc v1.82.1 // indirect gopkg.in/ini.v1 v1.67.0 // indirect gopkg.in/yaml.v2 v2.4.0 // indirect - honnef.co/go/tools v0.7.0 // indirect + honnef.co/go/tools v0.8.0 // indirect modernc.org/libc v1.74.4 // indirect modernc.org/mathutil v1.7.1 // indirect modernc.org/memory v1.11.0 // indirect - mvdan.cc/gofumpt v0.9.2 // indirect - mvdan.cc/unparam v0.0.0-20251027182757-5beb8c8f8f15 // indirect + mvdan.cc/gofumpt v0.11.0 // indirect + mvdan.cc/unparam v0.0.0-20260818115549-3f964bcb5673 // indirect sigs.k8s.io/yaml v1.6.0 // indirect ) diff --git a/go.sum b/go.sum index 1ff787f..e2fedc7 100644 --- a/go.sum +++ b/go.sum @@ -1,13 +1,15 @@ -4d63.com/gocheckcompilerdirectives v1.3.0 h1:Ew5y5CtcAAQeTVKUVFrE7EwHMrTO6BggtEj8BZSjZ3A= -4d63.com/gocheckcompilerdirectives v1.3.0/go.mod h1:ofsJ4zx2QAuIP/NO/NAh1ig6R1Fb18/GI7RVMwz7kAY= +4d63.com/gocheckcompilerdirectives v1.4.0 h1:ZLq62rbGWVmQhiZ8kuNVIT/M09xCSTdJz9K3xOdT/CY= +4d63.com/gocheckcompilerdirectives v1.4.0/go.mod h1:9ZOAiMOjqC/nRwci2fcUXVHUNLG/cH6r6rhUh+jTFtQ= 4d63.com/gochecknoglobals v0.2.2 h1:H1vdnwnMaZdQW/N+NrkT1SZMTBmcwHe9Vq8lJcYYTtU= 4d63.com/gochecknoglobals v0.2.2/go.mod h1:lLxwTQjL5eIesRbvnzIP3jZtG140FnTdz+AlMa+ogt0= cel.dev/expr v0.25.1 h1:1KrZg61W6TWSxuNZ37Xy49ps13NUovb66QLprthtwi4= cel.dev/expr v0.25.1/go.mod h1:hrXvqGP6G6gyx8UAHSHJ5RGk//1Oj5nXQ2NI02Nrsg4= +charm.land/lipgloss/v2 v2.0.6 h1:EaGKeuA8FvF+v2BT5VmZd2LoYLaMZJXA5n34th8nCIQ= +charm.land/lipgloss/v2 v2.0.6/go.mod h1:ipDDJNSGa1hlwDtSfW1s2/xR8Vdhbut4PXh2zEKZd0Q= cloud.google.com/go v0.123.0 h1:2NAUJwPR47q+E35uaJeYoNhuNEM9kM8SjgRgdeOJUSE= cloud.google.com/go v0.123.0/go.mod h1:xBoMV08QcqUGuPW65Qfm1o9Y4zKZBpGS+7bImXLTAZU= -cloud.google.com/go/auth v0.18.2 h1:+Nbt5Ev0xEqxlNjd6c+yYUeosQ5TtEUaNcN/3FozlaM= -cloud.google.com/go/auth v0.18.2/go.mod h1:xD+oY7gcahcu7G2SG2DsBerfFxgPAJz17zz2joOFF3M= +cloud.google.com/go/auth v0.21.0 h1:g/QwYfYb2Ai6HH8oomAOyBaIHLbscZ4+T/F/f5JZHkE= +cloud.google.com/go/auth v0.21.0/go.mod h1:M9o2Oz+YI2jAfxewJgb1vyI3vceHF+eohmxyzmrl+9s= cloud.google.com/go/auth/oauth2adapt v0.2.8 h1:keo8NaayQZ6wimpNSmW5OPc283g65QNIiLpZnkHRbnc= cloud.google.com/go/auth/oauth2adapt v0.2.8/go.mod h1:XQ9y31RkqZCcwJWNSx2Xvric3RrU88hAYYbjDWYDL+c= cloud.google.com/go/compute/metadata v0.9.0 h1:pDUj4QMoPejqq20dK0Pg2N4yG9zIkYGdBtwLoEkH9Zs= @@ -24,23 +26,25 @@ codeberg.org/polyfloyd/go-errorlint v1.9.0 h1:VkdEEmA1VBpH6ecQoMR4LdphVI3fA4RrCh codeberg.org/polyfloyd/go-errorlint v1.9.0/go.mod h1:GPRRu2LzVijNn4YkrZYJfatQIdS+TrcK8rL5Xs24qw8= dev.gaijin.team/go/exhaustruct/v4 v4.0.0 h1:873r7aNneqoBB3IaFIzhvt2RFYTuHgmMjoKfwODoI1Y= dev.gaijin.team/go/exhaustruct/v4 v4.0.0/go.mod h1:aZ/k2o4Y05aMJtiux15x8iXaumE88YdiB0Ai4fXOzPI= -dev.gaijin.team/go/golib v0.6.0 h1:v6nnznFTs4bppib/NyU1PQxobwDHwCXXl15P7DV5Zgo= -dev.gaijin.team/go/golib v0.6.0/go.mod h1:uY1mShx8Z/aNHWDyAkZTkX+uCi5PdX7KsG1eDQa2AVE= +dev.gaijin.team/go/exhaustruct/v5 v5.0.3 h1:yOeA7DNjlT8y4yfmN6nWWYYggA13N523YAj9/TXbuTM= +dev.gaijin.team/go/exhaustruct/v5 v5.0.3/go.mod h1:KwtBsX8nHHH1YxhxkpiBq6bfsmw5WnazWpNvJPHgY9Y= +dev.gaijin.team/go/golib v0.8.1 h1:JYju4x9BSo+QD/AYeHULVDcvEhiFg8wOi6pT0IaZF5E= +dev.gaijin.team/go/golib v0.8.1/go.mod h1:c5fu7t1RSGMxSQgcUYO1sODbzsYnOCXJLmHeNG1Eb+0= filippo.io/edwards25519 v1.1.0/go.mod h1:BxyFTGdWcka3PhytdK4V28tE5sGfRvvvRV7EaN4VDT4= filippo.io/edwards25519 v1.2.0 h1:crnVqOiS4jqYleHd9vaKZ+HKtHfllngJIiOpNpoJsjo= filippo.io/edwards25519 v1.2.0/go.mod h1:xzAOLCNug/yB62zG1bQ8uziwrIqIuxhctzJT18Q77mc= github.com/4meepo/tagalign v1.4.3 h1:Bnu7jGWwbfpAie2vyl63Zup5KuRv21olsPIha53BJr8= github.com/4meepo/tagalign v1.4.3/go.mod h1:00WwRjiuSbrRJnSVeGWPLp2epS5Q/l4UEy0apLLS37c= -github.com/Abirdcfly/dupword v0.1.7 h1:2j8sInznrje4I0CMisSL6ipEBkeJUJAmK1/lfoNGWrQ= -github.com/Abirdcfly/dupword v0.1.7/go.mod h1:K0DkBeOebJ4VyOICFdppB23Q0YMOgVafM0zYW0n9lF4= +github.com/Abirdcfly/dupword v0.1.8 h1:SrhcUuGsROBuChFxHALRYzyyPODWn9zwghmzPvD9Cd8= +github.com/Abirdcfly/dupword v0.1.8/go.mod h1:XZrhVnI7YGpsTiWZANSQaBJ4QpL/Tq5vIEdKJJAs9WI= github.com/AdminBenni/iota-mixing v1.0.0 h1:Os6lpjG2dp/AE5fYBPAA1zfa2qMdCAWwPMCgpwKq7wo= github.com/AdminBenni/iota-mixing v1.0.0/go.mod h1:i4+tpAaB+qMVIV9OK3m4/DAynOd5bQFaOu+2AhtBCNY= -github.com/AlwxSin/noinlineerr v1.0.5 h1:RUjt63wk1AYWTXtVXbSqemlbVTb23JOSRiNsshj7TbY= -github.com/AlwxSin/noinlineerr v1.0.5/go.mod h1:+QgkkoYrMH7RHvcdxdlI7vYYEdgeoFOVjU9sUhw/rQc= -github.com/Antonboom/errname v1.1.1 h1:bllB7mlIbTVzO9jmSWVWLjxTEbGBVQ1Ff/ClQgtPw9Q= -github.com/Antonboom/errname v1.1.1/go.mod h1:gjhe24xoxXp0ScLtHzjiXp0Exi1RFLKJb0bVBtWKCWQ= -github.com/Antonboom/nilnil v1.1.1 h1:9Mdr6BYd8WHCDngQnNVV0b554xyisFioEKi30sksufQ= -github.com/Antonboom/nilnil v1.1.1/go.mod h1:yCyAmSw3doopbOWhJlVci+HuyNRuHJKIv6V2oYQa8II= +github.com/AlwxSin/noinlineerr v1.0.6 h1:KAvuxunTe9QxvqrFB7nZTdb/7Wzas4AvifslTnG0Ld8= +github.com/AlwxSin/noinlineerr v1.0.6/go.mod h1:+QgkkoYrMH7RHvcdxdlI7vYYEdgeoFOVjU9sUhw/rQc= +github.com/Antonboom/errname v1.1.2 h1:dxwONZJua3VB8Xh/VaCjqAcqF645sWWv7xj26zy7tdQ= +github.com/Antonboom/errname v1.1.2/go.mod h1:YeZIpgLMxT+SNkruGgYkLhzq/9vs3fsolTZegKaKDZI= +github.com/Antonboom/nilnil v1.1.2 h1:aNlFuJhaEseXe4fHO3xbjXlSeEiQVYa2lEkWD2s2hAY= +github.com/Antonboom/nilnil v1.1.2/go.mod h1:0ynwvphOLmAuMwTNDyBnDZmSwZoDpcFXmUHmzoHH2WA= github.com/Antonboom/testifylint v1.6.4 h1:gs9fUEy+egzxkEbq9P4cpcMB6/G0DYdMeiFS87UiqmQ= github.com/Antonboom/testifylint v1.6.4/go.mod h1:YO33FROXX2OoUfwjz8g+gUxQXio5i9qpVy7nXGbxDD4= github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0 h1:fou+2+WFTib47nS+nz/ozhEBnvU96bKHy6LjRsY4E28= @@ -62,6 +66,8 @@ github.com/AzureAD/microsoft-authentication-library-for-go v1.7.0/go.mod h1:HKpQ github.com/BurntSushi/toml v0.3.1/go.mod h1:xHWCNGjB5oqiDr8zfno3MHue2Ht5sIBksp03qcyfWMU= github.com/BurntSushi/toml v1.6.0 h1:dRaEfpa2VI55EwlIW72hMRHdWouJeRF7TPYhI+AUQjk= github.com/BurntSushi/toml v1.6.0/go.mod h1:ukJfTF/6rtPPRCnwkur4qwRxa8vTRFBF0uk2lLoLwho= +github.com/ClickHouse/clickhouse-go-linter v1.2.1 h1:zGEKIyd5YL08ieWG/LOUmlau2DxbxPVOfAeo+4Jz3ck= +github.com/ClickHouse/clickhouse-go-linter v1.2.1/go.mod h1:pLorS7ffPTfuUV9M0SJgfHA/h/WQPQUk2FWG9x74cQ4= github.com/CycloneDX/cyclonedx-go v0.11.0 h1:GokP8FiRC+foiuwWhSSLpSD5H4hSWtGnR3wo7apkBFI= github.com/CycloneDX/cyclonedx-go v0.11.0/go.mod h1:vUvbCXQsEm48OI6oOlanxstwNByXjCZ2wuleUlwGEO8= github.com/Djarvur/go-err113 v0.1.1 h1:eHfopDqXRwAi+YmCUas75ZE0+hoBHJ2GQNLYRSxao4g= @@ -74,10 +80,10 @@ github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapp github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0/go.mod h1:Mf6O40IAyB9zR/1J8nGDDPirZQQPbYJni8Yisy7NTMc= github.com/KyleBanks/depth v1.2.1 h1:5h8fQADFrWtarTdtDudMmGsC7GPbOAu6RVB3ffsVFHc= github.com/KyleBanks/depth v1.2.1/go.mod h1:jzSb9d0L43HxTQfT+oSA1EEp2q+ne2uh6XgeJcm8brE= -github.com/Masterminds/semver/v3 v3.4.0 h1:Zog+i5UMtVoCU8oKka5P7i9q9HgrJeGzI9SA1Xbatp0= -github.com/Masterminds/semver/v3 v3.4.0/go.mod h1:4V+yj/TJE1HU9XfppCwVMZq3I84lprf4nC11bSS5beM= -github.com/MirrexOne/unqueryvet v1.5.3 h1:LpT3rsH+IY3cQddWF9bg4C7jsbASdGnrOSofY8IPEiw= -github.com/MirrexOne/unqueryvet v1.5.3/go.mod h1:fs9Zq6eh1LRIhsDIsxf9PONVUjYdFHdtkHIgZdJnyPU= +github.com/Masterminds/semver/v3 v3.5.0 h1:kQceYJfbupGfZOKZQg0kou0DgAKhzDg2NZPAwZ/2OOE= +github.com/Masterminds/semver/v3 v3.5.0/go.mod h1:4V+yj/TJE1HU9XfppCwVMZq3I84lprf4nC11bSS5beM= +github.com/MirrexOne/unqueryvet v1.5.4 h1:38QOxShO7JmMWT+eCdDMbcUgGCOeJphVkzzRgyLJgsQ= +github.com/MirrexOne/unqueryvet v1.5.4/go.mod h1:fs9Zq6eh1LRIhsDIsxf9PONVUjYdFHdtkHIgZdJnyPU= github.com/OpenPeeDeeP/depguard/v2 v2.2.1 h1:vckeWVESWp6Qog7UZSARNqfu/cZqvki8zsuj3piCMx4= github.com/OpenPeeDeeP/depguard/v2 v2.2.1/go.mod h1:q4DKzC4UcVaAvcfd41CZh0PWpGgzrVxUYBlgKNGquUo= github.com/PuerkitoBio/purell v1.1.1 h1:WEQqlqaGbrPkxLJWfBwQmfEAE1Z7ONdDLqrN38tNFfI= @@ -87,16 +93,16 @@ github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578/go.mod h1:uGdko github.com/RaveNoX/go-jsoncommentstrip v1.0.0/go.mod h1:78ihd09MekBnJnxpICcwzCMzGrKSKYe4AqU6PDYYpjk= github.com/alecthomas/assert/v2 v2.11.0 h1:2Q9r3ki8+JYXvGsDyBXwH3LcJ+WK5D0gc5E8vS6K3D0= github.com/alecthomas/assert/v2 v2.11.0/go.mod h1:Bze95FyfUr7x34QZrjL+XP+0qgp/zg8yS+TtBj1WA3k= -github.com/alecthomas/chroma/v2 v2.23.1 h1:nv2AVZdTyClGbVQkIzlDm/rnhk1E9bU9nXwmZ/Vk/iY= -github.com/alecthomas/chroma/v2 v2.23.1/go.mod h1:NqVhfBR0lte5Ouh3DcthuUCTUpDC9cxBOfyMbMQPs3o= +github.com/alecthomas/chroma/v2 v2.27.0 h1:FodwmyOBgJULFYmDqibcp9pvfDLWdtPRh9v/r5BXYZs= +github.com/alecthomas/chroma/v2 v2.27.0/go.mod h1:NjJ3ciIgrqBNeIkWZ4e46nseoLDslxU1LmfCoL+wcY8= github.com/alecthomas/go-check-sumtype v0.3.1 h1:u9aUvbGINJxLVXiFvHUlPEaD7VDULsrxJb4Aq31NLkU= github.com/alecthomas/go-check-sumtype v0.3.1/go.mod h1:A8TSiN3UPRw3laIgWEUOHHLPa6/r9MtoigdlP5h3K/E= github.com/alecthomas/repr v0.5.2 h1:SU73FTI9D1P5UNtvseffFSGmdNci/O6RsqzeXJtP0Qs= github.com/alecthomas/repr v0.5.2/go.mod h1:Fr0507jx4eOXV7AlPV6AVZLYrLIuIeSOWtW57eE/O/4= github.com/alexkohler/nakedret/v2 v2.0.6 h1:ME3Qef1/KIKr3kWX3nti3hhgNxw6aqN5pZmQiFSsuzQ= github.com/alexkohler/nakedret/v2 v2.0.6/go.mod h1:l3RKju/IzOMQHmsEvXwkqMDzHHvurNQfAgE1eVmT40Q= -github.com/alexkohler/prealloc v1.0.2 h1:MPo8cIkGkZytq7WNH9UHv3DIX1mPz1RatPXnZb0zHWQ= -github.com/alexkohler/prealloc v1.0.2/go.mod h1:fT39Jge3bQrfA7nPMDngUfvUbQGQeJyGQnR+913SCig= +github.com/alexkohler/prealloc v1.1.0 h1:cKGRBqlXw5iyQGLYhrXrDlcHxugXpTq4tQ5c91wkf8M= +github.com/alexkohler/prealloc v1.1.0/go.mod h1:fT39Jge3bQrfA7nPMDngUfvUbQGQeJyGQnR+913SCig= github.com/alfatraining/structtag v1.0.0 h1:2qmcUqNcCoyVJ0up879K614L9PazjBSFruTB0GOFjCc= github.com/alfatraining/structtag v1.0.0/go.mod h1:p3Xi5SwzTi+Ryj64DqjLWz7XurHxbGsq6y3ubePJPus= github.com/alingse/asasalint v0.0.11 h1:SFwnQXJ49Kx/1GghOFz1XGqHYKp21Kq1nHad/0WQRnw= @@ -107,10 +113,10 @@ github.com/anchore/go-struct-converter v0.1.0 h1:2rDRssAl6mgKBSLNiVCMADgZRhoqtw9 github.com/anchore/go-struct-converter v0.1.0/go.mod h1:rYqSE9HbjzpHTI74vwPvae4ZVYZd1lue2ta6xHPdblA= github.com/apapsch/go-jsonmerge/v2 v2.0.0 h1:axGnT1gRIfimI7gJifB699GoE/oq+F2MU7Dml6nw9rQ= github.com/apapsch/go-jsonmerge/v2 v2.0.0/go.mod h1:lvDnEdqiQrp0O42VQGgmlKpxL1AP2+08jFMw88y4klk= -github.com/ashanbrown/forbidigo/v2 v2.3.0 h1:OZZDOchCgsX5gvToVtEBoV2UWbFfI6RKQTir2UZzSxo= -github.com/ashanbrown/forbidigo/v2 v2.3.0/go.mod h1:5p6VmsG5/1xx3E785W9fouMxIOkvY2rRV9nMdWadd6c= -github.com/ashanbrown/makezero/v2 v2.1.0 h1:snuKYMbqosNokUKm+R6/+vOPs8yVAi46La7Ck6QYSaE= -github.com/ashanbrown/makezero/v2 v2.1.0/go.mod h1:aEGT/9q3S8DHeE57C88z2a6xydvgx8J5hgXIGWgo0MY= +github.com/ashanbrown/forbidigo/v2 v2.3.1 h1:KAZijvQ7zeIBKbhikT4jCm0TLYXC4u78bTiLh/8JROI= +github.com/ashanbrown/forbidigo/v2 v2.3.1/go.mod h1:2QDkLTzU6TV937eFROamXrW92M3paehdae4HCDCOZCM= +github.com/ashanbrown/makezero/v2 v2.2.1 h1:A7uU8dgB1PA9aelTxHMfHIQ8Qev8AB3JLxJUBUsejqM= +github.com/ashanbrown/makezero/v2 v2.2.1/go.mod h1:aEGT/9q3S8DHeE57C88z2a6xydvgx8J5hgXIGWgo0MY= github.com/aws/aws-sdk-go-v2 v1.41.9 h1:/rYeyO2+HrMztAmxAq9++XJtFMqSIpSsNA0yDGALYq4= github.com/aws/aws-sdk-go-v2 v1.41.9/go.mod h1:+HsoOEX80qAVUitj1A2DhCNTjmb3edVyuDypb6LNEeo= github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.11 h1:h5+3VT69KUBK24grGuuA5saDJTj2IIjLb9au668Fo5I= @@ -149,8 +155,6 @@ github.com/aws/aws-sdk-go-v2/service/sts v1.42.3 h1:ErklX/7uhSbkAAeyQD/Y1OoQ9hO3 github.com/aws/aws-sdk-go-v2/service/sts v1.42.3/go.mod h1:ULe4HCzfKPiR6R3HEurE3b1upEkuk8AkMrOKtaOxKO8= github.com/aws/smithy-go v1.26.0 h1:9ouqbi+NyKP7fV3Te7UElCwdAb6Y8uk7LGwPE5tVe/s= github.com/aws/smithy-go v1.26.0/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc= -github.com/aymanbagabas/go-osc52/v2 v2.0.1 h1:HwpRHbFMcZLEVr42D4p7XBqjyuxQH5SMiErDT4WkJ2k= -github.com/aymanbagabas/go-osc52/v2 v2.0.1/go.mod h1:uYgXzlJ7ZpABp8OJ+exZzJJhRNQ2ASbcXHWsFqH8hp8= github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM= github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6rlkpw= github.com/bkielbasa/cyclop v1.2.3 h1:faIVMIGDIANuGPWH031CZJTi2ymOQBULs9H21HSMa5w= @@ -160,18 +164,18 @@ github.com/blizzy78/varnamelen v0.8.0/go.mod h1:V9TzQZ4fLJ1DSrjVDfl89H7aMnTvKkAp github.com/bmatcuk/doublestar v1.1.1/go.mod h1:UD6OnuiIn0yFxxA2le/rnRU1G4RaI4UvFv1sNto9p6w= github.com/bombsimon/wsl/v4 v4.7.0 h1:1Ilm9JBPRczjyUs6hvOPKvd7VL1Q++PL8M0SXBDf+jQ= github.com/bombsimon/wsl/v4 v4.7.0/go.mod h1:uV/+6BkffuzSAVYD+yGyld1AChO7/EuLrCF/8xTiapg= -github.com/bombsimon/wsl/v5 v5.6.0 h1:4z+/sBqC5vUmSp1O0mS+czxwH9+LKXtCWtHH9rZGQL8= -github.com/bombsimon/wsl/v5 v5.6.0/go.mod h1:Uqt2EfrMj2NV8UGoN1f1Y3m0NpUVCsUdrNCdet+8LvU= +github.com/bombsimon/wsl/v5 v5.9.0 h1:WCrgZ7RQnZO5oEwbVTlYgBdU3wL294kR1BSWV8vTfsU= +github.com/bombsimon/wsl/v5 v5.9.0/go.mod h1:kjo4HiAV5FDkHC8/uzJq9mBffEEd6WT/nvN7DoMovDM= github.com/bradleyjkemp/cupaloy/v2 v2.8.0 h1:any4BmKE+jGIaMpnU8YgH/I2LPiLBufr6oMMlVBbn9M= github.com/bradleyjkemp/cupaloy/v2 v2.8.0/go.mod h1:bm7JXdkRd4BHJk9HpwqAI8BoAY1lps46Enkdqw6aRX0= github.com/breml/bidichk v0.3.3 h1:WSM67ztRusf1sMoqH6/c4OBCUlRVTKq+CbSeo0R17sE= github.com/breml/bidichk v0.3.3/go.mod h1:ISbsut8OnjB367j5NseXEGGgO/th206dVa427kR8YTE= github.com/breml/errchkjson v0.4.1 h1:keFSS8D7A2T0haP9kzZTi7o26r7kE3vymjZNeNDRDwg= github.com/breml/errchkjson v0.4.1/go.mod h1:a23OvR6Qvcl7DG/Z4o0el6BRAjKnaReoPQFciAl9U3s= -github.com/butuzov/ireturn v0.4.0 h1:+s76bF/PfeKEdbG8b54aCocxXmi0wvYdOVsWxVO7n8E= -github.com/butuzov/ireturn v0.4.0/go.mod h1:ghI0FrCmap8pDWZwfPisFD1vEc56VKH4NpQUxDHta70= -github.com/butuzov/mirror v1.3.0 h1:HdWCXzmwlQHdVhwvsfBb2Au0r3HyINry3bDWLYXiKoc= -github.com/butuzov/mirror v1.3.0/go.mod h1:AEij0Z8YMALaq4yQj9CPPVYOyJQyiexpQEQgihajRfI= +github.com/butuzov/ireturn v0.4.1 h1:vWb3NO4t77iku/sjCQ/2pHTQeOmxEhjIriJqRLg1Y+I= +github.com/butuzov/ireturn v0.4.1/go.mod h1:q+DXKzTDV5guNuXLnIab9fKXizTn2miZHLhxH7V/GB4= +github.com/butuzov/mirror v1.3.3 h1:v0RsWBhfFc1RQqE/f3sHpSttKDtodFn0gFmtYyD4/hA= +github.com/butuzov/mirror v1.3.3/go.mod h1:h9BzzwYnTiHO0GzgvaTqIg7VSsOUhdIv51cHFFBmX1w= github.com/catenacyber/perfsprint v0.10.1 h1:u7Riei30bk46XsG8nknMhKLXG9BcXz3+3tl/WpKm0PQ= github.com/catenacyber/perfsprint v0.10.1/go.mod h1:DJTGsi/Zufpuus6XPGJyKOTMELe347o6akPvWG9Zcsc= github.com/ccojocar/zxcvbn-go v1.0.4 h1:FWnCIRMXPj43ukfX000kvBZvV6raSxakYr1nzyNrUcc= @@ -182,18 +186,24 @@ github.com/cespare/xxhash/v2 v2.3.0 h1:UL815xU9SqsFlibzuggzjXhog7bL6oX9BbNZnL2UF github.com/cespare/xxhash/v2 v2.3.0/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs= github.com/charithe/durationcheck v0.0.11 h1:g1/EX1eIiKS57NTWsYtHDZ/APfeXKhye1DidBcABctk= github.com/charithe/durationcheck v0.0.11/go.mod h1:x5iZaixRNl8ctbM+3B2RrPG5t856TxRyVQEnbIEM2X4= -github.com/charmbracelet/colorprofile v0.2.3-0.20250311203215-f60798e515dc h1:4pZI35227imm7yK2bGPcfpFEmuY1gc2YSTShr4iJBfs= -github.com/charmbracelet/colorprofile v0.2.3-0.20250311203215-f60798e515dc/go.mod h1:X4/0JoqgTIPSFcRA/P6INZzIuyqdFY5rm8tb41s9okk= -github.com/charmbracelet/lipgloss v1.1.0 h1:vYXsiLHVkK7fp74RkV7b2kq9+zDLoEU4MZoFqR/noCY= -github.com/charmbracelet/lipgloss v1.1.0/go.mod h1:/6Q8FR2o+kj8rz4Dq0zQc3vYf7X+B0binUUBwA0aL30= -github.com/charmbracelet/x/ansi v0.10.1 h1:rL3Koar5XvX0pHGfovN03f5cxLbCF2YvLeyz7D2jVDQ= -github.com/charmbracelet/x/ansi v0.10.1/go.mod h1:3RQDQ6lDnROptfpWuUVIUG64bD2g2BgntdxH0Ya5TeE= -github.com/charmbracelet/x/cellbuf v0.0.13-0.20250311204145-2c3ea96c31dd h1:vy0GVL4jeHEwG5YOXDmi86oYw2yuYUGqz6a8sLwg0X8= -github.com/charmbracelet/x/cellbuf v0.0.13-0.20250311204145-2c3ea96c31dd/go.mod h1:xe0nKWGd3eJgtqZRaN9RjMtK7xUYchjzPr7q6kcvCCs= -github.com/charmbracelet/x/term v0.2.1 h1:AQeHeLZ1OqSXhrAWpYUtZyX1T3zVxfpZuEQMIQaGIAQ= -github.com/charmbracelet/x/term v0.2.1/go.mod h1:oQ4enTYFV7QN4m0i9mzHrViD7TQKvNEEkHUMCmsxdUg= +github.com/charmbracelet/colorprofile v0.4.3 h1:QPa1IWkYI+AOB+fE+mg/5/4HRMZcaXex9t5KX76i20Q= +github.com/charmbracelet/colorprofile v0.4.3/go.mod h1:/zT4BhpD5aGFpqQQqw7a+VtHCzu+zrQtt1zhMt9mR4Q= +github.com/charmbracelet/ultraviolet v0.0.0-20260811164956-006e29f97886 h1:rdnVWKgJpTVXKuKuJyxDJ+NFJdUaUqGvyGy61OcvlbA= +github.com/charmbracelet/ultraviolet v0.0.0-20260811164956-006e29f97886/go.mod h1:nAw0d9PhFp1qdzi2xhQU5YOu5sVpDIHWlaW2Uz/bCro= +github.com/charmbracelet/x/ansi v0.11.8 h1:JMFwp0CgDC2+jcOB162HH5k7I3FVbgFSMMYg7dSPBQQ= +github.com/charmbracelet/x/ansi v0.11.8/go.mod h1:ZNN+3mXny/516oTQPLMPIBeSINvNJJQ8uQXDgbeJxY0= +github.com/charmbracelet/x/term v0.2.2 h1:xVRT/S2ZcKdhhOuSP4t5cLi5o+JxklsoEObBSgfgZRk= +github.com/charmbracelet/x/term v0.2.2/go.mod h1:kF8CY5RddLWrsgVwpw4kAa6TESp6EB5y3uxGLeCqzAI= +github.com/charmbracelet/x/termios v0.1.1 h1:o3Q2bT8eqzGnGPOYheoYS8eEleT5ZVNYNy8JawjaNZY= +github.com/charmbracelet/x/termios v0.1.1/go.mod h1:rB7fnv1TgOPOyyKRJ9o+AsTU/vK5WHJ2ivHeut/Pcwo= +github.com/charmbracelet/x/windows v0.2.2 h1:IofanmuvaxnKHuV04sC0eBy/smG6kIKrWG2/jYn2GuM= +github.com/charmbracelet/x/windows v0.2.2/go.mod h1:/8XtdKZzedat74NQFn0NGlGL4soHB0YQZrETF96h75k= github.com/ckaznocha/intrange v0.3.1 h1:j1onQyXvHUsPWujDH6WIjhyH26gkRt/txNlV7LspvJs= github.com/ckaznocha/intrange v0.3.1/go.mod h1:QVepyz1AkUoFQkpEqksSYpNpUo3c5W7nWh/s6SHIJJk= +github.com/clipperhouse/displaywidth v0.11.0 h1:lBc6kY44VFw+TDx4I8opi/EtL9m20WSEFgwIwO+UVM8= +github.com/clipperhouse/displaywidth v0.11.0/go.mod h1:bkrFNkf81G8HyVqmKGxsPufD3JhNl3dSqnGhOoSD/o0= +github.com/clipperhouse/uax29/v2 v2.7.0 h1:+gs4oBZ2gPfVrKPthwbMzWZDaAFPGYK72F0NJv2v7Vk= +github.com/clipperhouse/uax29/v2 v2.7.0/go.mod h1:EFJ2TJMRUaplDxHKj1qAEhCtQPW2tJSwu5BF98AuoVM= github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2 h1:aBangftG7EVZoUb69Os8IaYg++6uMOdKK83QtkkvJik= github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2/go.mod h1:qwXFYgsP6T7XnJtbKlf1HP8AjxZZyzxMmc+Lq5GjlU4= github.com/cpuguy83/go-md2man/v2 v2.0.0-20190314233015-f79a8a8ca69d/go.mod h1:maD7wRr/U5Z6m/iR4s+kqSMx2CaBsrgA7czyZG/E6dU= @@ -209,12 +219,15 @@ github.com/dave/dst v0.27.3/go.mod h1:jHh6EOibnHgcUW3WjKHisiooEkYwqpHLBSX1iOBhEy github.com/dave/jennifer v1.7.1 h1:B4jJJDHelWcDhlRQxWeo0Npa/pYKBLrirAQoTN45txo= github.com/dave/jennifer v1.7.1/go.mod h1:nXbxhEmQfOZhWml3D1cDK5M1FLnMSozpbFN/m3RmGZc= github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= -github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c= github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= +github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc h1:U9qPSI2PIWSS1VwoXQT9A3Wy9MM3WgvqSxFWenqJduM= +github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= github.com/denis-tingaikin/go-header v0.5.0 h1:SRdnP5ZKvcO9KKRP1KJrhFR3RrlGuD+42t4429eC9k8= github.com/denis-tingaikin/go-header v0.5.0/go.mod h1:mMenU5bWrok6Wl2UsZjy+1okegmwQ3UgWl4V1D8gjlY= -github.com/dlclark/regexp2 v1.11.5 h1:Q/sSnsKerHeCkc/jSTNq1oCm7KiVgUMZRDUoRu0JQZQ= -github.com/dlclark/regexp2 v1.11.5/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8= +github.com/dlclark/regexp2 v1.12.0 h1:0j4c5qQmnC6XOWNjP3PIXURXN2gWx76rd3KvgdPkCz8= +github.com/dlclark/regexp2 v1.12.0/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8= +github.com/dlclark/regexp2/v2 v2.2.1 h1:mf4KkFUj0gJuarK8P+LgiS+Lit7m9N1yAwEfPbee7R0= +github.com/dlclark/regexp2/v2 v2.2.1/go.mod h1:avUrQvPaLz2DrFNHJF0taWAFFX2C1GMSSoeiqFjcBmU= github.com/dustin/go-humanize v1.0.1 h1:GzkhY7T5VNhEkwH0PVJgjz+fX1rhBrR7pRT3mDkpeCY= github.com/dustin/go-humanize v1.0.1/go.mod h1:Mu1zIs6XwVuF/gI1OepvI0qD18qycQx+mFykh5fBlto= github.com/ecosyste-ms/ecosystems-go v0.4.0 h1:5A+zF+XWT8sYYYjlc2/tI1SmiDGzbHLyT9CapVc5dGA= @@ -228,38 +241,40 @@ github.com/ettle/strcase v0.2.0 h1:fGNiVF21fHXpX1niBgk0aROov1LagYsOwV/xqKDKR/Q= github.com/ettle/strcase v0.2.0/go.mod h1:DajmHElDSaX76ITe3/VHVyMin4LWSJN5Z909Wp+ED1A= github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a h1:yDWHCSQ40h88yih2JAcL6Ls/kVkSE8GFACTGVnMPruw= github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a/go.mod h1:7Ga40egUymuWXxAe151lTNnCv97MddSOVsjpPPkityA= -github.com/fatih/color v1.18.0 h1:S8gINlzdQ840/4pfAwic/ZE0djQEH3wM94VfqLTZcOM= -github.com/fatih/color v1.18.0/go.mod h1:4FelSpRwEGDpQ12mAdzqdOukCy4u8WUtOY6lkT/6HfU= +github.com/fatih/color v1.19.0 h1:Zp3PiM21/9Ld6FzSKyL5c/BULoe/ONr9KlbYVOfG8+w= +github.com/fatih/color v1.19.0/go.mod h1:zNk67I0ZUT1bEGsSGyCZYZNrHuTkJJB+r6Q9VuMi0LE= github.com/fatih/structtag v1.2.0 h1:/OdNE99OxoI/PqaW/SuSK9uxxT3f/tcSZgon/ssNSx4= github.com/fatih/structtag v1.2.0/go.mod h1:mBJUNpUnHmRKrKlQQlmCrh5PuhftFbNv8Ys4/aAZl94= -github.com/felixge/httpsnoop v1.0.4 h1:NFTV2Zj1bL4mc9sqWACXbQFVBBg2W3GPvqp8/ESS2Wg= -github.com/felixge/httpsnoop v1.0.4/go.mod h1:m8KPJKqk1gH5J9DgRY2ASl2lWCfGKXixSwevea8zH2U= -github.com/firefart/nonamedreturns v1.0.6 h1:vmiBcKV/3EqKY3ZiPxCINmpS431OcE1S47AQUwhrg8E= -github.com/firefart/nonamedreturns v1.0.6/go.mod h1:R8NisJnSIpvPWheCq0mNRXJok6D8h7fagJTF8EMEwCo= +github.com/felixge/httpsnoop v1.1.0 h1:3YtUj32ZZkqZtt3sZZsClsymw/QDuVfpNhoA31zeORc= +github.com/felixge/httpsnoop v1.1.0/go.mod h1:Zqxgdd+1Rkcz8euOqdr7lqgCRJztwr5hp9vDSi5UZCE= +github.com/firefart/nonamedreturns v1.0.8 h1:iB32Dl17zJl1zlVEj/WlUWgx0HiRyQ85OUw1WHa4/II= +github.com/firefart/nonamedreturns v1.0.8/go.mod h1:vxFNvm5AfP/8rgAKFzYmnqx0yp1HjrYsErZ9pHPTznA= github.com/frankban/quicktest v1.14.3 h1:FJKSZTDHjyhriyC81FLQ0LY93eSai0ZyR/ZIkd3ZUKE= github.com/frankban/quicktest v1.14.3/go.mod h1:mgiwOwqx65TmIk1wJ6Q7wvnVMocbUorkibMOrVTHZps= github.com/fsnotify/fsnotify v1.9.0 h1:2Ml+OJNzbYCTzsxtv8vKSFD9PbJjmhYF14k/jKC7S9k= github.com/fsnotify/fsnotify v1.9.0/go.mod h1:8jBTzvmWwFyi3Pb8djgCCO5IBqzKJ/Jwo8TRcHyHii0= github.com/fzipp/gocyclo v0.6.0 h1:lsblElZG7d3ALtGMx9fmxeTKZaLLpU8mET09yN4BBLo= github.com/fzipp/gocyclo v0.6.0/go.mod h1:rXPyn8fnlpa0R2csP/31uerbiVBugk5whMdlyaLkLoA= -github.com/ghostiam/protogetter v0.3.20 h1:oW7OPFit2FxZOpmMRPP9FffU4uUpfeE/rEdE1f+MzD0= -github.com/ghostiam/protogetter v0.3.20/go.mod h1:FjIu5Yfs6FT391m+Fjp3fbAYJ6rkL/J6ySpZBfnODuI= +github.com/ghostiam/protogetter v0.3.21 h1:EeWTGvL/Eyosp653hiWb6Byx4b69iJC4/E+za7vQHoI= +github.com/ghostiam/protogetter v0.3.21/go.mod h1:iAKSpyoHwYzay+OpjoWgwzRtPFthEfuUvmlomTThck0= github.com/git-pkgs/archives v0.5.1 h1:qwu/vsoerQZF1iysRtfcxpy1KIUSJJSpXJ5JNxzNoQw= github.com/git-pkgs/archives v0.5.1/go.mod h1:AKpkxnts49R9uAt1mL2ULYcHrmYujCDVu24IsFvW9so= github.com/git-pkgs/cooldown v0.1.1 h1:9OqqzCB8gANz/y44SmqGD0Jp8Qtu81D1sCbKl6Ehg7w= github.com/git-pkgs/cooldown v0.1.1/go.mod h1:v7APuK/UouTiu8mWQZbdDmj7DfxxkGUeuhjaRB5gv9E= github.com/git-pkgs/enrichment v0.6.5 h1:U0SPzWVGoK4R8TwojCTASBRTEV+QSs0IitdLmzI/g/k= github.com/git-pkgs/enrichment v0.6.5/go.mod h1:Vt2PLMvWPOio9DLyC8Gdhh1yxsHwcRcG+L2Kkc9+kak= +github.com/git-pkgs/integrity v0.1.1 h1:nHQ7SktOiGM1dOb5BFnkdtttG/6FCgE6r5ru6QnsGts= +github.com/git-pkgs/integrity v0.1.1/go.mod h1:hxu24lcd230377hCF28JQW7sGcCbuNLqo/0ULeb+F1Q= github.com/git-pkgs/magic v0.2.0 h1:c7HqVxnP8c88EaVMH0/KraDFVTcmiXckRiSvNZEnvMQ= github.com/git-pkgs/magic v0.2.0/go.mod h1:3ndidt+yvFaI1M0aEkkzkOlFnLPkeVQASIUojazcxCI= github.com/git-pkgs/packageurl-go v0.3.1 h1:WM3RBABQZLaRBxgKyYughc3cVBE8KyQxbSC6Jt5ak7M= github.com/git-pkgs/packageurl-go v0.3.1/go.mod h1:rcIxiG37BlQLB6FZfgdj9Fm7yjhRQd3l+5o7J0QPAk4= github.com/git-pkgs/pom v0.1.5 h1:TGT8Az2OMxGWsXnSagtUMGzZm7Oax8HrSCteA+mi0qY= github.com/git-pkgs/pom v0.1.5/go.mod h1:ufdMBe1lKzqOeP9IUb9NPZ458xKV8E8NvuyBMxOfwIk= -github.com/git-pkgs/purl v0.1.16 h1:VAX6tv0hhdTENbkrGMoPZbOAl1Y8U1/ZnzoCsYuNBYM= -github.com/git-pkgs/purl v0.1.16/go.mod h1:7u7ora8tQdrkS7Auclr5v8dCJdjN4ej6AbrvYZi2b7k= -github.com/git-pkgs/registries v0.7.0 h1:+LbOOMHbvjmXGfsi88hcGH+SfTXYsXA3UY5KYI5mB7s= -github.com/git-pkgs/registries v0.7.0/go.mod h1:VCD4q+ZW0fInopzseg9rAmBEL553R2JQe60UHXtv26w= +github.com/git-pkgs/purl v0.1.17 h1:oRSd8tqllTLl74Wa4WnuqU500hXd9OdUnImOEswQUVE= +github.com/git-pkgs/purl v0.1.17/go.mod h1:7u7ora8tQdrkS7Auclr5v8dCJdjN4ej6AbrvYZi2b7k= +github.com/git-pkgs/registries v0.8.1 h1:Yf2FFdARQ1HcdtZfWBYa5OZFwZHzhFYStiz7qbTDDUU= +github.com/git-pkgs/registries v0.8.1/go.mod h1:5dc3V7rOhAI5755L/bDtjtYV4D5XV4J/4ZtyIXSEs0U= github.com/git-pkgs/spdx v0.3.1 h1:58JPY5X9pYpXvnzzZIgehItlBykeOOw52pNc4OBcS+c= github.com/git-pkgs/spdx v0.3.1/go.mod h1:cqRoZcvl530s/W+oGNvwjt4ODN8T1W6D/20MUZEFdto= github.com/git-pkgs/vers v0.3.1 h1:jy/ht2wIRJI5zQrccm6GTeYr+hGFwe2z8LV1HOr4Wco= @@ -270,8 +285,8 @@ github.com/github/go-spdx/v2 v2.7.0 h1:GzfXx4wFdlilARxmFRXW/mgUy3A4vSqZocCMFV6XF github.com/github/go-spdx/v2 v2.7.0/go.mod h1:Ftc45YYG1WzpzwEPKRVm9Jv8vDqOrN4gWoCkK+bHer0= github.com/go-chi/chi/v5 v5.3.1 h1:3j4HZLGZQ3JpMCrPJF/Jl3mYJfWLKBfNJ6quurUGCf8= github.com/go-chi/chi/v5 v5.3.1/go.mod h1:R+tYY2hNuVUUjxoPtqUdgBqevM9s9njzkTLutVsOCto= -github.com/go-critic/go-critic v0.14.3 h1:5R1qH2iFeo4I/RJU8vTezdqs08Egi4u5p6vOESA0pog= -github.com/go-critic/go-critic v0.14.3/go.mod h1:xwntfW6SYAd7h1OqDzmN6hBX/JxsEKl5up/Y2bsxgVQ= +github.com/go-critic/go-critic v0.14.4 h1:dSX4C3pWSeuMVxvQh6yG8U0ReSf3YOmKi4nwX5q7n/8= +github.com/go-critic/go-critic v0.14.4/go.mod h1:xwntfW6SYAd7h1OqDzmN6hBX/JxsEKl5up/Y2bsxgVQ= github.com/go-jose/go-jose/v4 v4.1.4 h1:moDMcTHmvE6Groj34emNPLs/qtYXRVcd6S7NHbHz3kA= github.com/go-jose/go-jose/v4 v4.1.4/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08= github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A= @@ -289,8 +304,8 @@ github.com/go-openapi/spec v0.20.4/go.mod h1:faYFR1CvsJZ0mNsmsphTMSoRrNV3TEDoAM7 github.com/go-openapi/swag v0.19.5/go.mod h1:POnQmlKehdgb5mhVOsnJFsivZCEZ/vjK9gh66Z9tfKk= github.com/go-openapi/swag v0.19.15 h1:D2NRCBzS9/pEY3gP9Nl8aDqGUcPFrwG2p+CNFrLyrCM= github.com/go-openapi/swag v0.19.15/go.mod h1:QYRuS/SOXUCsnplDa677K7+DxSOj6IPNl/eQntq43wQ= -github.com/go-quicktest/qt v1.101.0 h1:O1K29Txy5P2OK0dGo59b7b0LR6wKfIhttaAhHUyn7eI= -github.com/go-quicktest/qt v1.101.0/go.mod h1:14Bz/f7NwaXPtdYEgzsx46kqSxVwTbzVZsDC26tQJow= +github.com/go-quicktest/qt v1.102.0 h1:HSQxCeh5YZH3EL3W39ixjtyaEhcWSXQHtHnMBzSs474= +github.com/go-quicktest/qt v1.102.0/go.mod h1:p4lGIVX+8Wa6ZPNDvqcxq36XpUDLh42FLetFU7odllI= github.com/go-sql-driver/mysql v1.8.1/go.mod h1:wEBSXgmK//2ZFJyE+qWnIsVGmvmEKlqwuVSjsCm7DZg= github.com/go-sql-driver/mysql v1.9.3 h1:U/N249h2WzJ3Ukj8SowVFjdtZKfu9vlLZxjPXV1aweo= github.com/go-sql-driver/mysql v1.9.3/go.mod h1:qn46aNg1333BRMNU69Lq93t8du/dwxI64Gl8i5p1WMU= @@ -331,14 +346,14 @@ github.com/golang/protobuf v1.5.4 h1:i7eJL8qZTpSEXOPTxNKhASYpMn+8e5Q6AdndVa1dWek github.com/golang/protobuf v1.5.4/go.mod h1:lnTiLA8Wa4RWRcIUkrtSVa5nRhsEGBg48fD6rSs7xps= github.com/golangci/asciicheck v0.5.0 h1:jczN/BorERZwK8oiFBOGvlGPknhvq0bjnysTj4nUfo0= github.com/golangci/asciicheck v0.5.0/go.mod h1:5RMNAInbNFw2krqN6ibBxN/zfRFa9S6tA1nPdM0l8qQ= -github.com/golangci/dupl v0.0.0-20250308024227-f665c8d69b32 h1:WUvBfQL6EW/40l6OmeSBYQJNSif4O11+bmWEz+C7FYw= -github.com/golangci/dupl v0.0.0-20250308024227-f665c8d69b32/go.mod h1:NUw9Zr2Sy7+HxzdjIULge71wI6yEg1lWQr7Evcu8K0E= +github.com/golangci/dupl v0.0.0-20260401084720-c99c5cf5c202 h1:CbTB8KpqnViI6lIXxp03Oclc4VFHi3K4BWC1TacsZ+A= +github.com/golangci/dupl v0.0.0-20260401084720-c99c5cf5c202/go.mod h1:NUw9Zr2Sy7+HxzdjIULge71wI6yEg1lWQr7Evcu8K0E= github.com/golangci/go-printf-func-name v0.1.1 h1:hIYTFJqAGp1iwoIfsNTpoq1xZAarogrvjO9AfiW3B4U= github.com/golangci/go-printf-func-name v0.1.1/go.mod h1:Es64MpWEZbh0UBtTAICOZiB+miW53w/K9Or/4QogJss= -github.com/golangci/gofmt v0.0.0-20250106114630-d62b90e6713d h1:viFft9sS/dxoYY0aiOTsLKO2aZQAPT4nlQCsimGcSGE= -github.com/golangci/gofmt v0.0.0-20250106114630-d62b90e6713d/go.mod h1:ivJ9QDg0XucIkmwhzCDsqcnxxlDStoTl89jDMIoNxKY= -github.com/golangci/golangci-lint/v2 v2.10.1 h1:flhw5Px6ojbLyEFzXvJn5B2HEdkkRlkhE1SnmCbQBiE= -github.com/golangci/golangci-lint/v2 v2.10.1/go.mod h1:dBsrOk6zj0vDhlTv+IiJGqkDokR24IVTS7W3EVfPTQY= +github.com/golangci/gofmt v0.0.0-20260820135601-e84e05053792 h1:WL8YKrt3UbOBqSRU7GpP5BTtQTMWtVtj+mfPijgZeIg= +github.com/golangci/gofmt v0.0.0-20260820135601-e84e05053792/go.mod h1:te5hX0dW4C5r6YbXs+6ysNr8Q5UTmdIqGbb+mlFiYmA= +github.com/golangci/golangci-lint/v2 v2.13.1 h1:RuM4OcluM4xFQcGuRE6R7jA33pqxK/W1EsBxpugdZjg= +github.com/golangci/golangci-lint/v2 v2.13.1/go.mod h1:HwX7mDzqHbcSxlhrTygjX1GJbAfQ3sJAqOx41qQlhDE= github.com/golangci/golines v0.15.0 h1:Qnph25g8Y1c5fdo1X7GaRDGgnMHgnxh4Gk4VfPTtRx0= github.com/golangci/golines v0.15.0/go.mod h1:AZjXd23tbHMpowhtnGlj9KCNsysj72aeZVVHnVcZx10= github.com/golangci/misspell v0.8.0 h1:qvxQhiE2/5z+BVRo1kwYA8yGz+lOlu5Jfvtx2b04Jbg= @@ -347,6 +362,8 @@ github.com/golangci/plugin-module-register v0.1.2 h1:e5WM6PO6NIAEcij3B053CohVp3H github.com/golangci/plugin-module-register v0.1.2/go.mod h1:1+QGTsKBvAIvPvoY/os+G5eoqxWn70HYDm2uvUyGuVw= github.com/golangci/revgrep v0.8.0 h1:EZBctwbVd0aMeRnNUsFogoyayvKHyxlV3CdUA46FX2s= github.com/golangci/revgrep v0.8.0/go.mod h1:U4R/s9dlXZsg8uJmaR1GrloUr14D7qDl8gi2iPXJH8k= +github.com/golangci/rowserrcheck v0.0.0-20260419091836-c5f79b8a11ba h1:lqtcnSMDuuJdu/LrKWi5RJzpSNLOJXYe/nzQutTI5kg= +github.com/golangci/rowserrcheck v0.0.0-20260419091836-c5f79b8a11ba/go.mod h1:sCBNcpRmhJCtbFGz49+IM3ETTFf7QdJ30AeYCd43NKk= github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e h1:ai0EfmVYE2bRA5htgAG9r7s3tHsfjIhN98WshBTJ9jM= github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e/go.mod h1:Vrn4B5oR9qRwM+f54koyeH3yzphlecwERs0el27Fr/s= github.com/golangci/unconvert v0.0.0-20250410112200-a129a6e6413e h1:gD6P7NEo7Eqtt0ssnqSJNNndxe69DOQ24A5h7+i3KpM= @@ -370,10 +387,10 @@ github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0= github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= github.com/google/wire v0.7.0 h1:JxUKI6+CVBgCO2WToKy/nQk0sS+amI9z9EjVmdaocj4= github.com/google/wire v0.7.0/go.mod h1:n6YbUQD9cPKTnHXEBN2DXlOp/mVADhVErcMFb0v3J18= -github.com/googleapis/enterprise-certificate-proxy v0.3.14 h1:yh8ncqsbUY4shRD5dA6RlzjJaT4hi3kII+zYw8wmLb8= -github.com/googleapis/enterprise-certificate-proxy v0.3.14/go.mod h1:vqVt9yG9480NtzREnTlmGSBmFrA+bzb0yl0TxoBQXOg= -github.com/googleapis/gax-go/v2 v2.19.0 h1:fYQaUOiGwll0cGj7jmHT/0nPlcrZDFPrZRhTsoCr8hE= -github.com/googleapis/gax-go/v2 v2.19.0/go.mod h1:w2ROXVdfGEVFXzmlciUU4EdjHgWvB5h2n6x/8XSTTJA= +github.com/googleapis/enterprise-certificate-proxy v0.3.18 h1:hvVi34VucdrV1IIsiWuqYM8kutw/92MxNEFxCJZEh0k= +github.com/googleapis/enterprise-certificate-proxy v0.3.18/go.mod h1:rSEsBUemEBZEexP2y6jPp16LUmUbjmSbcPMQizR0o4k= +github.com/googleapis/gax-go/v2 v2.23.0 h1:Tchl7qkvE7Ip3y+ztvNufYFvkfqTe7NfLTYGIdJRLuE= +github.com/googleapis/gax-go/v2 v2.23.0/go.mod h1:rBQKOVJCdb8IFEzg+FCwlt1LP/xMDGuqUXhUG+XMXEg= github.com/gordonklaus/ineffassign v0.2.0 h1:Uths4KnmwxNJNzq87fwQQDDnbNb7De00VOk9Nu0TySs= github.com/gordonklaus/ineffassign v0.2.0/go.mod h1:TIpymnagPSexySzs7F9FnO1XFTy8IT3a59vmZp5Y9Lw= github.com/gostaticanalysis/analysisutil v0.7.1 h1:ZMCjoue3DtDWQ5WyU16YbjbQEQ3VuzwxALrpYd+HeKk= @@ -393,8 +410,8 @@ github.com/hashicorp/go-immutable-radix/v2 v2.1.0/go.mod h1:hgdqLXA4f6NIjRVisM1T github.com/hashicorp/go-uuid v1.0.3 h1:2gKiV6YVmrJ1i2CKKa9obLvRieoRGviZFL26PcT/Co8= github.com/hashicorp/go-uuid v1.0.3/go.mod h1:6SBZvOh/SIDV7/2o3Jml5SYk/TvGqwFJ/bN7x4byOro= github.com/hashicorp/go-version v1.2.1/go.mod h1:fltr4n8CU8Ke44wwGCBoEymUuxUHl09ZGVZPK5anwXA= -github.com/hashicorp/go-version v1.8.0 h1:KAkNb1HAiZd1ukkxDFGmokVZe1Xy9HG6NUp+bPle2i4= -github.com/hashicorp/go-version v1.8.0/go.mod h1:fltr4n8CU8Ke44wwGCBoEymUuxUHl09ZGVZPK5anwXA= +github.com/hashicorp/go-version v1.9.0 h1:CeOIz6k+LoN3qX9Z0tyQrPtiB1DFYRPfCIBtaXPSCnA= +github.com/hashicorp/go-version v1.9.0/go.mod h1:fltr4n8CU8Ke44wwGCBoEymUuxUHl09ZGVZPK5anwXA= github.com/hashicorp/golang-lru/v2 v2.0.7 h1:a+bsQ5rvGLjzHuww6tVxozPZFVghXaHOwFs4luLUK2k= github.com/hashicorp/golang-lru/v2 v2.0.7/go.mod h1:QeFd9opnmA6QUJc5vARoKUSoFhyfM2/ZepoAG6RGpeM= github.com/hashicorp/hcl v1.0.0 h1:0Anlzjpi4vEasTeNFn2mLJgTSwt0+6sfsiTG8qcWGx4= @@ -403,10 +420,8 @@ github.com/hexops/gotextdiff v1.0.3 h1:gitA9+qJrrTCsiCl7+kh75nPqQt1cx4ZkudSTLoUq github.com/hexops/gotextdiff v1.0.3/go.mod h1:pSWU5MAI3yDq+fZBTazCSJysOMbxWL1BSow5/V2vxeg= github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2s0bqwp9tc8= github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw= -github.com/jgautheron/goconst v1.8.2 h1:y0XF7X8CikZ93fSNT6WBTb/NElBu9IjaY7CCYQrCMX4= -github.com/jgautheron/goconst v1.8.2/go.mod h1:A0oxgBCHy55NQn6sYpO7UdnA9p+h7cPtoOZUmvNIako= -github.com/jingyugao/rowserrcheck v1.1.1 h1:zibz55j/MJtLsjP1OF4bSdgXxwL1b+Vn7Tjzq7gFzUs= -github.com/jingyugao/rowserrcheck v1.1.1/go.mod h1:4yvlZSDb3IyDTUZJUmpZfm2Hwok+Dtp+nu2qOq+er9c= +github.com/jgautheron/goconst v1.11.0 h1:KgN90z5qXt5f0Uzf3cWXev3hfMMFUyNeKdpkSBRvLDk= +github.com/jgautheron/goconst v1.11.0/go.mod h1:0p+wv1lFOiUr0IlNNT1nrm6+8DB8u2sU6KHGzFRXHDc= github.com/jjti/go-spancheck v0.6.5 h1:lmi7pKxa37oKYIMScialXUK6hP3iY5F1gu+mLBPgYB8= github.com/jjti/go-spancheck v0.6.5/go.mod h1:aEogkeatBrbYsyW6y5TgDfihCulDYciL1B7rG2vSsrU= github.com/jmoiron/sqlx v1.4.0 h1:1PLqN7S1UYp5t4SrVVnt4nUVNemrDAtxlulVe+Qgm3o= @@ -420,8 +435,8 @@ github.com/karamaru-alpha/copyloopvar v1.2.2 h1:yfNQvP9YaGQR7VaWLYcfZUlRP2eo2vhE github.com/karamaru-alpha/copyloopvar v1.2.2/go.mod h1:oY4rGZqZ879JkJMtX3RRkcXRkmUvH0x35ykgaKgsgJY= github.com/keybase/go-keychain v0.0.1 h1:way+bWYa6lDppZoZcgMbYsvC7GxljxrskdNInRtuthU= github.com/keybase/go-keychain v0.0.1/go.mod h1:PdEILRW3i9D8JcdM+FmY6RwkHGnhHxXwkPPMeUgOK1k= -github.com/kisielk/errcheck v1.9.0 h1:9xt1zI9EBfcYBvdU1nVrzMzzUPUtPKs9bVSIM3TAb3M= -github.com/kisielk/errcheck v1.9.0/go.mod h1:kQxWMMVZgIkDq7U8xtG/n2juOjbLgZtedi0D+/VL/i8= +github.com/kisielk/errcheck v1.20.0 h1:9rwHBNKzd4wkDWcROy3DvFGNqEPlkxBg305rvk7HabI= +github.com/kisielk/errcheck v1.20.0/go.mod h1:O+f80MKNwX8Oor2jwgpeQ9An7uJm+hRSgT+h22knRJU= github.com/kkHAIKE/contextcheck v1.1.6 h1:7HIyRcnyzxL9Lz06NGhiKvenXq7Zw6Q0UQu/ttjfJCE= github.com/kkHAIKE/contextcheck v1.1.6/go.mod h1:3dDbMRNBFaq8HFXWC1JyvDSPm43CmE6IuHam8Wr0rkg= github.com/klauspost/compress v1.19.1 h1:VsB4HPswih7mmZ8WleSFQ75c/Ui1M4trX5oAsJnhSlk= @@ -443,8 +458,8 @@ github.com/lasiar/canonicalheader v1.1.2 h1:vZ5uqwvDbyJCnMhmFYimgMZnJMjwljN5VGY0 github.com/lasiar/canonicalheader v1.1.2/go.mod h1:qJCeLFS0G/QlLQ506T+Fk/fWMa2VmBUiEI2cuMK4djI= github.com/ldez/exptostd v0.4.5 h1:kv2ZGUVI6VwRfp/+bcQ6Nbx0ghFWcGIKInkG/oFn1aQ= github.com/ldez/exptostd v0.4.5/go.mod h1:QRjHRMXJrCTIm9WxVNH6VW7oN7KrGSht69bIRwvdFsM= -github.com/ldez/gomoddirectives v0.8.0 h1:JqIuTtgvFC2RdH1s357vrE23WJF2cpDCPFgA/TWDGpk= -github.com/ldez/gomoddirectives v0.8.0/go.mod h1:jutzamvZR4XYJLr0d5Honycp4Gy6GEg2mS9+2YX3F1Q= +github.com/ldez/gomoddirectives v0.9.0 h1:2YV/EX7nVlWL4jySusYTzBKHuE3D2fgcRsQuMa3yIoo= +github.com/ldez/gomoddirectives v0.9.0/go.mod h1:DdZzfm9MdXCjn2/UGYXCFfo+tzrp2Ib4iD2Q0kIJkwE= github.com/ldez/grignotin v0.10.1 h1:keYi9rYsgbvqAZGI1liek5c+jv9UUjbvdj3Tbn5fn4o= github.com/ldez/grignotin v0.10.1/go.mod h1:UlDbXFCARrXbWGNGP3S5vsysNXAPhnSuBufpTEbwOas= github.com/ldez/structtags v0.6.1 h1:bUooFLbXx41tW8SvkfwfFkkjPYvFFs59AAMgVg6DUBk= @@ -458,8 +473,8 @@ github.com/leonklingele/grouper v1.1.2/go.mod h1:6D0M/HVkhs2yRKRFZUoGjeDy7EZTfFB github.com/lib/pq v1.10.9/go.mod h1:AlVN5x4E4T544tWzH6hKfbfQvm3HdbOxrmggDNAPY9o= github.com/lib/pq v1.12.3 h1:tTWxr2YLKwIvK90ZXEw8GP7UFHtcbTtty8zsI+YjrfQ= github.com/lib/pq v1.12.3/go.mod h1:/p+8NSbOcwzAEI7wiMXFlgydTwcgTr3OSKMsD2BitpA= -github.com/lucasb-eyer/go-colorful v1.2.0 h1:1nnpGOrhyZZuNyfu1QjKiUICQ74+3FNCN69Aj6K7nkY= -github.com/lucasb-eyer/go-colorful v1.2.0/go.mod h1:R4dSotOR9KMtayYi1e77YzuveK+i7ruzyGqttikkLy0= +github.com/lucasb-eyer/go-colorful v1.4.1 h1:1EO+WB73+EH8EVbzlrG3KLAfEypQWVHIBqlTf+2hNss= +github.com/lucasb-eyer/go-colorful v1.4.1/go.mod h1:R4dSotOR9KMtayYi1e77YzuveK+i7ruzyGqttikkLy0= github.com/macabu/inamedparam v0.2.0 h1:VyPYpOc10nkhI2qeNUdh3Zket4fcZjEWe35poddBCpE= github.com/macabu/inamedparam v0.2.0/go.mod h1:+Pee9/YfGe5LJ62pYXqB89lJ+0k5bsR8Wgz/C0Zlq3U= github.com/magiconair/properties v1.8.6 h1:5ibWZ6iY0NctNGWo87LalDlEZ6R41TqbbDamhfG/Qzo= @@ -471,8 +486,8 @@ github.com/mailru/easyjson v0.7.7 h1:UGYAvKxe3sBsEDzO8ZeWOSlIQfWFlxbzLZe7hwFURr0 github.com/mailru/easyjson v0.7.7/go.mod h1:xzfreul335JAWq5oZzymOObrkdz5UnU4kGfJJLY9Nlc= github.com/manuelarte/embeddedstructfieldcheck v0.4.0 h1:3mAIyaGRtjK6EO9E73JlXLtiy7ha80b2ZVGyacxgfww= github.com/manuelarte/embeddedstructfieldcheck v0.4.0/go.mod h1:z8dFSyXqp+fC6NLDSljRJeNQJJDWnY7RoWFzV3PC6UM= -github.com/manuelarte/funcorder v0.5.0 h1:llMuHXXbg7tD0i/LNw8vGnkDTHFpTnWqKPI85Rknc+8= -github.com/manuelarte/funcorder v0.5.0/go.mod h1:Yt3CiUQthSBMBxjShjdXMexmzpP8YGvGLjrxJNkO2hA= +github.com/manuelarte/funcorder v0.6.0 h1:0hBngc4fa1IgNiI65A7sFGkMvoMCc878RjqB5V7rWP0= +github.com/manuelarte/funcorder v0.6.0/go.mod h1:id3NDhXdQBmeqXH7eVC6Z89xS6JxvZ8kF9xUxpArU/g= github.com/maratori/testableexamples v1.0.1 h1:HfOQXs+XgfeRBJ+Wz0XfH+FHnoY9TVqL6Fcevpzy4q8= github.com/maratori/testableexamples v1.0.1/go.mod h1:XE2F/nQs7B9N08JgyRmdGjYVGqxWwClLPCGSQhXQSrQ= github.com/maratori/testpackage v1.1.2 h1:ffDSh+AgqluCLMXhM19f/cpvQAKygKAJXFl9aUjmbqs= @@ -481,24 +496,24 @@ github.com/matoous/godox v1.1.0 h1:W5mqwbyWrwZv6OQ5Z1a/DHGMOvXYCBP3+Ht7KMoJhq4= github.com/matoous/godox v1.1.0/go.mod h1:jgE/3fUXiTurkdHOLT5WEkThTSuE7yxHv5iWPa80afs= github.com/matryer/is v1.4.0 h1:sosSmIWwkYITGrxZ25ULNDeKiMNzFSr4V/eqBQP0PeE= github.com/matryer/is v1.4.0/go.mod h1:8I/i5uYgLzgsgEloJE1U6xx5HkBQpAZvepWuujKwMRU= -github.com/mattn/go-colorable v0.1.14 h1:9A9LHSqF/7dyVVX6g0U9cwm9pG3kP9gSzcuIPHPsaIE= -github.com/mattn/go-colorable v0.1.14/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8= +github.com/mattn/go-colorable v0.1.15 h1:+u9SLTRGnXv73cEsnsmoZBom+dMU88B2M0aDcWy0/jY= +github.com/mattn/go-colorable v0.1.15/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8= github.com/mattn/go-isatty v0.0.24 h1:tGZZoVgT/KiqK1c8ocVLeDS8BSWMRd47J3Lbz7vsReI= github.com/mattn/go-isatty v0.0.24/go.mod h1:nMCL3Zebbrt45jsMDgnfIwz6ydEQApk5oEI3HqDio6A= -github.com/mattn/go-runewidth v0.0.16 h1:E5ScNMtiwvlvB5paMFdw9p4kSQzbXFikJ5SQO6TULQc= -github.com/mattn/go-runewidth v0.0.16/go.mod h1:Jdepj2loyihRzMpdS35Xk/zdY8IAYHsh153qUoGf23w= +github.com/mattn/go-runewidth v0.0.24 h1:cpokDiIn0MGnhdHwuWnJBITySJ20QyNGnY2kR/ay2DU= +github.com/mattn/go-runewidth v0.0.24/go.mod h1:XBkDxAl56ILZc9knddidhrOlY5R/pDhgLpndooCuJAs= github.com/mattn/go-sqlite3 v1.14.22 h1:2gZY6PC6kBnID23Tichd1K+Z0oS6nE/XwU+Vz/5o4kU= github.com/mattn/go-sqlite3 v1.14.22/go.mod h1:Uh1q+B4BYcTPb+yiD3kU8Ct7aC0hY9fxUwlHK0RXw+Y= -github.com/mgechev/revive v1.14.0 h1:CC2Ulb3kV7JFYt+izwORoS3VT/+Plb8BvslI/l1yZsc= -github.com/mgechev/revive v1.14.0/go.mod h1:MvnujelCZBZCaoDv5B3foPo6WWgULSSFxvfxp7GsPfo= +github.com/mgechev/revive v1.15.0 h1:vJ0HzSBzfNyPbHKolgiFjHxLek9KUijhqh42yGoqZ8Q= +github.com/mgechev/revive v1.15.0/go.mod h1:LlAKO3QQe9OJ0pVZzI2GPa8CbXGZ/9lNpCGvK4T/a8A= github.com/mitchellh/go-homedir v1.1.0 h1:lukF9ziXFxDFPkA1vsr5zpc1XuPDn/wFntq5mG+4E0Y= github.com/mitchellh/go-homedir v1.1.0/go.mod h1:SfyaCUpYCn1Vlf4IUYiD9fPX4A5wJrkLzIz1N1q0pr0= github.com/mitchellh/mapstructure v1.5.0 h1:jeMsZIYE/09sWLaz43PL7Gy6RuMjD2eJVyuac5Z2hdY= github.com/mitchellh/mapstructure v1.5.0/go.mod h1:bFUtVrKA4DC2yAKiSyO/QUcy7e+RRV2QTWOzhPopBRo= github.com/moricho/tparallel v0.3.2 h1:odr8aZVFA3NZrNybggMkYO3rgPRcqjeQUlBBFVxKHTI= github.com/moricho/tparallel v0.3.2/go.mod h1:OQ+K3b4Ln3l2TZveGCywybl68glfLEwFGqvnjok8b+U= -github.com/muesli/termenv v0.16.0 h1:S5AlUN9dENB57rsbnkPyfdGuWIlkmzJjbFf0Tf5FWUc= -github.com/muesli/termenv v0.16.0/go.mod h1:ZRfOIKPFDYQoDFF4Olj7/QJbW60Ol/kL1pU3VfY/Cnk= +github.com/muesli/cancelreader v0.2.2 h1:3I4Kt4BQjOR54NavqnDogx/MIoWBFa0StPA8ELUXHmA= +github.com/muesli/cancelreader v0.2.2/go.mod h1:3XuTXfFS2VjM+HTLZY9Ak0l6eUKfijIfMUZ4EgX0QYo= github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 h1:C3w9PqII01/Oq1c1nUAm88MOHcQC9l5mIlSMApZMrHA= github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822/go.mod h1:+n7T8mK8HuQTcFwEeznm/DIxMOiR9yIdICNftLE1DvQ= github.com/nakabonne/nestif v0.3.1 h1:wm28nZjhQY5HyYPx+weN3Q65k6ilSBxDb8v5S81B81U= @@ -510,16 +525,16 @@ github.com/nishanths/exhaustive v0.12.0 h1:vIY9sALmw6T/yxiASewa4TQcFsVYZQQRUQJhK github.com/nishanths/exhaustive v0.12.0/go.mod h1:mEZ95wPIZW+x8kC4TgC+9YCUgiST7ecevsVDTgc2obs= github.com/nishanths/predeclared v0.2.2 h1:V2EPdZPliZymNAn79T8RkNApBjMmVKh5XRpLm/w98Vk= github.com/nishanths/predeclared v0.2.2/go.mod h1:RROzoN6TnGQupbC+lqggsOlcgysk3LMK/HI84Mp280c= -github.com/nunnatsa/ginkgolinter v0.23.0 h1:x3o4DGYOWbBMP/VdNQKgSj+25aJKx2Pe6lHr8gBcgf8= -github.com/nunnatsa/ginkgolinter v0.23.0/go.mod h1:9qN1+0akwXEccwV1CAcCDfcoBlWXHB+ML9884pL4SZ4= +github.com/nunnatsa/ginkgolinter v0.24.0 h1:Mp0EagluLFP98JatP6nqp/gGEoljNG97uf9AcxcBVy8= +github.com/nunnatsa/ginkgolinter v0.24.0/go.mod h1:2ZMRuzX6+3XXyY6UZOwb6n+MCocVGbkIsDBC4vuWz5c= github.com/oapi-codegen/nullable v1.2.0 h1:VflFkDW980KhBPiFF7nWSyjg+r4Obqj8lXipV0UkP5w= github.com/oapi-codegen/nullable v1.2.0/go.mod h1:KUZ3vUzkmEKY90ksAmit2+5juDIhIZhfDl+0PwOQlFY= github.com/oapi-codegen/runtime v1.6.0 h1:7Xx+GlueD6nRuyKoCPzL434Jfi3BetbiJOrzCHp/VPU= github.com/oapi-codegen/runtime v1.6.0/go.mod h1:GwV7hC2hviaMzj+ITfHVRESK5J2W/GefVwIND/bMGvU= -github.com/onsi/ginkgo/v2 v2.28.1 h1:S4hj+HbZp40fNKuLUQOYLDgZLwNUVn19N3Atb98NCyI= -github.com/onsi/ginkgo/v2 v2.28.1/go.mod h1:CLtbVInNckU3/+gC8LzkGUb9oF+e8W8TdUsxPwvdOgE= -github.com/onsi/gomega v1.39.1 h1:1IJLAad4zjPn2PsnhH70V4DKRFlrCzGBNrNaru+Vf28= -github.com/onsi/gomega v1.39.1/go.mod h1:hL6yVALoTOxeWudERyfppUcZXjMwIMLnuSfruD2lcfg= +github.com/onsi/ginkgo/v2 v2.32.0 h1:Hw7s2pVrQo/8Yz5N77qdnpHaoc+c6cC9WIV1Jce+J6E= +github.com/onsi/ginkgo/v2 v2.32.0/go.mod h1:+aXOY+vzZ5mu2iI2HpTZUPmM//oQfsNFX6gU9kNcA44= +github.com/onsi/gomega v1.42.1 h1:iN1rCUX+44NZ1Dc97MPoeFYbFR0vh8zxoxMFwKdyZ6I= +github.com/onsi/gomega v1.42.1/go.mod h1:REff/hsDsodHoKlWsP2mAPhu1+5/6hVYNf9rIEBpeSg= github.com/otiai10/copy v1.2.0/go.mod h1:rrF5dJ5F0t/EWSYODDu4j9/vEeYHMkc8jt0zJChqQWw= github.com/otiai10/copy v1.14.0 h1:dCI/t1iTdYGtkvCuBG2BgR6KZa83PTclw4U5n2wAllU= github.com/otiai10/copy v1.14.0/go.mod h1:ECfuL02W+/FkTWZWgQqXPWZgW9oeKCSQ5qVfSc4qc4w= @@ -533,16 +548,17 @@ github.com/pandatix/go-cvss v0.6.2 h1:TFiHlzUkT67s6UkelHmK6s1INKVUG7nlKYiWWDTITG github.com/pandatix/go-cvss v0.6.2/go.mod h1:jDXYlQBZrc8nvrMUVVvTG8PhmuShOnKrxP53nOFkt8Q= github.com/pelletier/go-toml v1.9.5 h1:4yBQzkHv+7BHq2PQUZF3Mx0IYxG7LsP222s7Agd3ve8= github.com/pelletier/go-toml v1.9.5/go.mod h1:u1nR/EPcESfeI/szUZKdtJ0xRNbUoANCkoOuaOx1Y+c= -github.com/pelletier/go-toml/v2 v2.2.4 h1:mye9XuhQ6gvn5h28+VilKrrPoQVanw5PMw/TB0t5Ec4= -github.com/pelletier/go-toml/v2 v2.2.4/go.mod h1:2gIqNv+qfxSVS7cM2xJQKtLSTLUE9V8t9Stt+h56mCY= +github.com/pelletier/go-toml/v2 v2.4.3 h1:GTRvJQutkOSftxIFD5xw9aepkYNuPWmVJpffdDPYVpY= +github.com/pelletier/go-toml/v2 v2.4.3/go.mod h1:2gIqNv+qfxSVS7cM2xJQKtLSTLUE9V8t9Stt+h56mCY= github.com/peterbourgon/g2s v0.0.0-20170223122336-d4e7ad98afea h1:sKwxy1H95npauwu8vtF95vG/syrL0p8fSZo/XlDg5gk= github.com/peterbourgon/g2s v0.0.0-20170223122336-d4e7ad98afea/go.mod h1:1VcHEd3ro4QMoHfiNl/j7Jkln9+KQuorp0PItHMJYNg= github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c h1:+mdjkGKdHQG3305AYmdv1U2eRNDiU2ErMBj1gwrq8eQ= github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c/go.mod h1:7rwL4CYBLnjLxUqIJNnCWiEdr3bn6IUYi15bNlnbCCU= github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 h1:GFCKgmp0tecUJ0sJuv4pzYCqS9+RGSn52M3FUwPs+uo= github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10/go.mod h1:t/avpk3KcrXxUnYOhZhMXJlSEyie6gQbtLq5NM3loB8= -github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM= github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= +github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 h1:Jamvg5psRIccs7FGNTlIRMkT8wgtp5eCXdBlqhYGL6U= +github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= github.com/prometheus/client_golang v1.24.1 h1:JnJkREXzWxUdCuPFpIWZiPispT9xVV59uiuyR2bPlnU= github.com/prometheus/client_golang v1.24.1/go.mod h1:F+oSRECHg4sse5ucfYpYDeIv/hu68Zo0uoHKetWnzcE= github.com/prometheus/client_model v0.6.2 h1:oBsgwpGs7iVziMvrGhE53c/GrLUsZdHnqNwqPLxwZyk= @@ -561,15 +577,14 @@ github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727 h1:TCg2WBOl github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727/go.mod h1:rlzQ04UMyJXu/aOvhd8qT+hvDrFpiwqp8MRXDY9szc0= github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567 h1:M8mH9eK4OUR4lu7Gd+PU1fV2/qnDNfzT635KRSObncs= github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567/go.mod h1:DWNGW8A4Y+GyBgPuaQJuWiy0XYftx4Xm/y5Jqk9I6VQ= -github.com/raeperd/recvcheck v0.2.0 h1:GnU+NsbiCqdC2XX5+vMZzP+jAJC5fht7rcVTAhX74UI= -github.com/raeperd/recvcheck v0.2.0/go.mod h1:n04eYkwIR0JbgD73wT8wL4JjPC3wm0nFtzBnWNocnYU= +github.com/raeperd/recvcheck v0.3.0 h1:PM+XYvyxIj3bo+kobJfFTdTuU3Lmfu96mKDbyHDbRt8= +github.com/raeperd/recvcheck v0.3.0/go.mod h1:PZNwG+HztFYMH2ZPq0Hu3QgkV2yiA6VrtNz9c1fXWJo= github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec h1:W09IVJc94icq4NjY3clb7Lk8O1qJ8BdBEF8z0ibU0rE= github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec/go.mod h1:qqbHyh8v60DhA7CoWK5oRCqLrMHRGoxYCSS9EjAz6Eo= -github.com/rivo/uniseg v0.2.0/go.mod h1:J6wj4VEh+S6ZtnVlnTBMWIodfgj8LQOQFoIToxlJtxc= github.com/rivo/uniseg v0.4.7 h1:WUdvkW8uEhrYfLC4ZzdpI2ztxP1I582+49Oc5Mq64VQ= github.com/rivo/uniseg v0.4.7/go.mod h1:FN3SvrM+Zdj16jyLfmOkMNblXMcoc8DfTHruCPUcx88= -github.com/rogpeppe/go-internal v1.14.1 h1:UQB4HGPB6osV0SQTLymcB4TgvyWu6ZyliaW0tI/otEQ= -github.com/rogpeppe/go-internal v1.14.1/go.mod h1:MaRKkUm5W0goXpeCfT7UZI6fk/L7L7so1lCWt35ZSgc= +github.com/rogpeppe/go-internal v1.16.0 h1:O9DK+vNMDVGLr2BeZqmpLeMjiMNkuXfcqntWbZV6S5g= +github.com/rogpeppe/go-internal v1.16.0/go.mod h1:DrUVZyrJU+txYW5/1kwtXQSMFio52ZOxX7yM1VHvnxs= github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529 h1:18kd+8ZUlt/ARXhljq+14TwAoKa61q6dX8jtwOf6DH8= github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529/go.mod h1:qe5TWALJ8/a1Lqznoc5BDHpYX/8HU60Hm2AwRmqzxqA= github.com/rubyist/circuitbreaker v2.2.1+incompatible h1:KUKd/pV8Geg77+8LNDwdow6rVCAYOp8+kHUyFvL6Mhk= @@ -579,31 +594,31 @@ github.com/russross/blackfriday/v2 v2.1.0 h1:JIOH55/0cWyOuilr9/qlrm0BSXldqnqwMsf github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM= github.com/ryancurrah/gomodguard v1.4.1 h1:eWC8eUMNZ/wM/PWuZBv7JxxqT5fiIKSIyTvjb7Elr+g= github.com/ryancurrah/gomodguard v1.4.1/go.mod h1:qnMJwV1hX9m+YJseXEBhd2s90+1Xn6x9dLz11ualI1I= -github.com/ryanrolds/sqlclosecheck v0.5.1 h1:dibWW826u0P8jNLsLN+En7+RqWWTYrjCB9fJfSfdyCU= -github.com/ryanrolds/sqlclosecheck v0.5.1/go.mod h1:2g3dUjoS6AL4huFdv6wn55WpLIDjY7ZgUR4J8HOO/XQ= +github.com/ryancurrah/gomodguard/v2 v2.1.3 h1:E7sz3PJwE9Ba1reVxSpF6XLCPJZ74Kfw/LabTNM4GIA= +github.com/ryancurrah/gomodguard/v2 v2.1.3/go.mod h1:CQicdLGatWMxLX53JzoBjYlsNZhHbmLv2AVa0s2aivU= +github.com/ryanrolds/sqlclosecheck v0.6.0 h1:pEyL9okISdg1F1SEpJNlrEotkTGerv5BMk7U4AG0eVg= +github.com/ryanrolds/sqlclosecheck v0.6.0/go.mod h1:xyX16hsDaCMXHrMJ3JMzGf5OpDfHTOTTQrT7HOFUmeU= github.com/sanposhiho/wastedassign/v2 v2.1.0 h1:crurBF7fJKIORrV85u9UUpePDYGWnwvv3+A96WvwXT0= github.com/sanposhiho/wastedassign/v2 v2.1.0/go.mod h1:+oSmSC+9bQ+VUAxA66nBb0Z7N8CK7mscKTDYC6aIek4= -github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 h1:KRzFb2m7YtdldCEkzs6KqmJw4nqEVZGK7IN2kJkjTuQ= -github.com/santhosh-tekuri/jsonschema/v6 v6.0.2/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU= +github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 h1:1EYB5IzjZawrrnELUi78f9fPu57HuXjmddZPjrls/28= +github.com/santhosh-tekuri/jsonschema/v6 v6.0.3/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU= github.com/sashamelentyev/interfacebloat v1.1.0 h1:xdRdJp0irL086OyW1H/RTZTr1h/tMEOsumirXcOJqAw= github.com/sashamelentyev/interfacebloat v1.1.0/go.mod h1:+Y9yU5YdTkrNvoX0xHc84dxiN1iBi9+G8zZIhPVoNjQ= github.com/sashamelentyev/usestdlibvars v1.29.0 h1:8J0MoRrw4/NAXtjQqTHrbW9NN+3iMf7Knkq057v4XOQ= github.com/sashamelentyev/usestdlibvars v1.29.0/go.mod h1:8PpnjHMk5VdeWlVb4wCdrB8PNbLqZ3wBZTZWkrpZZL8= -github.com/securego/gosec/v2 v2.23.0 h1:h4TtF64qFzvnkqvsHC/knT7YC5fqyOCItlVR8+ptEBo= -github.com/securego/gosec/v2 v2.23.0/go.mod h1:qRHEgXLFuYUDkI2T7W7NJAmOkxVhkR0x9xyHOIcMNZ0= +github.com/securego/gosec/v2 v2.28.0 h1:ZsSdiDb0AtTpLFVol5z91gbMei9ZiLEPG/pZjZujp7c= +github.com/securego/gosec/v2 v2.28.0/go.mod h1:lb4/9AHe+lJy/kjWmWRWWsEipvbwGKuxf+tY1Pmjdnk= github.com/sergi/go-diff v1.2.0 h1:XU+rvMAioB0UC3q1MFrIQy4Vo5/4VsRDQQXHsEya6xQ= github.com/sergi/go-diff v1.2.0/go.mod h1:STckp+ISIX8hZLjrqAeVduY0gWCT9IjLuqbuNXdaHfM= -github.com/shurcooL/go v0.0.0-20180423040247-9e1955d9fb6e/go.mod h1:TDJrrUr11Vxrven61rcy3hJMUqaf/CLWYhHNPmT14Lk= -github.com/shurcooL/go-goon v0.0.0-20170922171312-37c2f522c041/go.mod h1:N5mDOmsrJOB+vfqUK+7DmDyjhSLIIBnXo9lvZJj3MWQ= github.com/shurcooL/sanitized_anchor_name v1.0.0/go.mod h1:1NzhyTcUVG4SuEtjjoZeVRXNmyL/1OwPU0+IJeTBvfc= -github.com/sirupsen/logrus v1.9.4 h1:TsZE7l11zFCLZnZ+teH4Umoq5BhEIfIzfRDZ1Uzql2w= -github.com/sirupsen/logrus v1.9.4/go.mod h1:ftWc9WdOfJ0a92nsE2jF5u5ZwH8Bv2zdeOC42RjbV2g= +github.com/sirupsen/logrus v1.10.1 h1:xi4336Zh11WpU14fXR6I67V3yaTPQYwRx2WEtHbRg4Q= +github.com/sirupsen/logrus v1.10.1/go.mod h1:vsQHnG7xzNsxk3NrwboUiWPnIC3dmbjcGPykD7+tiHk= github.com/sivchari/containedctx v1.0.3 h1:x+etemjbsh2fB5ewm5FeLNi5bUjK0V8n0RB+Wwfd0XE= github.com/sivchari/containedctx v1.0.3/go.mod h1:c1RDvCbnJLtH4lLcYD/GqwiBSSf4F5Qk0xld2rBqzJ4= -github.com/sonatard/noctx v0.4.0 h1:7MC/5Gg4SQ4lhLYR6mvOP6mQVSxCrdyiExo7atBs27o= -github.com/sonatard/noctx v0.4.0/go.mod h1:64XdbzFb18XL4LporKXp8poqZtPKbCrqQ402CV+kJas= -github.com/sourcegraph/go-diff v0.7.0 h1:9uLlrd5T46OXs5qpp8L/MTltk0zikUGi0sNNyCpA8G0= -github.com/sourcegraph/go-diff v0.7.0/go.mod h1:iBszgVvyxdc8SFZ7gm69go2KDdt3ag071iBaWPF6cjs= +github.com/sonatard/noctx v0.5.1 h1:wklWg9c9ZYugOAk7qG4yP4PBrlQsmSLPTvW1K4PRQMs= +github.com/sonatard/noctx v0.5.1/go.mod h1:64XdbzFb18XL4LporKXp8poqZtPKbCrqQ402CV+kJas= +github.com/sourcegraph/go-diff v0.8.0 h1:ipIyu4cTsLbIrln4l0qtHA3r0a7gyK4ntKjtQytHhvY= +github.com/sourcegraph/go-diff v0.8.0/go.mod h1:hWlcO7Al+UZStZAP8rBumHpCK5ZHQ5BXsMls8p4+F5E= github.com/spdx/tools-golang v0.5.7 h1:+sWcKGnhwp3vLdMqPcLdA6QK679vd86cK9hQWH3AwCg= github.com/spdx/tools-golang v0.5.7/go.mod h1:jg7w0LOpoNAw6OxKEzCoqPC2GCTj45LyTlVmXubDsYw= github.com/spf13/afero v1.15.0 h1:b/YBCLWAJdFWJTN9cLhiXXcD7mzKn9Dm86dNnfyQw1I= @@ -628,14 +643,14 @@ github.com/ssgreg/nlreturn/v2 v2.2.1/go.mod h1:E/iiPB78hV7Szg2YfRgyIrk1AD6JVMTRk github.com/stbenjam/no-sprintf-host-port v0.3.1 h1:AyX7+dxI4IdLBPtDbsGAyqiTSLpCP9hWRrXQDU4Cm/g= github.com/stbenjam/no-sprintf-host-port v0.3.1/go.mod h1:ODbZesTCHMVKthBHskvUUexdcNHAQRXk9NpSsL8p/HQ= github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME= -github.com/stretchr/objx v0.5.2 h1:xuMeJ0Sdp5ZMRXx/aWO6RZxdr3beISkG5/G/aIRr3pY= -github.com/stretchr/objx v0.5.2/go.mod h1:FRsXN1f5AsAjCGJKqEizvkpNtU+EGNCLh3NxZ/8L+MA= +github.com/stretchr/objx v0.5.3 h1:jmXUvGomnU1o3W/V5h2VEradbpJDwGrzugQQvL0POH4= +github.com/stretchr/objx v0.5.3/go.mod h1:rDQraq+vQZU7Fde9LOZLr8Tax6zZvy4kuNKF+QYS+U0= github.com/stretchr/testify v1.2.2/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs= github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI= github.com/stretchr/testify v1.4.0/go.mod h1:j7eGeouHqKxXV5pUuKE4zz7dFj8WfuZ+81PSLYec5m4= github.com/stretchr/testify v1.6.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg= -github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U= -github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U= +github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE= +github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg= github.com/subosito/gotenv v1.4.1 h1:jyEFiXpy21Wm81FBN71l9VoMMV8H8jG+qIK3GCpY6Qs= github.com/subosito/gotenv v1.4.1/go.mod h1:ayKnFf/c6rvx/2iiLrJUk1e6plDbT3edrFNGqEflhK0= github.com/swaggo/swag v1.16.6 h1:qBNcx53ZaX+M5dxVyTrgQ0PJ/ACK+NzhwcbieTt+9yI= @@ -646,10 +661,10 @@ github.com/tenntenn/text/transform v0.0.0-20200319021203-7eef512accb3 h1:f+jULpR github.com/tenntenn/text/transform v0.0.0-20200319021203-7eef512accb3/go.mod h1:ON8b8w4BN/kE1EOhwT0o+d62W65a6aPw1nouo9LMgyY= github.com/terminalstatic/go-xsd-validate v0.1.6 h1:TenYeQ3eY631qNi1/cTmLH/s2slHPRKTTHT+XSHkepo= github.com/terminalstatic/go-xsd-validate v0.1.6/go.mod h1:18lsvYFofBflqCrvo1umpABZ99+GneNTw2kEEc8UPJw= -github.com/tetafro/godot v1.5.4 h1:u1ww+gqpRLiIA16yF2PV1CV1n/X3zhyezbNXC3E14Sg= -github.com/tetafro/godot v1.5.4/go.mod h1:eOkMrVQurDui411nBY2FA05EYH01r14LuWY/NrVDVcU= -github.com/timakin/bodyclose v0.0.0-20241222091800-1db5c5ca4d67 h1:9LPGD+jzxMlnk5r6+hJnar67cgpDIz/iyD+rfl5r2Vk= -github.com/timakin/bodyclose v0.0.0-20241222091800-1db5c5ca4d67/go.mod h1:mkjARE7Yr8qU23YcGMSALbIxTQ9r9QBVahQOBRfU460= +github.com/tetafro/godot v1.5.6 h1:IEkrFCwXaYHlOn4mGzGS3F3dkP6m9t0jpwqBFPIkKiA= +github.com/tetafro/godot v1.5.6/go.mod h1:eOkMrVQurDui411nBY2FA05EYH01r14LuWY/NrVDVcU= +github.com/timakin/bodyclose v0.0.0-20260129054331-73d1f95b84b4 h1:SiHe5XLTn9sFWJ5pBwJ5FN/4j34q9ZlOAD//kMoMYp0= +github.com/timakin/bodyclose v0.0.0-20260129054331-73d1f95b84b4/go.mod h1:sDHLK7rb/59v/ZxZ7KtymgcoxuUMxjXq8gtu9VMOK8M= github.com/timonwong/loggercheck v0.11.0 h1:jdaMpYBl+Uq9mWPXv1r8jc5fC3gyXx4/WGwTnnNKn4M= github.com/timonwong/loggercheck v0.11.0/go.mod h1:HEAWU8djynujaAVX7QI65Myb8qgfcZ1uKbdpg3ZzKl8= github.com/tomarrell/wrapcheck/v2 v2.12.0 h1:H/qQ1aNWz/eeIhxKAFvkfIA+N7YDvq6TWVFL27Of9is= @@ -664,10 +679,10 @@ github.com/ultraware/whitespace v0.2.0 h1:TYowo2m9Nfj1baEQBjuHzvMRbp19i+RCcRYrSW github.com/ultraware/whitespace v0.2.0/go.mod h1:XcP1RLD81eV4BW8UhQlpaR+SDc2givTvyI8a586WjW8= github.com/urfave/cli/v2 v2.3.0 h1:qph92Y649prgesehzOrQjdWyxFOp/QVM+6imKHad91M= github.com/urfave/cli/v2 v2.3.0/go.mod h1:LJmUH05zAU44vOAcrfzZQKsZbVcdbOG8rtL3/XcUArI= -github.com/uudashr/gocognit v1.2.0 h1:3BU9aMr1xbhPlvJLSydKwdLN3tEUUrzPSSM8S4hDYRA= -github.com/uudashr/gocognit v1.2.0/go.mod h1:k/DdKPI6XBZO1q7HgoV2juESI2/Ofj9AcHPZhBBdrTU= -github.com/uudashr/iface v1.4.1 h1:J16Xl1wyNX9ofhpHmQ9h9gk5rnv2A6lX/2+APLTo0zU= -github.com/uudashr/iface v1.4.1/go.mod h1:pbeBPlbuU2qkNDn0mmfrxP2X+wjPMIQAy+r1MBXSXtg= +github.com/uudashr/gocognit v1.2.1 h1:CSJynt5txTnORn/DkhiB4mZjwPuifyASC8/6Q0I/QS4= +github.com/uudashr/gocognit v1.2.1/go.mod h1:acaubQc6xYlXFEMb9nWX2dYBzJ/bIjEkc1zzvyIZg5Q= +github.com/uudashr/iface v1.5.0 h1:PgdMt4uAettGG8K/Kbamc4B9FABgUgnS3TLbl6fnjEk= +github.com/uudashr/iface v1.5.0/go.mod h1:pbeBPlbuU2qkNDn0mmfrxP2X+wjPMIQAy+r1MBXSXtg= github.com/xeipuuv/gojsonpointer v0.0.0-20180127040702-4e3ac2762d5f h1:J9EGpcZtP0E/raorCMxlFGSTBrsSlaDGf3jU/qvAE2c= github.com/xeipuuv/gojsonpointer v0.0.0-20180127040702-4e3ac2762d5f/go.mod h1:N2zxlSyiKSe5eX1tZViRH5QA0qijqEDrYZiPEAiq3wU= github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 h1:EzJWgHovont7NscjpAxXsDA8S8BMYve8Y5+7cuRE7R0= @@ -687,7 +702,6 @@ github.com/ykadowak/zerologlint v0.1.5/go.mod h1:KaUskqF3e/v59oPmdq1U1DnKcuHokl2 github.com/yuin/goldmark v1.1.25/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= github.com/yuin/goldmark v1.1.32/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= github.com/yuin/goldmark v1.2.1/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= -github.com/yuin/goldmark v1.3.5/go.mod h1:mwnBkeHKe2W/ZEtQ+71ViKU8L12m81fl3OWwC1Zlc8k= github.com/yuin/goldmark v1.4.1/go.mod h1:mwnBkeHKe2W/ZEtQ+71ViKU8L12m81fl3OWwC1Zlc8k= github.com/yuin/goldmark v1.4.13/go.mod h1:6yULJ656Px+3vBD8DxQVa3kxgyrAnzto9xy5taEt/CY= gitlab.com/bosi/decorder v0.4.2 h1:qbQaV3zgwnBZ4zPMhGLW4KZe7A7NwxEhJx39R3shffo= @@ -696,20 +710,20 @@ go-simpler.org/assert v0.9.0 h1:PfpmcSvL7yAnWyChSjOz6Sp6m9j5lyK8Ok9pEL31YkQ= go-simpler.org/assert v0.9.0/go.mod h1:74Eqh5eI6vCK6Y5l3PI8ZYFXG4Sa+tkr70OIPJAUr28= go-simpler.org/musttag v0.14.0 h1:XGySZATqQYSEV3/YTy+iX+aofbZZllJaqwFWs+RTtSo= go-simpler.org/musttag v0.14.0/go.mod h1:uP8EymctQjJ4Z1kUnjX0u2l60WfUdQxCwSNKzE1JEOE= -go-simpler.org/sloglint v0.11.1 h1:xRbPepLT/MHPTCA6TS/wNfZrDzkGvCCqUv4Bdwc3H7s= -go-simpler.org/sloglint v0.11.1/go.mod h1:2PowwiCOK8mjiF+0KGifVOT8ZsCNiFzvfyJeJOIt8MQ= +go-simpler.org/sloglint v0.12.0 h1:UzWDlLWNE5FLqsvyq3tWYHuQMbqrervOhT8qPl4Mmw4= +go-simpler.org/sloglint v0.12.0/go.mod h1:jBjjC2bm8rYrs88oTRlFX497kWjJsyZWYoNaXkGRI6I= go.augendre.info/arangolint v0.4.0 h1:xSCZjRoS93nXazBSg5d0OGCi9APPLNMmmLrC995tR50= go.augendre.info/arangolint v0.4.0/go.mod h1:l+f/b4plABuFISuKnTGD4RioXiCCgghv2xqst/xOvAA= -go.augendre.info/fatcontext v0.9.0 h1:Gt5jGD4Zcj8CDMVzjOJITlSb9cEch54hjRRlN3qDojE= -go.augendre.info/fatcontext v0.9.0/go.mod h1:L94brOAT1OOUNue6ph/2HnwxoNlds9aXDF2FcUntbNw= +go.augendre.info/fatcontext v0.10.0 h1:HhFopmivh8U1+AU7f0kuwUeg2eiIns7YsGQOMHwSJ90= +go.augendre.info/fatcontext v0.10.0/go.mod h1:pqpGvA9GlrXy+aXkp8L2dKz12Zp4g2FhzcAtwToU+2w= go.opentelemetry.io/auto/sdk v1.2.1 h1:jXsnJ4Lmnqd11kwkBV2LgLoFMZKizbCi5fNZ/ipaZ64= go.opentelemetry.io/auto/sdk v1.2.1/go.mod h1:KRTj+aOaElaLi+wW1kO/DZRXwkF4C5xPbEe3ZiIhN7Y= go.opentelemetry.io/contrib/detectors/gcp v1.43.0 h1:62yY3dT7/ShwOxzA0RsKRgshBmfElKI4d/Myu2OxDFU= go.opentelemetry.io/contrib/detectors/gcp v1.43.0/go.mod h1:RyaZMFY7yi1kAs45S6mbFGz8O8rqB0dTY14uzvG4LCs= go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.67.0 h1:yI1/OhfEPy7J9eoa6Sj051C7n5dvpj0QX8g4sRchg04= go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.67.0/go.mod h1:NoUCKYWK+3ecatC4HjkRktREheMeEtrXoQxrqYFeHSc= -go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.67.0 h1:OyrsyzuttWTSur2qN/Lm0m2a8yqyIjUVBZcxFPuXq2o= -go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.67.0/go.mod h1:C2NGBr+kAB4bk3xtMXfZ94gqFDtg/GkI7e9zqGh5Beg= +go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0 h1:8tvICD4vSTOOsNrsI4Ljf6C+6UKvpTEH5XY3JMoyPoo= +go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0/go.mod h1:z9+yiacE0IHRqM4qFfkbt/JYlmYXgss8GY/jXoNuPJI= go.opentelemetry.io/otel v1.44.0 h1:JjwHmHpA4iZ3wBxluu2fbbE7j4kqlE8jXyAyPXH7HqU= go.opentelemetry.io/otel v1.44.0/go.mod h1:BMgjTHL9WPRlRjL2oZCBTL4whCGtXch2H4BhOPIAyYc= go.opentelemetry.io/otel/metric v1.44.0 h1:1w0gILTcHdr3YI+ixLyjemwrVnsMURbTZFrSYCdDdmc= @@ -730,51 +744,43 @@ go.uber.org/zap v1.27.1 h1:08RqriUEv8+ArZRYSTXy1LeBScaMpVSTBhCeaZYfMYc= go.uber.org/zap v1.27.1/go.mod h1:GB2qFLM7cTU87MWRP2mPIjqfIDnGu+VIO4V/SdhGo2E= go.yaml.in/yaml/v2 v2.4.4 h1:tuyd0P+2Ont/d6e2rl3be67goVK4R6deVxCUX5vyPaQ= go.yaml.in/yaml/v2 v2.4.4/go.mod h1:gMZqIpDtDqOfM0uNfy0SkpRhvUryYH0Z6wdMYcacYXQ= -go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc= go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg= +go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw= +go.yaml.in/yaml/v3 v3.0.5/go.mod h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg= gocloud.dev v0.46.0 h1:niIuZwSjMtBx8K+ITB2s5kZullB13PGOS2ZoQPZxQ4Q= gocloud.dev v0.46.0/go.mod h1:ACQe+2qO+hEO+pdcvvsM+RB63r8TyGD1W3ESCLFyzvM= golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w= golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI= golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto= golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc= -golang.org/x/crypto v0.13.0/go.mod h1:y6Z2r+Rw4iayiXXAIxJIDAJ1zMW4yaTpebo8fPOliYc= -golang.org/x/crypto v0.14.0/go.mod h1:MVFd36DqK4CsrnJYDkBA3VC4m2GkXAM0PvzMCn4JQf4= -golang.org/x/crypto v0.54.0 h1:YLIA59K4fiNzHzjnZt2tUJQjQtUWfWbeHBqKtk3eScw= -golang.org/x/crypto v0.54.0/go.mod h1:KWL8ny2AZdGR2cWmzeHrp2azQPGogOv+HeQaVEXC2dk= +golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M= +golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis= golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa h1:Zt3DZoOFFYkKhDT3v7Lm9FDMEV06GpzjG2jrqW+QTE0= golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa/go.mod h1:K79w1Vqn7PoiZn+TkNpx3BUWUQksGO3JcVX6qIjytmA= golang.org/x/exp/typeparams v0.0.0-20220428152302-39d4317da171/go.mod h1:AbB0pIl9nAr9wVwH+Z2ZpaocVmF5I4GyWCDIsVjR0bk= golang.org/x/exp/typeparams v0.0.0-20230203172020-98cc5a0785f9/go.mod h1:AbB0pIl9nAr9wVwH+Z2ZpaocVmF5I4GyWCDIsVjR0bk= -golang.org/x/exp/typeparams v0.0.0-20260209203927-2842357ff358 h1:qWFG1Dj7TBjOjOvhEOkmyGPVoquqUKnIU0lEVLp8xyk= -golang.org/x/exp/typeparams v0.0.0-20260209203927-2842357ff358/go.mod h1:4Mzdyp/6jzw9auFDJ3OMF5qksa7UvPnzKqTVGcb04ms= +golang.org/x/exp/typeparams v0.0.0-20260811152304-ee035b5b010f h1:+lI8cDJ4uceLipg2f1ODay7fEuLkk0BIHXd6PB8icxo= +golang.org/x/exp/typeparams v0.0.0-20260811152304-ee035b5b010f/go.mod h1:PqrXSW65cXDZH0k4IeUbhmg/bcAZDbzNz3byBpKCsXo= golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= golang.org/x/mod v0.4.1/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= -golang.org/x/mod v0.4.2/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= golang.org/x/mod v0.6.0-dev.0.20220106191415-9b9b3d81d5e3/go.mod h1:3p9vT2HGsQu2K1YbXdKPJLVgG5VJdoTa1poYQBtP1AY= golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4= golang.org/x/mod v0.8.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs= -golang.org/x/mod v0.12.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs= -golang.org/x/mod v0.13.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c= -golang.org/x/mod v0.37.0 h1:vF1DjpVEshcIqoEaauuHebaLk1O1forxjxBaVn884JQ= -golang.org/x/mod v0.37.0/go.mod h1:m8S8VeM9r4dzDwjrKO0a1sZP3YjeMamRRlD+fmR2Q/0= +golang.org/x/mod v0.40.0 h1:hUv+3cXcdRHz08UmSiOob7sadHig73uo5bkXxQ/tvUs= +golang.org/x/mod v0.40.0/go.mod h1:0/weTWkPWGBikyTWAX3dkjVztMmBA5hM0DH6BElSupE= golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg= golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= golang.org/x/net v0.0.0-20200625001655-4c5254603344/go.mod h1:/O7V0waA8r7cgGh81Ro3o1hOxt32SMVPicZroKQ2sZA= golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU= golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg= -golang.org/x/net v0.0.0-20210405180319-a5a99cb37ef4/go.mod h1:p54w0d4576C0XHj96bSt6lcn1PtDYWL6XObtHCRCNQM= golang.org/x/net v0.0.0-20210421230115-4e50805a0758/go.mod h1:72T/g9IO56b78aLF+1Kcs5dz7/ng1VjMUvfKvpfy+jM= golang.org/x/net v0.0.0-20211015210444-4f30a5c0130f/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y= golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c= golang.org/x/net v0.6.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs= -golang.org/x/net v0.10.0/go.mod h1:0qNGK6F8kojg2nk9dLZ2mShWaEBan6FAoqfSigmmuDg= -golang.org/x/net v0.15.0/go.mod h1:idbUs1IY1+zTqbi8yxTbhexhEEk5ur9LInksu6HrEpk= -golang.org/x/net v0.16.0/go.mod h1:NxSsAGuq816PNPmqtQdLE42eU2Fs7NoRIZrHJAlaCOE= -golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE= -golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU= +golang.org/x/net v0.58.0 h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To= +golang.org/x/net v0.58.0/go.mod h1:YwCddHnFlT7eLQqVprV19OnhLGtc5xOKgE0RyqgfWAU= golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs= golang.org/x/oauth2 v0.36.0/go.mod h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7Q= golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= @@ -784,8 +790,6 @@ golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJ golang.org/x/sync v0.0.0-20210220032951-036812b2e83c/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= golang.org/x/sync v0.1.0/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= -golang.org/x/sync v0.3.0/go.mod h1:FU7BRWz2tNW+3quACPkgCx/L+uEAv1htQ0V83Z9Rj+Y= -golang.org/x/sync v0.4.0/go.mod h1:FU7BRWz2tNW+3quACPkgCx/L+uEAv1htQ0V83Z9Rj+Y= golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek= golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0= golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= @@ -794,10 +798,8 @@ golang.org/x/sys v0.0.0-20200323222414-85ca7c5b95cd/go.mod h1:h1NjWce9XRLGQEsW7w golang.org/x/sys v0.0.0-20200930185726-fdedc70b468f/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= golang.org/x/sys v0.0.0-20210124154548-22da62e12c0c/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= -golang.org/x/sys v0.0.0-20210330210617-4fbd30eecc44/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= golang.org/x/sys v0.0.0-20210420072515-93ed5bcd2bfe/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= golang.org/x/sys v0.0.0-20210423082822-04245dca01da/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= -golang.org/x/sys v0.0.0-20210510120138-977fb7262007/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.0.0-20210615035016-665e8c7367d1/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.0.0-20211019181941-9d821ace8654/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.0.0-20211105183446-c75c47738b0c/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= @@ -805,27 +807,19 @@ golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a/go.mod h1:oPkhp1MJrh7nUepCBc golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.1.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.8.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.12.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.13.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs= golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo= golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8= golang.org/x/term v0.5.0/go.mod h1:jMB1sMXY+tzblOD4FWmEbocvup2/aLOaQEp7JmGp78k= -golang.org/x/term v0.8.0/go.mod h1:xPskH00ivmX89bAKVGSKKtLOWNx2+17Eiy94tnKShWo= -golang.org/x/term v0.12.0/go.mod h1:owVbMEjm3cBLCHdkQu9b1opXd4ETQWc3BhuQGKgXgvU= -golang.org/x/term v0.13.0/go.mod h1:LTmsnFJwVN6bCy1rVCoS+qHT1HhALEFxKncY3WNNh4U= golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ= golang.org/x/text v0.3.2/go.mod h1:bEr9sfX3Q8Zfm5fL9x+3itogRgK3+ptLWKqgva+5dAk= golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= golang.org/x/text v0.3.6/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ= golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8= -golang.org/x/text v0.9.0/go.mod h1:e1OnstbJyHTd6l/uOt8jFFHp6TRDWZR/bV3emEE/zU8= -golang.org/x/text v0.13.0/go.mod h1:TvPlkZtksWOMsz7fbANvkp4WM8x/WCo/om8BMLbz+aE= -golang.org/x/text v0.40.0 h1:Ub2Z6/xjgF1WrYQz2nuITOEegKFtiIy+rieRJ5lHZKs= -golang.org/x/text v0.40.0/go.mod h1:hpnzDAfGV753zIKo+wk3u1bVKCGPbrnF7+7LBF/UHVY= +golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8= +golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M= golang.org/x/time v0.15.0 h1:bbrp8t3bGUeFOx08pvsMYRTCVSMk89u4tKbNOZbp88U= golang.org/x/time v0.15.0/go.mod h1:Y4YMaQmXwGQZoFaVFk4YpCt4FLQMYKZe9oeV/f4MSno= golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= @@ -834,14 +828,11 @@ golang.org/x/tools v0.0.0-20200329025819-fd4102a86c65/go.mod h1:Sl4aGygMT6LrqrWc golang.org/x/tools v0.0.0-20200724022722-7017fd6b1305/go.mod h1:njjCfa9FT2d7l9Bc6FUM5FLjQPp3cFF28FI3qnDFljA= golang.org/x/tools v0.1.1-0.20210205202024-ef80cdb6ec6d/go.mod h1:9bzcO0MWcOuT0tm1iBGzDVPshzfwoVvREIui8C+MHqU= golang.org/x/tools v0.1.1-0.20210302220138-2ac05c832e1a/go.mod h1:9bzcO0MWcOuT0tm1iBGzDVPshzfwoVvREIui8C+MHqU= -golang.org/x/tools v0.1.1/go.mod h1:o0xws9oXOQQZyjljx8fwUC0k7L1pTE6eaCbjGeHmOkk= golang.org/x/tools v0.1.10/go.mod h1:Uh6Zz+xoGYZom868N8YTex3t7RhtHDBrE8Gzo9bV56E= golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc= golang.org/x/tools v0.6.0/go.mod h1:Xwgl3UAJ/d3gWutnCtw505GrjyAbvKui8lOU390QaIU= -golang.org/x/tools v0.13.0/go.mod h1:HvlwmtVNQAhOuCjW7xxvovg8wbNq7LwfXh/k7wXUl58= -golang.org/x/tools v0.14.0/go.mod h1:uYBEerGOWcJyEORxN+Ek8+TT266gXkNlHdJBwexUsBg= -golang.org/x/tools v0.47.0 h1:7Kn5x/d1svx/PzryTsqeoZN4TZwqeH5pGWjefhLi/1Q= -golang.org/x/tools v0.47.0/go.mod h1:dFHnyTvFWY212G+h7ZY4Vsp/K3U4/7W9TyVaAul8uCA= +golang.org/x/tools v0.49.0 h1:3NI7VXzL9+1WZD52Dx2ttoPwD5DWrFGpl9mFZDlmisI= +golang.org/x/tools v0.49.0/go.mod h1:SJNXV9DBKT0UbdttsQjbfJlAE/q+y36++zo3uL3N0Oo= golang.org/x/tools/go/expect v0.1.1-deprecated h1:jpBZDwmgPhXsKZC6WhL20P4b/wmnpsEAGHaNy0n/rJM= golang.org/x/tools/go/expect v0.1.1-deprecated/go.mod h1:eihoPOH+FgIqa3FpoTwguz/bVUSGBlGQU67vpBeOrBY= golang.org/x/tools/go/packages/packagestest v0.1.1-deprecated h1:1h2MnaIAIXISqTFKdENegdpAgUXz6NrPEsbIeWaBRvM= @@ -854,14 +845,14 @@ golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da h1:noIWHXmPHxILtqtCOPIhS golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da/go.mod h1:NDW/Ps6MPRej6fsCIbMTohpP40sJ/P/vI1MoTEGwX90= gonum.org/v1/gonum v0.17.0 h1:VbpOemQlsSMrYmn7T2OUvQ4dqxQXU+ouZFQsZOx50z4= gonum.org/v1/gonum v0.17.0/go.mod h1:El3tOrEuMpv2UdMrbNlKEh9vd86bmQ6vqIcDwxEOc1E= -google.golang.org/api v0.272.0 h1:eLUQZGnAS3OHn31URRf9sAmRk3w2JjMx37d2k8AjJmA= -google.golang.org/api v0.272.0/go.mod h1:wKjowi5LNJc5qarNvDCvNQBn3rVK8nSy6jg2SwRwzIA= -google.golang.org/genproto v0.0.0-20260316180232-0b37fe3546d5 h1:JNfk58HZ8lfmXbYK2vx/UvsqIL59TzByCxPIX4TDmsE= -google.golang.org/genproto v0.0.0-20260316180232-0b37fe3546d5/go.mod h1:x5julN69+ED4PcFk/XWayw35O0lf/nGa4aNgODCmNmw= -google.golang.org/genproto/googleapis/api v0.0.0-20260414002931-afd174a4e478 h1:yQugLulqltosq0B/f8l4w9VryjV+N/5gcW0jQ3N8Qec= -google.golang.org/genproto/googleapis/api v0.0.0-20260414002931-afd174a4e478/go.mod h1:C6ADNqOxbgdUUeRTU+LCHDPB9ttAMCTff6auwCVa4uc= -google.golang.org/genproto/googleapis/rpc v0.0.0-20260414002931-afd174a4e478 h1:RmoJA1ujG+/lRGNfUnOMfhCy5EipVMyvUE+KNbPbTlw= -google.golang.org/genproto/googleapis/rpc v0.0.0-20260414002931-afd174a4e478/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8= +google.golang.org/api v0.288.0 h1:glhO/J88obKP5I269W3hB73dvBKrjU56ZfmNlNXpgTU= +google.golang.org/api v0.288.0/go.mod h1:lM2kYRzYUCBY91P9h6VF1PYmvhxii3O5hji37qRvIcY= +google.golang.org/genproto v0.0.0-20260319201613-d00831a3d3e7 h1:XzmzkmB14QhVhgnawEVsOn6OFsnpyxNPRY9QV01dNB0= +google.golang.org/genproto v0.0.0-20260319201613-d00831a3d3e7/go.mod h1:L43LFes82YgSonw6iTXTxXUX1OlULt4AQtkik4ULL/I= +google.golang.org/genproto/googleapis/api v0.0.0-20260630182238-925bb5da69e7 h1:jQ9p21COKWjP3VwuFrNRiiOTMh3mPpN45R7SLrH/HUU= +google.golang.org/genproto/googleapis/api v0.0.0-20260630182238-925bb5da69e7/go.mod h1:KqHwBx2upmfa1XSi1WuRvC+2VGCLtooKkfmyvRbUmqA= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800 h1:qEHAMpSaUhtD0p3NbEEI83HwNGFxEwaSJ1G9PLnCBZE= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8= google.golang.org/grpc v1.82.1 h1:NnAxzGRA0677vCa4BUkOAnO5+FfQqVl9iUXeD0IqcGE= google.golang.org/grpc v1.82.1/go.mod h1:yzTZ1TB1Z3SG+LIYaI+WiE8D5+PZ3ArnrSp8zF3+/ZA= google.golang.org/protobuf v1.36.12 h1:pJOKDDOyeXErUroCihFAd5LQuwXBSpVnKGrj5o/fwxc= @@ -881,8 +872,8 @@ gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C gopkg.in/yaml.v3 v3.0.0-20200615113413-eeeca48fe776/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= -honnef.co/go/tools v0.7.0 h1:w6WUp1VbkqPEgLz4rkBzH/CSU6HkoqNLp6GstyTx3lU= -honnef.co/go/tools v0.7.0/go.mod h1:pm29oPxeP3P82ISxZDgIYeOaf9ta6Pi0EWvCFoLG2vc= +honnef.co/go/tools v0.8.0 h1:UacpzPr7D6i5BAjTkA7sNVcx4kIbhAZcQ4zYtKiXx68= +honnef.co/go/tools v0.8.0/go.mod h1:XA+OnlRA9EDh/ukGvXMNSZNKGwFQJ+5dER0ioUkOxks= modernc.org/cc/v4 v4.29.1 h1:MKgdCV3WykTSPqpVrnxdEDS0HEd2FHpKZDzxzU5LyeI= modernc.org/cc/v4 v4.29.1/go.mod h1:OnovgIhbbMXMu1aISnJ0wvVD1KnW+cAUJkIrAWh+kVI= modernc.org/ccgo/v4 v4.34.6 h1:sBgfIwyN0TQ9C5hwIeuqyeAKyMWnbvj2fvpF4L11uzU= @@ -911,9 +902,9 @@ modernc.org/strutil v1.2.1 h1:UneZBkQA+DX2Rp35KcM69cSsNES9ly8mQWD71HKlOA0= modernc.org/strutil v1.2.1/go.mod h1:EHkiggD70koQxjVdSBM3JKM7k6L0FbGE5eymy9i3B9A= modernc.org/token v1.1.0 h1:Xl7Ap9dKaEs5kLoOQeQmPWevfnk/DM5qcLcYlA8ys6Y= modernc.org/token v1.1.0/go.mod h1:UGzOrNV1mAFSEB63lOFHIpNRUVMvYTc6yu1SMY/XTDM= -mvdan.cc/gofumpt v0.9.2 h1:zsEMWL8SVKGHNztrx6uZrXdp7AX8r421Vvp23sz7ik4= -mvdan.cc/gofumpt v0.9.2/go.mod h1:iB7Hn+ai8lPvofHd9ZFGVg2GOr8sBUw1QUWjNbmIL/s= -mvdan.cc/unparam v0.0.0-20251027182757-5beb8c8f8f15 h1:ssMzja7PDPJV8FStj7hq9IKiuiKhgz9ErWw+m68e7DI= -mvdan.cc/unparam v0.0.0-20251027182757-5beb8c8f8f15/go.mod h1:4M5MMXl2kW6fivUT6yRGpLLPNfuGtU2Z0cPvFquGDYU= +mvdan.cc/gofumpt v0.11.0 h1:0H01XB95PnN2QgCSR9ELdZyTlJqNZ7181B0BTMh5VZc= +mvdan.cc/gofumpt v0.11.0/go.mod h1:BeT5wCsOJt6J9zT2MZIOGszjUHzFkn1/l9g6xAzqsXo= +mvdan.cc/unparam v0.0.0-20260818115549-3f964bcb5673 h1:dEE6li4OPIE54oojY2qaayFS1fSp17G14si0gXRxl0U= +mvdan.cc/unparam v0.0.0-20260818115549-3f964bcb5673/go.mod h1:62roFV3D3nYOWIXv3PfGO4UYEKAotz2WgLywT87ONd8= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/internal/accesslog/accesslog.go b/internal/accesslog/accesslog.go new file mode 100644 index 0000000..6a3cb01 --- /dev/null +++ b/internal/accesslog/accesslog.go @@ -0,0 +1,109 @@ +// Package accesslog writes proxy activity as JSON Lines. +package accesslog + +import ( + "context" + "encoding/json" + "fmt" + "net/url" + "os" + "sync" + "time" +) + +const ( + accessLogFileMode os.FileMode = 0o600 + + // EventRequest identifies the response sent by the proxy to a client. + EventRequest = "request" + // EventUpstream identifies one HTTP exchange with an upstream service. + EventUpstream = "upstream" +) + +type requestIDKey struct{} + +// Entry is one proxy activity record. +type Entry struct { + Time time.Time `json:"time"` + Event string `json:"event"` + RequestID string `json:"request_id,omitempty"` + Method string `json:"method"` + Path string `json:"path,omitempty"` + URL string `json:"url,omitempty"` + StatusCode int `json:"status_code,omitempty"` + DurationMS int64 `json:"duration_ms"` + RemoteAddr string `json:"remote_addr,omitempty"` + Error string `json:"error,omitempty"` +} + +// Logger appends complete JSON objects to a file, one per line. +type Logger struct { + mu sync.Mutex + file *os.File + encoder *json.Encoder +} + +// Open opens path for append, creating it with owner-only permissions when needed. +func Open(path string) (*Logger, error) { + file, err := os.OpenFile(path, os.O_APPEND|os.O_CREATE|os.O_WRONLY, accessLogFileMode) + if err != nil { + return nil, fmt.Errorf("opening access log: %w", err) + } + + return &Logger{ + file: file, + encoder: json.NewEncoder(file), + }, nil +} + +// Write appends an entry to the log. +func (l *Logger) Write(entry Entry) error { + if entry.Time.IsZero() { + entry.Time = time.Now().UTC() + } + + l.mu.Lock() + defer l.mu.Unlock() + + if err := l.encoder.Encode(entry); err != nil { + return fmt.Errorf("writing access log: %w", err) + } + return nil +} + +// Close closes the log file after any active writer finishes. +func (l *Logger) Close() error { + l.mu.Lock() + defer l.mu.Unlock() + + if err := l.file.Close(); err != nil { + return fmt.Errorf("closing access log: %w", err) + } + return nil +} + +// WithRequestID stores a proxy request ID in ctx. +func WithRequestID(ctx context.Context, requestID string) context.Context { + return context.WithValue(ctx, requestIDKey{}, requestID) +} + +// RequestID returns the proxy request ID stored in ctx. +func RequestID(ctx context.Context) string { + requestID, _ := ctx.Value(requestIDKey{}).(string) + return requestID +} + +// URLWithoutSecrets returns a URL without user information, query values, or fragments. +func URLWithoutSecrets(value *url.URL) string { + if value == nil { + return "" + } + + clean := *value + clean.User = nil + clean.RawQuery = "" + clean.ForceQuery = false + clean.Fragment = "" + clean.RawFragment = "" + return clean.String() +} diff --git a/internal/accesslog/accesslog_test.go b/internal/accesslog/accesslog_test.go new file mode 100644 index 0000000..4e53fa8 --- /dev/null +++ b/internal/accesslog/accesslog_test.go @@ -0,0 +1,91 @@ +package accesslog + +import ( + "bufio" + "context" + "encoding/json" + "net/url" + "os" + "path/filepath" + "sync" + "testing" +) + +func TestLoggerWritesJSONLines(t *testing.T) { + path := filepath.Join(t.TempDir(), "access.jsonl") + logger, err := Open(path) + if err != nil { + t.Fatal(err) + } + + const entries = 20 + var wg sync.WaitGroup + for range entries { + wg.Add(1) + go func() { + defer wg.Done() + if err := logger.Write(Entry{ + Event: EventUpstream, + RequestID: "request-id", + Method: "GET", + URL: "https://registry.example/packages/example", + StatusCode: 429, + }); err != nil { + t.Errorf("Write: %v", err) + } + }() + } + wg.Wait() + + if err := logger.Close(); err != nil { + t.Fatal(err) + } + + file, err := os.Open(path) + if err != nil { + t.Fatal(err) + } + defer func() { _ = file.Close() }() + + scanner := bufio.NewScanner(file) + count := 0 + for scanner.Scan() { + var entry Entry + if err := json.Unmarshal(scanner.Bytes(), &entry); err != nil { + t.Fatalf("line %d is not JSON: %v", count+1, err) + } + if entry.Time.IsZero() { + t.Errorf("line %d has no time", count+1) + } + if entry.StatusCode != 429 { + t.Errorf("line %d status_code = %d, want 429", count+1, entry.StatusCode) + } + count++ + } + if err := scanner.Err(); err != nil { + t.Fatal(err) + } + if count != entries { + t.Errorf("lines = %d, want %d", count, entries) + } +} + +func TestRequestID(t *testing.T) { + ctx := WithRequestID(context.Background(), "abc-123") + if got := RequestID(ctx); got != "abc-123" { + t.Errorf("RequestID = %q, want %q", got, "abc-123") + } +} + +func TestURLWithoutSecrets(t *testing.T) { + value, err := url.Parse("https://user:password@registry.example/package.tgz?token=secret#fragment") + if err != nil { + t.Fatal(err) + } + + got := URLWithoutSecrets(value) + want := "https://registry.example/package.tgz" + if got != want { + t.Errorf("URLWithoutSecrets = %q, want %q", got, want) + } +} diff --git a/internal/config/config.go b/internal/config/config.go index 31f8c26..a3dfbc6 100644 --- a/internal/config/config.go +++ b/internal/config/config.go @@ -91,6 +91,9 @@ type Config struct { // Log configures logging. Log LogConfig `json:"log" yaml:"log"` + // AccessLog configures the JSONL activity log. + AccessLog AccessLogConfig `json:"access_log" yaml:"access_log"` + // Upstream configures upstream registry URLs (optional overrides). Upstream UpstreamConfig `json:"upstream" yaml:"upstream"` @@ -280,6 +283,12 @@ type LogConfig struct { Format string `json:"format" yaml:"format"` } +// AccessLogConfig configures the JSONL activity log. +type AccessLogConfig struct { + // Path is the file to append activity records to. Empty disables the access log. + Path string `json:"path" yaml:"path"` +} + // UpstreamConfig configures upstream registry URLs and authentication. // Leave empty to use defaults. type UpstreamConfig struct { @@ -309,6 +318,16 @@ type UpstreamConfig struct { // Default: http://deb.debian.org/debian Debian string `json:"debian" yaml:"debian"` + // Helm maps repository names to HTTP Helm chart repository URLs. + // Requests use /helm/{name}/index.yaml and chart URLs in the index are + // rewritten to the same named proxy endpoint. + Helm map[string]string `json:"helm" yaml:"helm"` + + // OCI maps names to OCI registry URLs. Requests to a named registry use + // the repository prefix upstream/{name}/, for example + // oci://proxy.example.com/upstream/ghcr/owner/chart. + OCI map[string]string `json:"oci" yaml:"oci"` + // Auth configures authentication for upstream registries. // Keys are absolute URL scopes matched by scheme, host, effective port, // and path-segment prefix. @@ -349,6 +368,24 @@ func (u *UpstreamConfig) Validate() error { return fmt.Errorf("invalid upstream.auth URL %q: %w", pattern, err) } } + if err := validateNamedUpstreams("upstream.helm", u.Helm); err != nil { + return err + } + if err := validateNamedUpstreams("upstream.oci", u.OCI); err != nil { + return err + } + return nil +} + +func validateNamedUpstreams(field string, upstreams map[string]string) error { + for name, upstreamURL := range upstreams { + if name == "" || name == "." || name == ".." || strings.ContainsAny(name, `/\\`) { + return fmt.Errorf("invalid %s name %q", field, name) + } + if err := validateAbsoluteURL(field+"."+name, upstreamURL); err != nil { + return err + } + } return nil } @@ -508,6 +545,7 @@ func setEnvBool(dst *bool, key string) { // - PROXY_DATABASE_PATH // - PROXY_LOG_LEVEL // - PROXY_LOG_FORMAT +// - PROXY_ACCESS_LOG_PATH // - PROXY_HEALTH_STORAGE_PROBE_INTERVAL func (c *Config) LoadFromEnv() { setEnvString(&c.Listen, "PROXY_LISTEN") @@ -524,6 +562,7 @@ func (c *Config) LoadFromEnv() { setEnvString(&c.Database.URL, "PROXY_DATABASE_URL") setEnvString(&c.Log.Level, "PROXY_LOG_LEVEL") setEnvString(&c.Log.Format, "PROXY_LOG_FORMAT") + setEnvString(&c.AccessLog.Path, "PROXY_ACCESS_LOG_PATH") setEnvString(&c.Upstream.Maven, "PROXY_UPSTREAM_MAVEN") setEnvString(&c.Upstream.GradlePluginPortal, "PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL") setEnvString(&c.Upstream.Debian, "PROXY_UPSTREAM_DEBIAN") @@ -889,8 +928,7 @@ func ParseSize(s string) (int64, error) { } for _, s2 := range suffixes { - if strings.HasSuffix(s, s2.suffix) { - numStr := strings.TrimSuffix(s, s2.suffix) + if numStr, ok := strings.CutSuffix(s, s2.suffix); ok { num, err := strconv.ParseFloat(numStr, 64) if err != nil { return 0, fmt.Errorf("invalid number %q", numStr) diff --git a/internal/config/config_test.go b/internal/config/config_test.go index e4677c3..0ccc308 100644 --- a/internal/config/config_test.go +++ b/internal/config/config_test.go @@ -26,6 +26,9 @@ func TestDefault(t *testing.T) { if cfg.Database.Path == "" { t.Error("Database.Path should not be empty") } + if cfg.AccessLog.Path != "" { + t.Errorf("AccessLog.Path = %q, want disabled by default", cfg.AccessLog.Path) + } if cfg.Gradle.BuildCache.MaxUploadSize != "100MB" { t.Errorf("Gradle.BuildCache.MaxUploadSize = %q, want %q", cfg.Gradle.BuildCache.MaxUploadSize, "100MB") } @@ -212,6 +215,8 @@ database: log: level: "debug" format: "json" +access_log: + path: "/var/log/proxy/access.jsonl" ` if err := os.WriteFile(path, []byte(content), 0644); err != nil { t.Fatalf("writing config file: %v", err) @@ -240,6 +245,9 @@ log: if cfg.Log.Format != "json" { t.Errorf("Log.Format = %q, want %q", cfg.Log.Format, "json") } + if cfg.AccessLog.Path != "/var/log/proxy/access.jsonl" { + t.Errorf("AccessLog.Path = %q, want %q", cfg.AccessLog.Path, "/var/log/proxy/access.jsonl") + } } func TestLoadJSON(t *testing.T) { @@ -275,6 +283,7 @@ func TestLoadFromEnv(t *testing.T) { t.Setenv("PROXY_UI_URL", "https://ui.env.example.com/ui") t.Setenv("PROXY_STORAGE_PATH", "/env/cache") t.Setenv("PROXY_LOG_LEVEL", testLevelDebug) + t.Setenv("PROXY_ACCESS_LOG_PATH", "/tmp/proxy-access.jsonl") t.Setenv("PROXY_UPSTREAM_MAVEN", "https://maven.example.com/repository/maven-public") t.Setenv("PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL", "https://plugins.example.com/m2") t.Setenv("PROXY_UPSTREAM_DEBIAN", "http://archive.ubuntu.com/ubuntu") @@ -301,6 +310,9 @@ func TestLoadFromEnv(t *testing.T) { if cfg.Log.Level != testLevelDebug { t.Errorf("Log.Level = %q, want %q", cfg.Log.Level, testLevelDebug) } + if cfg.AccessLog.Path != "/tmp/proxy-access.jsonl" { + t.Errorf("AccessLog.Path = %q, want %q", cfg.AccessLog.Path, "/tmp/proxy-access.jsonl") + } if cfg.Upstream.Maven != "https://maven.example.com/repository/maven-public" { t.Errorf("Upstream.Maven = %q, want %q", cfg.Upstream.Maven, "https://maven.example.com/repository/maven-public") } @@ -866,3 +878,44 @@ func TestValidateUpstreamAuthURLs(t *testing.T) { } }) } + +func TestValidateNamedUpstreams(t *testing.T) { + tests := []struct { + name string + modify func(*Config) + wantErr bool + }{ + { + name: "valid Helm and OCI upstreams", + modify: func(cfg *Config) { + cfg.Upstream.Helm = map[string]string{"bitnami": "https://charts.bitnami.com/bitnami"} + cfg.Upstream.OCI = map[string]string{"ghcr": "https://ghcr.io"} + }, + }, + { + name: "Helm upstream name contains path separator", + modify: func(cfg *Config) { + cfg.Upstream.Helm = map[string]string{"team/charts": "https://charts.example.com"} + }, + wantErr: true, + }, + { + name: "OCI upstream URL is not absolute", + modify: func(cfg *Config) { + cfg.Upstream.OCI = map[string]string{"private": "registry.example.com"} + }, + wantErr: true, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + cfg := Default() + tt.modify(cfg) + err := cfg.Validate() + if (err != nil) != tt.wantErr { + t.Errorf("Validate() error = %v, wantErr %t", err, tt.wantErr) + } + }) + } +} diff --git a/internal/database/database_test.go b/internal/database/database_test.go index 3e92b91..bb2b195 100644 --- a/internal/database/database_test.go +++ b/internal/database/database_test.go @@ -8,6 +8,11 @@ import ( "time" ) +const ( + testContentHash = "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + testIntegrity = "sha512-z4PhNX7vuL3xVChQ1m2AB9Yg5AULVxXcg/SpIdNs6c5H0NE8XYXysP+DGNKHfuwvY7kxvUdBeoGlODJ6+SfaPg==" +) + func TestCreateAndOpen(t *testing.T) { dir := t.TempDir() dbPath := filepath.Join(dir, "test.db") @@ -132,7 +137,7 @@ func TestVersionCRUD(t *testing.T) { v := &Version{ PURL: "pkg:npm/lodash@4.17.21", PackagePURL: "pkg:npm/lodash", - Integrity: sql.NullString{String: "sha512-abc123", Valid: true}, + Integrity: sql.NullString{String: testIntegrity, Valid: true}, } err = db.UpsertVersion(v) @@ -200,7 +205,7 @@ func TestArtifactCRUD(t *testing.T) { t.Error("expected artifact to not be cached yet") } - err = db.MarkArtifactCached(versionPURL, "lodash-4.17.21.tgz", "/cache/npm/lodash-4.17.21.tgz", "sha256-abc", 12345, "application/gzip") + err = db.MarkArtifactCached(versionPURL, "lodash-4.17.21.tgz", "/cache/npm/lodash-4.17.21.tgz", testContentHash, 12345, "application/gzip") if err != nil { t.Fatalf("MarkArtifactCached failed: %v", err) } @@ -257,7 +262,7 @@ func TestGetCachedArtifact(t *testing.T) { } if err := db.MarkArtifactCached(versionPURL, filename, "/cache/npm/"+filename, - "sha256-abc", 12345, "application/gzip"); err != nil { + testContentHash, 12345, "application/gzip"); err != nil { t.Fatalf("MarkArtifactCached failed: %v", err) } @@ -274,7 +279,7 @@ func TestGetCachedArtifact(t *testing.T) { if cached.StoragePath != "/cache/npm/"+filename { t.Errorf("expected cached storage path, got %q", cached.StoragePath) } - if cached.ContentHash.String != "sha256-abc" { + if cached.ContentHash.String != testContentHash { t.Errorf("expected cached content hash, got %q", cached.ContentHash.String) } if cached.Size.Int64 != 12345 { @@ -283,7 +288,7 @@ func TestGetCachedArtifact(t *testing.T) { if cached.ContentType.String != "application/gzip" { t.Errorf("expected cached content type, got %q", cached.ContentType.String) } - if cached.Integrity.String != "sha512-abc123" { + if cached.Integrity.String != testIntegrity { t.Errorf("expected cached integrity, got %q", cached.Integrity.String) } @@ -306,7 +311,7 @@ func seedCachedArtifactTestData(t *testing.T, db *DB, packagePURL, versionPURL, if err := db.UpsertVersion(&Version{ PURL: versionPURL, PackagePURL: packagePURL, - Integrity: sql.NullString{String: "sha512-abc123", Valid: true}, + Integrity: sql.NullString{String: testIntegrity, Valid: true}, }); err != nil { t.Fatalf("UpsertVersion failed: %v", err) } diff --git a/internal/enrichment/enrichment.go b/internal/enrichment/enrichment.go index 247dd2b..6b09db9 100644 --- a/internal/enrichment/enrichment.go +++ b/internal/enrichment/enrichment.go @@ -201,43 +201,6 @@ func (s *Service) CheckVulnerabilities(ctx context.Context, ecosystem, name, ver return results, nil } -// BulkCheckVulnerabilities queries vulnerabilities for multiple package versions. -func (s *Service) BulkCheckVulnerabilities(ctx context.Context, packages []struct{ Ecosystem, Name, Version string }) (map[string][]VulnInfo, error) { - purls := make([]*purl.PURL, len(packages)) - for i, pkg := range packages { - purls[i] = purl.MakePURL(pkg.Ecosystem, pkg.Name, pkg.Version) - } - - vulnResults, err := s.vulnSource.QueryBatch(ctx, purls) - if err != nil { - return nil, err - } - - result := make(map[string][]VulnInfo, len(packages)) - for i, vulnList := range vulnResults { - pkg := packages[i] - key := purl.MakePURLString(pkg.Ecosystem, pkg.Name, pkg.Version) - - var infos []VulnInfo - for _, v := range vulnList { - info := VulnInfo{ - ID: v.ID, - Summary: v.Summary, - Severity: v.SeverityLevel(), - CVSSScore: v.CVSSScore(), - FixedVersion: v.FixedVersion(pkg.Ecosystem, pkg.Name), - } - for _, ref := range v.References { - info.References = append(info.References, ref.URL) - } - infos = append(infos, info) - } - result[key] = infos - } - - return result, nil -} - // IsOutdated checks if a version is older than the latest version. func (s *Service) IsOutdated(currentVersion, latestVersion string) bool { if latestVersion == "" || currentVersion == "" { @@ -288,19 +251,6 @@ func (s *Service) CategorizeLicense(license string) LicenseCategory { return LicenseUnknown } -// NormalizeLicense normalizes a license string to SPDX format. -func (s *Service) NormalizeLicense(license string) string { - if license == "" { - return "" - } - - if normalized, err := spdx.NormalizeExpressionLax(license); err == nil { - return normalized - } - - return license -} - // EnrichmentResult contains all enrichment data for a package version. type EnrichmentResult struct { Package *PackageInfo diff --git a/internal/enrichment/enrichment_test.go b/internal/enrichment/enrichment_test.go index aa9a16e..e6a6dde 100644 --- a/internal/enrichment/enrichment_test.go +++ b/internal/enrichment/enrichment_test.go @@ -74,25 +74,3 @@ func TestCategorizeLicense(t *testing.T) { } } } - -func TestNormalizeLicense(t *testing.T) { - logger := slog.New(slog.NewTextHandler(os.Stdout, nil)) - svc := New(logger) - - tests := []struct { - input string - expected string - }{ - {"MIT", "MIT"}, - {"Apache 2", "Apache-2.0"}, - {"Apache-2.0", "Apache-2.0"}, - {"", ""}, - } - - for _, tc := range tests { - result := svc.NormalizeLicense(tc.input) - if result != tc.expected { - t.Errorf("NormalizeLicense(%q) = %q, want %q", tc.input, result, tc.expected) - } - } -} diff --git a/internal/handler/container.go b/internal/handler/container.go index 3a3b267..74819dd 100644 --- a/internal/handler/container.go +++ b/internal/handler/container.go @@ -11,28 +11,40 @@ import ( ) const ( - dockerHubRegistry = "https://registry-1.docker.io" - blobMatchCount = 3 // full match + name + digest - manifestMatchCount = 3 // full match + name + reference - tagsListMatchCount = 2 // full match + name + dockerHubRegistry = "https://registry-1.docker.io" + blobMatchCount = 3 // full match + name + digest + manifestMatchCount = 3 // full match + name + reference + tagsListMatchCount = 2 // full match + name + registrySelectorParts = 3 // upstream + name + repository ) // ContainerHandler handles OCI/Docker container registry protocol requests. // It implements the OCI Distribution Spec for pulling images. // Reference: https://github.com/opencontainers/distribution-spec/blob/main/spec.md type ContainerHandler struct { - proxy *Proxy - registryURL string - proxyURL string + proxy *Proxy + registryURL string + proxyURL string + namedRegistries map[string]string } // NewContainerHandler creates a new container registry protocol handler. -func NewContainerHandler(proxy *Proxy, proxyURL string) *ContainerHandler { - return &ContainerHandler{ +// Named registries are selected with the repository prefix +// upstream/{name}/, leaving unprefixed requests compatible with the Docker Hub +// mirror behavior. +func NewContainerHandler(proxy *Proxy, proxyURL string, namedRegistries ...map[string]string) *ContainerHandler { + h := &ContainerHandler{ proxy: proxy, registryURL: dockerHubRegistry, proxyURL: strings.TrimSuffix(proxyURL, "/"), } + if len(namedRegistries) > 0 { + h.namedRegistries = make(map[string]string, len(namedRegistries[0])) + for name, registryURL := range namedRegistries[0] { + h.namedRegistries[name] = strings.TrimSuffix(registryURL, "/") + } + } + return h } // Routes returns the HTTP handler for container registry requests. @@ -85,10 +97,16 @@ func (h *ContainerHandler) handleBlobDownload(w http.ResponseWriter, r *http.Req return } - h.proxy.Logger.Info("container blob request", "name", name, "digest", digest) + registryURL, upstreamName, cacheName, ok := h.registryForName(name) + if !ok { + h.containerError(w, http.StatusNotFound, "NAME_UNKNOWN", "unknown upstream registry") + return + } + + h.proxy.Logger.Info("container blob request", "name", upstreamName, "digest", digest) filename := digest - cached, err := h.proxy.GetCachedArtifact(r.Context(), "oci", name, digest, filename) + cached, err := h.proxy.GetCachedArtifact(r.Context(), "oci", cacheName, digest, filename) if err != nil { h.proxy.Logger.Error("failed to check blob cache", "error", err) h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to check blob cache") @@ -96,14 +114,18 @@ func (h *ContainerHandler) handleBlobDownload(w http.ResponseWriter, r *http.Req } if cached != nil { w.Header().Set("Docker-Content-Digest", digest) - w.Header().Set("Content-Type", "application/octet-stream") + if cached.ContentType != "" { + w.Header().Set("Content-Type", cached.ContentType) + } else { + w.Header().Set("Content-Type", "application/octet-stream") + } serveArtifact(w, r.Method, cached) return } // For HEAD requests, just proxy to upstream if r.Method == http.MethodHead { - h.proxyBlobHead(w, r, name, digest) + h.proxyBlobHead(w, r, registryURL, upstreamName, digest) return } @@ -111,10 +133,10 @@ func (h *ContainerHandler) handleBlobDownload(w http.ResponseWriter, r *http.Req result, err := h.proxy.GetOrFetchArtifactFromURL( r.Context(), "oci", - name, + cacheName, digest, // use digest as version filename, - fmt.Sprintf("%s/v2/%s/blobs/%s", h.registryURL, name, digest), + fmt.Sprintf("%s/v2/%s/blobs/%s", registryURL, upstreamName, digest), ) if err != nil { @@ -128,7 +150,11 @@ func (h *ContainerHandler) handleBlobDownload(w http.ResponseWriter, r *http.Req } w.Header().Set("Docker-Content-Digest", digest) - w.Header().Set("Content-Type", "application/octet-stream") + if result.ContentType != "" { + w.Header().Set("Content-Type", result.ContentType) + } else { + w.Header().Set("Content-Type", "application/octet-stream") + } ServeArtifact(w, result) } @@ -146,8 +172,14 @@ func (h *ContainerHandler) handleManifest(w http.ResponseWriter, r *http.Request return } - h.proxy.Logger.Info("container manifest request", "name", name, "reference", reference) - h.serveManifest(w, r, name, reference) + registryURL, upstreamName, _, ok := h.registryForName(name) + if !ok { + h.containerError(w, http.StatusNotFound, "NAME_UNKNOWN", "unknown upstream registry") + return + } + + h.proxy.Logger.Info("container manifest request", "name", upstreamName, "reference", reference) + h.serveManifest(w, r, registryURL, upstreamName, reference) } // handleTagsList proxies tag list requests to upstream. @@ -163,7 +195,13 @@ func (h *ContainerHandler) handleTagsList(w http.ResponseWriter, r *http.Request return } - upstreamURL := fmt.Sprintf("%s/v2/%s/tags/list", h.registryURL, name) + registryURL, upstreamName, _, ok := h.registryForName(name) + if !ok { + h.containerError(w, http.StatusNotFound, "NAME_UNKNOWN", "unknown upstream registry") + return + } + + upstreamURL := fmt.Sprintf("%s/v2/%s/tags/list", registryURL, upstreamName) if r.URL.RawQuery != "" { upstreamURL += "?" + r.URL.RawQuery } @@ -187,8 +225,8 @@ func (h *ContainerHandler) handleTagsList(w http.ResponseWriter, r *http.Request } // proxyBlobHead handles HEAD requests for blobs. -func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request, name, digest string) { - upstreamURL := fmt.Sprintf("%s/v2/%s/blobs/%s", h.registryURL, name, digest) +func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request, registryURL, name, digest string) { + upstreamURL := fmt.Sprintf("%s/v2/%s/blobs/%s", registryURL, name, digest) req, err := http.NewRequestWithContext(r.Context(), http.MethodHead, upstreamURL, nil) if err != nil { @@ -212,6 +250,24 @@ func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request, w.WriteHeader(resp.StatusCode) } +// registryForName resolves a client-visible OCI repository name to an upstream +// registry and its repository name. Named upstreams use upstream/{name}/ as a +// reserved prefix; all other names continue to target Docker Hub. +func (h *ContainerHandler) registryForName(name string) (registryURL, upstreamName, cacheName string, ok bool) { + parts := strings.SplitN(name, "/", registrySelectorParts) + if len(parts) >= 2 && parts[0] == "upstream" { + if len(parts) != registrySelectorParts || parts[2] == "" { + return "", "", "", false + } + registryURL, ok = h.namedRegistries[parts[1]] + if !ok || registryURL == "" { + return "", "", "", false + } + return registryURL, parts[2], name, true + } + return h.registryURL, name, name, true +} + // containerError writes an OCI-compliant error response. func (h *ContainerHandler) containerError(w http.ResponseWriter, status int, code, message string) { w.Header().Set("Content-Type", "application/json") diff --git a/internal/handler/container_manifest.go b/internal/handler/container_manifest.go index 245ced4..cf058ba 100644 --- a/internal/handler/container_manifest.go +++ b/internal/handler/container_manifest.go @@ -33,9 +33,9 @@ type cachedContainerManifest struct { fetchedAt time.Time } -func (h *ContainerHandler) serveManifest(w http.ResponseWriter, r *http.Request, name, reference string) { +func (h *ContainerHandler) serveManifest(w http.ResponseWriter, r *http.Request, registryURL, name, reference string) { accept := containerManifestAccept(r) - cacheKey := h.containerManifestCacheKey(name, reference, accept) + cacheKey := h.containerManifestCacheKey(registryURL, name, reference, accept) cached, err := h.loadContainerManifest(r.Context(), cacheKey) if err != nil { h.proxy.Logger.Warn("failed to read cached container manifest", "error", err) @@ -48,7 +48,7 @@ func (h *ContainerHandler) serveManifest(w http.ResponseWriter, r *http.Request, return } - upstreamURL := fmt.Sprintf("%s/v2/%s/manifests/%s", h.registryURL, name, reference) + upstreamURL := fmt.Sprintf("%s/v2/%s/manifests/%s", registryURL, name, reference) req, err := http.NewRequestWithContext(r.Context(), r.Method, upstreamURL, nil) if err != nil { h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create request") @@ -111,7 +111,7 @@ func (h *ContainerHandler) serveManifest(w http.ResponseWriter, r *http.Request, h.proxy.Logger.Warn("failed to cache container manifest", "error", err) } if manifest.contentDigest != reference && manifestDigestReferencePattern.MatchString(manifest.contentDigest) { - digestKey := h.containerManifestCacheKey(name, manifest.contentDigest, accept) + digestKey := h.containerManifestCacheKey(registryURL, name, manifest.contentDigest, accept) if err := h.storeContainerManifest(r.Context(), digestKey, manifest); err != nil { h.proxy.Logger.Warn("failed to cache container manifest by digest", "error", err) } @@ -133,8 +133,8 @@ func (h *ContainerHandler) containerManifestFresh(manifest *cachedContainerManif return h.proxy.MetadataTTL > 0 && !manifest.fetchedAt.IsZero() && time.Since(manifest.fetchedAt) < h.proxy.MetadataTTL } -func (h *ContainerHandler) containerManifestCacheKey(name, reference, accept string) string { - identity := strings.Join([]string{h.registryURL, name, reference, accept}, "\x00") +func (h *ContainerHandler) containerManifestCacheKey(registryURL, name, reference, accept string) string { + identity := strings.Join([]string{registryURL, name, reference, accept}, "\x00") sum := sha256.Sum256([]byte(identity)) return hex.EncodeToString(sum[:]) } diff --git a/internal/handler/container_test.go b/internal/handler/container_test.go index 6e7322c..04f00a7 100644 --- a/internal/handler/container_test.go +++ b/internal/handler/container_test.go @@ -134,6 +134,52 @@ func TestContainerHandler_parseTagsListPath(t *testing.T) { } } +func TestContainerHandler_NamedOCIRegistryServesHelmArtifacts(t *testing.T) { + digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd" + manifest := `{"schemaVersion":2,"config":{"mediaType":"application/vnd.cncf.helm.config.v1+json"},"layers":[{"mediaType":"application/vnd.cncf.helm.chart.content.v1.tar+gzip","digest":"` + digest + `"}]}` + upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + switch r.URL.Path { + case "/v2/owner/demo/manifests/1.0.0": + w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json") + w.Header().Set("Docker-Content-Digest", digest) + _, _ = io.WriteString(w, manifest) + case "/v2/owner/demo/blobs/" + digest: + w.Header().Set("Content-Type", "application/vnd.cncf.helm.chart.content.v1.tar+gzip") + _, _ = io.WriteString(w, "chart archive") + default: + http.NotFound(w, r) + } + })) + defer upstream.Close() + + proxy, _, _, _ := setupTestProxy(t) + proxy.HTTPClient = upstream.Client() + fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0)) + proxy.Fetcher = fetcher + t.Cleanup(func() { _ = fetcher.Close() }) + h := NewContainerHandler(proxy, "http://proxy.example", map[string]string{"ghcr": upstream.URL}) + + manifestResponse := httptest.NewRecorder() + h.Routes().ServeHTTP(manifestResponse, + httptest.NewRequest(http.MethodGet, "/upstream/ghcr/owner/demo/manifests/1.0.0", nil)) + if manifestResponse.Code != http.StatusOK { + t.Fatalf("manifest status = %d, want 200: %s", manifestResponse.Code, manifestResponse.Body.String()) + } + if got := manifestResponse.Header().Get("Content-Type"); got != "application/vnd.oci.image.manifest.v1+json" { + t.Errorf("manifest Content-Type = %q", got) + } + + blobResponse := httptest.NewRecorder() + h.Routes().ServeHTTP(blobResponse, + httptest.NewRequest(http.MethodGet, "/upstream/ghcr/owner/demo/blobs/"+digest, nil)) + if blobResponse.Code != http.StatusOK { + t.Fatalf("blob status = %d, want 200: %s", blobResponse.Code, blobResponse.Body.String()) + } + if got := blobResponse.Header().Get("Content-Type"); got != "application/vnd.cncf.helm.chart.content.v1.tar+gzip" { + t.Errorf("blob Content-Type = %q", got) + } +} + func TestContainerHandler_BlobDownload_DiscoversBearerChallenge(t *testing.T) { digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd" registryRequests := 0 @@ -436,8 +482,9 @@ func TestContainerHandler_BlobHead_DirectServeRedirects(t *testing.T) { if got := w.Header().Get("Location"); got != store.signedURL { t.Errorf("Location = %q, want %q", got, store.signedURL) } - if got := w.Header().Get("ETag"); got != `"abc123"` { - t.Errorf("ETag = %q, want %q", got, `"abc123"`) + wantETag := `"` + sha256Hex("cached blob") + `"` + if got := w.Header().Get("ETag"); got != wantETag { + t.Errorf("ETag = %q, want %q", got, wantETag) } if w.Body.Len() != 0 { t.Errorf("HEAD response body length = %d, want 0", w.Body.Len()) diff --git a/internal/handler/download_test.go b/internal/handler/download_test.go index 8192eeb..dda3e84 100644 --- a/internal/handler/download_test.go +++ b/internal/handler/download_test.go @@ -49,7 +49,7 @@ func seedPackageWithPURL(t *testing.T, db *database.DB, store *mockStorage, ecos Filename: filename, UpstreamURL: "https://example.com/" + filename, StoragePath: sql.NullString{String: storagePath, Valid: true}, - ContentHash: sql.NullString{String: "abc123", Valid: true}, + ContentHash: sql.NullString{String: sha256Hex(content), Valid: true}, Size: sql.NullInt64{Int64: int64(len(content)), Valid: true}, ContentType: sql.NullString{String: "application/octet-stream", Valid: true}, FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, diff --git a/internal/handler/handler.go b/internal/handler/handler.go index 6a7aab4..6c65682 100644 --- a/internal/handler/handler.go +++ b/internal/handler/handler.go @@ -61,9 +61,7 @@ var artifactCopyBufferPool = sync.Pool{ //nolint:gochecknoglobals // shared acro // canonicalPackagePURL returns a versionless PURL in canonical form so cooldown // lookups match keys produced by config.CooldownConfig.NormalizedPackages. func canonicalPackagePURL(ecosystem, name string) string { - p := purl.MakePURL(ecosystem, name, "") - _ = p.Normalize() - return p.String() + return purl.MakePURLString(ecosystem, name, "") } const contentTypeJSON = "application/json" @@ -151,6 +149,7 @@ func (p *Proxy) GetOrFetchArtifact(ctx context.Context, ecosystem, name, version } else if cached != nil { return cached, nil } + metrics.RecordCacheMiss(ecosystem) pkgPURL := purl.MakePURLString(ecosystem, name, "") versionPURL := purl.MakePURLString(ecosystem, name, version) @@ -165,6 +164,27 @@ func (p *Proxy) GetCachedArtifact(ctx context.Context, ecosystem, name, version, return p.checkCache(ctx, pkgPURL, versionPURL, filename) } +// ClearCachedArtifact removes both an artifact cache record and its stored +// bytes after an external integrity check fails. +func (p *Proxy) ClearCachedArtifact(ctx context.Context, ecosystem, name, version, filename string) error { + if p.DB == nil || p.Storage == nil { + return nil + } + pkgPURL := purl.MakePURLString(ecosystem, name, "") + versionPURL := purl.MakePURLString(ecosystem, name, version) + cached, err := p.DB.GetCachedArtifact(pkgPURL, versionPURL, filename) + if err != nil { + return fmt.Errorf("looking up cached artifact: %w", err) + } + if cached == nil { + return nil + } + if err := p.Storage.Delete(ctx, cached.StoragePath); err != nil { + return fmt.Errorf("deleting cached artifact: %w", err) + } + return p.DB.ClearArtifactCache(versionPURL, filename) +} + // checkCache looks up an artifact in the cache. Returns nil if not cached. func (p *Proxy) checkCache(ctx context.Context, pkgPURL, versionPURL, filename string) (*CacheResult, error) { artifact, err := p.DB.GetCachedArtifact(pkgPURL, versionPURL, filename) @@ -174,6 +194,11 @@ func (p *Proxy) checkCache(ctx context.Context, pkgPURL, versionPURL, filename s if artifact == nil { return nil, nil } + checks, err := newIntegrityChecks(artifact.ContentHash.String, artifact.Integrity.String) + if err != nil { + p.rejectUnusableCacheRecord(artifact, versionPURL, filename, err) + return nil, nil + } result := &CacheResult{ Size: artifact.Size.Int64, @@ -205,16 +230,21 @@ func (p *Proxy) checkCache(ctx context.Context, pkgPURL, versionPURL, filename s return nil, nil } - result.Reader = newVerifyingReader(reader, artifact.ContentHash.String, artifact.Integrity.String, + result.Reader, err = checks.wrap(reader, func(reason string) { p.Logger.Error("cached artifact failed integrity check", "purl", versionPURL, "filename", filename, "path", artifact.StoragePath, "reason", reason) - metrics.RecordIntegrityFailure(artifact.Ecosystem) + metrics.RecordIntegrityFailure(purl.NormalizeEcosystem(artifact.Ecosystem)) if err := p.DB.ClearArtifactCache(versionPURL, filename); err != nil { p.Logger.Warn("failed to clear corrupt artifact from cache", "error", err) } }) + if err != nil { + _ = reader.Close() + p.rejectUnusableCacheRecord(artifact, versionPURL, filename, err) + return nil, nil + } p.recordCacheHit(artifact.Ecosystem, versionPURL, filename) return result, nil } @@ -241,13 +271,20 @@ func rewriteSignedURLHost(signed, baseURL string) string { func (p *Proxy) recordCacheHit(ecosystem, versionPURL, filename string) { _ = p.DB.RecordArtifactHit(versionPURL, filename) - metrics.RecordCacheHit(purl.NormalizeEcosystem(ecosystem)) + metrics.RecordCacheHit(ecosystem) +} + +func (p *Proxy) rejectUnusableCacheRecord(artifact *database.CachedArtifact, versionPURL, filename string, cause error) { + p.Logger.Warn("cached artifact has unusable integrity metadata", + "purl", versionPURL, "filename", filename, + "path", artifact.StoragePath, "error", cause) + metrics.RecordIntegrityFailure(purl.NormalizeEcosystem(artifact.Ecosystem)) + if err := p.DB.ClearArtifactCache(versionPURL, filename); err != nil { + p.Logger.Warn("failed to clear unusable artifact from cache", "error", err) + } } func (p *Proxy) fetchAndCache(ctx context.Context, ecosystem, name, version, filename, pkgPURL, versionPURL string) (*CacheResult, error) { - // Record cache miss - metrics.RecordCacheMiss(ecosystem) - // Resolve download URL info, err := p.Resolver.Resolve(ctx, ecosystem, name, version) if err != nil { @@ -521,12 +558,14 @@ func (p *Proxy) FetchOrCacheMetadata(ctx context.Context, ecosystem, cacheKey, u if entry.ContentType.Valid { ct = entry.ContentType.String } + metrics.RecordCacheHit(ecosystem) return data, ct, nil } } // Cache file missing/unreadable, fall through to upstream } } + p.recordMetadataCacheMiss(ecosystem) accept := contentTypeJSON if len(acceptHeaders) > 0 && acceptHeaders[0] != "" { @@ -574,6 +613,12 @@ func (p *Proxy) FetchOrCacheMetadata(ctx context.Context, ecosystem, cacheKey, u return data, ct, nil } +func (p *Proxy) recordMetadataCacheMiss(ecosystem string) { + if p.CacheMetadata { + metrics.RecordCacheMiss(ecosystem) + } +} + // fetchUpstreamMetadata fetches metadata from upstream, using ETag for conditional revalidation. // Returns the body, content type, ETag, upstream Last-Modified time, and any error. func (p *Proxy) fetchUpstreamMetadata(ctx context.Context, upstreamURL string, entry *database.MetadataCacheEntry, accept string) ([]byte, string, string, time.Time, error) { @@ -824,6 +869,7 @@ func (p *Proxy) GetOrFetchArtifactFromURLWithHeaders(ctx context.Context, ecosys } else if cached != nil { return cached, nil } + metrics.RecordCacheMiss(ecosystem) pkgPURL := purl.MakePURLString(ecosystem, name, "") versionPURL := purl.MakePURLString(ecosystem, name, version) diff --git a/internal/handler/handler_test.go b/internal/handler/handler_test.go index d52e7b6..ec0e300 100644 --- a/internal/handler/handler_test.go +++ b/internal/handler/handler_test.go @@ -15,9 +15,11 @@ import ( "github.com/git-pkgs/proxy/internal/config" "github.com/git-pkgs/proxy/internal/database" + "github.com/git-pkgs/proxy/internal/metrics" "github.com/git-pkgs/proxy/internal/storage" "github.com/git-pkgs/purl" "github.com/git-pkgs/registries/fetch" + "github.com/prometheus/client_golang/prometheus/testutil" ) // mockStorage implements storage.Storage for testing. @@ -42,7 +44,7 @@ func (s *mockStorage) Store(_ context.Context, path string, r io.Reader) (int64, return 0, "", err } s.files[path] = data - return int64(len(data)), "fakehash123", nil + return int64(len(data)), sha256Hex(string(data)), nil } func (s *mockStorage) Open(_ context.Context, path string) (io.ReadCloser, error) { @@ -177,7 +179,7 @@ func seedPackage(t testing.TB, db *database.DB, store *mockStorage, ecosystem, n Filename: filename, UpstreamURL: "https://example.com/" + filename, StoragePath: sql.NullString{String: storagePath, Valid: true}, - ContentHash: sql.NullString{String: "abc123", Valid: true}, + ContentHash: sql.NullString{String: sha256Hex(content), Valid: true}, Size: sql.NullInt64{Int64: int64(len(content)), Valid: true}, ContentType: sql.NullString{String: "application/octet-stream", Valid: true}, FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, @@ -266,13 +268,80 @@ func TestGetOrFetchArtifact_CacheHit(t *testing.T) { if result.ContentType != "application/octet-stream" { t.Errorf("got content type %q, want %q", result.ContentType, "application/octet-stream") } - if result.Hash != "abc123" { - t.Errorf("got hash %q, want %q", result.Hash, "abc123") + if result.Hash != sha256Hex("cached content") { + t.Errorf("got hash %q, want %q", result.Hash, sha256Hex("cached content")) + } +} + +func TestGetCachedArtifactRejectsMalformedIntegrityMetadata(t *testing.T) { + tests := []struct { + name string + malformedHash string + malformedIntegrity string + }{ + {name: "content hash", malformedHash: "abc123"}, + {name: "native integrity", malformedIntegrity: "sha512-abc123"}, + } + for _, test := range tests { + t.Run(test.name, func(t *testing.T) { + assertMalformedCacheRejected(t, test.malformedHash, test.malformedIntegrity) + }) + } +} + +func assertMalformedCacheRejected(t *testing.T, malformedHash, malformedIntegrity string) { + t.Helper() + proxy, db, store, _ := setupTestProxy(t) + const ( + packageName = "broken" + version = "1.0.0" + filename = "broken-1.0.0.tgz" + ) + seedPackage(t, db, store, "npm", packageName, version, filename, "cached content") + versionPURL := purl.MakePURLString("npm", packageName, version) + + if malformedHash != "" { + artifact, err := db.GetArtifact(versionPURL, filename) + if err != nil { + t.Fatal(err) + } + artifact.ContentHash = sql.NullString{String: malformedHash, Valid: true} + if err := db.UpsertArtifact(artifact); err != nil { + t.Fatal(err) + } + } + if malformedIntegrity != "" { + versionRecord := &database.Version{ + PURL: versionPURL, + PackagePURL: purl.MakePURLString("npm", packageName, ""), + Integrity: sql.NullString{String: malformedIntegrity, Valid: true}, + } + if err := db.UpsertVersion(versionRecord); err != nil { + t.Fatal(err) + } + } + + proxy.DirectServe = true + store.signedURL = "https://cache.example/broken" + result, err := proxy.GetCachedArtifact(context.Background(), "npm", packageName, version, filename) + if err != nil { + t.Fatalf("GetCachedArtifact: %v", err) + } + if result != nil { + t.Errorf("GetCachedArtifact = %+v, want nil", result) + } + artifact, err := db.GetArtifact(versionPURL, filename) + if err != nil { + t.Fatal(err) + } + if artifact.StoragePath.Valid { + t.Error("unusable cache record retained its storage path") } } func TestGetOrFetchArtifact_CacheMiss_NoPackage(t *testing.T) { proxy, _, _, fetcher := setupTestProxy(t) + missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("npm")) // The resolver will fail because "nonexistent" isn't a real package, // but we're testing that it tries to fetch (doesn't return from cache). @@ -282,6 +351,10 @@ func TestGetOrFetchArtifact_CacheMiss_NoPackage(t *testing.T) { if err == nil { t.Fatal("expected error for uncached package") } + missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("npm")) + if diff := missesAfter - missesBefore; diff != 1 { + t.Errorf("cache misses delta = %.0f, want 1", diff) + } } func TestGetOrFetchArtifactFromURL_CacheMiss_StorageMissing(t *testing.T) { @@ -297,7 +370,7 @@ func TestGetOrFetchArtifactFromURL_CacheMiss_StorageMissing(t *testing.T) { Filename: "missing-1.0.0.tgz", UpstreamURL: "https://example.com/missing.tgz", StoragePath: sql.NullString{String: "nonexistent/path.tgz", Valid: true}, - ContentHash: sql.NullString{String: "hash", Valid: true}, + ContentHash: sql.NullString{String: sha256Hex("missing content"), Valid: true}, Size: sql.NullInt64{Int64: 100, Valid: true}, ContentType: sql.NullString{String: "application/octet-stream", Valid: true}, FetchedAt: sql.NullTime{Time: time.Now(), Valid: true}, @@ -540,6 +613,7 @@ func TestServeArtifact_Stream(t *testing.T) { func TestGetOrFetchArtifactFromURL_CacheHit(t *testing.T) { proxy, db, store, fetcher := setupTestProxy(t) seedPackage(t, db, store, "pypi", "requests", "2.28.0", "requests-2.28.0.tar.gz", "pypi content") + missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi")) result, err := proxy.GetOrFetchArtifactFromURL(context.Background(), "pypi", "requests", "2.28.0", "requests-2.28.0.tar.gz", "https://pypi.org/files/requests-2.28.0.tar.gz") if err != nil { @@ -553,10 +627,15 @@ func TestGetOrFetchArtifactFromURL_CacheHit(t *testing.T) { if fetcher.fetchCalled { t.Error("fetcher should not be called on cache hit") } + missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi")) + if diff := missesAfter - missesBefore; diff != 0 { + t.Errorf("cache misses delta = %.0f, want 0", diff) + } } func TestGetOrFetchArtifactFromURL_CacheMiss(t *testing.T) { proxy, _, store, fetcher := setupTestProxy(t) + missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi")) fetcher.artifact = &fetch.Artifact{ Body: io.NopCloser(strings.NewReader("fetched content")), @@ -589,6 +668,10 @@ func TestGetOrFetchArtifactFromURL_CacheMiss(t *testing.T) { if _, ok := store.files[storagePath]; !ok { t.Error("artifact was not stored in storage") } + missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi")) + if diff := missesAfter - missesBefore; diff != 1 { + t.Errorf("cache misses delta = %.0f, want 1", diff) + } } func TestGetOrFetchArtifactFromURL_FetchError(t *testing.T) { @@ -878,6 +961,8 @@ func TestProxyCached_NoValidators_OmitsHeaders(t *testing.T) { } func TestFetchOrCacheMetadata_TTL_ServesFreshFromCache(t *testing.T) { + hitsBefore := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("test")) + missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test")) upstreamHits := 0 upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { upstreamHits++ @@ -904,6 +989,12 @@ func TestFetchOrCacheMetadata_TTL_ServesFreshFromCache(t *testing.T) { if upstreamHits != 1 { t.Fatalf("expected 1 upstream hit, got %d", upstreamHits) } + if diff := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test")) - missesBefore; diff != 1 { + t.Errorf("cache misses delta after first request = %.0f, want 1", diff) + } + if diff := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("test")) - hitsBefore; diff != 0 { + t.Errorf("cache hits delta after first request = %.0f, want 0", diff) + } // Second request within TTL should serve from cache without hitting upstream body, _, err = proxy.FetchOrCacheMetadata(ctx, "test", "ttl-pkg", upstream.URL+"/pkg") @@ -916,9 +1007,16 @@ func TestFetchOrCacheMetadata_TTL_ServesFreshFromCache(t *testing.T) { if upstreamHits != 1 { t.Errorf("expected upstream to still be hit only once, got %d", upstreamHits) } + if diff := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("test")) - hitsBefore; diff != 1 { + t.Errorf("cache hits delta after second request = %.0f, want 1", diff) + } + if diff := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test")) - missesBefore; diff != 1 { + t.Errorf("cache misses delta after second request = %.0f, want 1", diff) + } } func TestFetchOrCacheMetadata_TTL_Zero_AlwaysRevalidates(t *testing.T) { + missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test")) upstreamHits := 0 upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { upstreamHits++ @@ -947,6 +1045,40 @@ func TestFetchOrCacheMetadata_TTL_Zero_AlwaysRevalidates(t *testing.T) { if upstreamHits != 2 { t.Errorf("expected 2 upstream hits with TTL=0, got %d", upstreamHits) } + missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test")) + if diff := missesAfter - missesBefore; diff != 2 { + t.Errorf("cache misses delta = %.0f, want 2", diff) + } +} + +func TestFetchOrCacheMetadata_CacheDisabledDoesNotRecordMetrics(t *testing.T) { + const ecosystem = "metadata-disabled" + + upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + w.Header().Set("Content-Type", "application/json") + _, _ = w.Write([]byte(`{"v":1}`)) + })) + t.Cleanup(upstream.Close) + + proxy, _, _, _ := setupTestProxy(t) + proxy.HTTPClient = upstream.Client() + + hitsBefore := testutil.ToFloat64(metrics.CacheHits.WithLabelValues(ecosystem)) + missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues(ecosystem)) + + _, _, err := proxy.FetchOrCacheMetadata(context.Background(), ecosystem, "pkg", upstream.URL+"/pkg") + if err != nil { + t.Fatalf("fetch metadata: %v", err) + } + + hitsAfter := testutil.ToFloat64(metrics.CacheHits.WithLabelValues(ecosystem)) + missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues(ecosystem)) + if diff := hitsAfter - hitsBefore; diff != 0 { + t.Errorf("cache hits delta = %.0f, want 0", diff) + } + if diff := missesAfter - missesBefore; diff != 0 { + t.Errorf("cache misses delta = %.0f, want 0", diff) + } } func TestProxyCached_StaleWarningHeader(t *testing.T) { diff --git a/internal/handler/helm.go b/internal/handler/helm.go new file mode 100644 index 0000000..f91ba58 --- /dev/null +++ b/internal/handler/helm.go @@ -0,0 +1,364 @@ +package handler + +import ( + "crypto/sha256" + "encoding/hex" + "errors" + "fmt" + "net/http" + "net/url" + "path" + "strings" + "time" + + "gopkg.in/yaml.v3" +) + +const ( + helmMetadataEcosystem = "helm" + helmIndexFilename = "index.yaml" + sha256HexLength = 64 +) + +// HelmHandler serves read-only HTTP Helm chart repositories. Each configured +// repository is mounted at /helm/{repository}/. +type HelmHandler struct { + proxy *Proxy + proxyURL string + repositories map[string]string +} + +// NewHelmHandler creates a Helm chart repository protocol handler. +func NewHelmHandler(proxy *Proxy, proxyURL string, repositories map[string]string) *HelmHandler { + h := &HelmHandler{ + proxyURL: strings.TrimSuffix(proxyURL, "/"), + repositories: make(map[string]string, len(repositories)), + proxy: proxy, + } + for name, repositoryURL := range repositories { + h.repositories[name] = strings.TrimSuffix(repositoryURL, "/") + } + return h +} + +// Routes returns the HTTP handler for Helm chart repository requests. +func (h *HelmHandler) Routes() http.Handler { + mux := http.NewServeMux() + mux.HandleFunc("GET /{repository}/index.yaml", h.handleIndex) + mux.HandleFunc("GET /{repository}/charts/{digest}/{filename}", h.handleChart) + return mux +} + +func (h *HelmHandler) handleIndex(w http.ResponseWriter, r *http.Request) { + repository, upstreamURL, ok := h.repositoryForRequest(r) + if !ok { + http.NotFound(w, r) + return + } + + body, contentType, err := h.fetchIndex(r, repository, upstreamURL) + if err != nil { + h.serveIndexError(w, err) + return + } + + rewritten, err := h.rewriteIndex(repository, upstreamURL, body) + if err != nil { + h.proxy.Logger.Warn("failed to rewrite Helm index", "repository", repository, "error", err) + http.Error(w, "invalid Helm repository index", http.StatusBadGateway) + return + } + + h.proxy.writeMetadataCachedResponse(w, r, helmMetadataEcosystem, h.indexCacheKey(repository, upstreamURL), rewritten, contentType) +} + +func (h *HelmHandler) handleChart(w http.ResponseWriter, r *http.Request) { + repository, upstreamURL, ok := h.repositoryForRequest(r) + if !ok { + http.NotFound(w, r) + return + } + + digest, ok := normalizeHelmDigest(r.PathValue("digest")) + filename := r.PathValue("filename") + if !ok || filename == "" || strings.Contains(filename, "/") || containsPathTraversal(filename) { + http.Error(w, "invalid chart request", http.StatusBadRequest) + return + } + + cached, err := h.proxy.GetCachedArtifact(r.Context(), helmMetadataEcosystem, repository, digest, filename) + if err != nil { + h.proxy.Logger.Error("failed to check Helm chart cache", "error", err) + http.Error(w, "failed to check chart cache", http.StatusInternalServerError) + return + } + if cached != nil { + h.serveChart(w, r, repository, digest, filename, cached) + return + } + + body, _, err := h.fetchIndex(r, repository, upstreamURL) + if err != nil { + h.serveIndexError(w, err) + return + } + + downloadURL, err := h.findChartDownload(upstreamURL, body, digest, filename) + if err != nil { + if errors.Is(err, errHelmChartNotFound) { + http.NotFound(w, r) + return + } + h.proxy.Logger.Warn("failed to read Helm index", "repository", repository, "error", err) + http.Error(w, "invalid Helm repository index", http.StatusBadGateway) + return + } + + result, err := h.proxy.GetOrFetchArtifactFromURL( + r.Context(), helmMetadataEcosystem, repository, digest, filename, downloadURL) + if err != nil { + h.proxy.serveArtifactError(w, err, "failed to fetch chart") + return + } + h.serveChart(w, r, repository, digest, filename, result) +} + +func (h *HelmHandler) serveChart(w http.ResponseWriter, r *http.Request, repository, digest, filename string, result *CacheResult) { + if !strings.EqualFold(result.Hash, digest) { + if result.Reader != nil { + _ = result.Reader.Close() + } + if clearErr := h.proxy.ClearCachedArtifact(r.Context(), helmMetadataEcosystem, repository, digest, filename); clearErr != nil { + h.proxy.Logger.Warn("failed to clear Helm chart with invalid digest", "error", clearErr) + } + http.Error(w, "chart digest verification failed", http.StatusBadGateway) + return + } + + if result.ContentType == "" { + w.Header().Set("Content-Type", "application/gzip") + } + ServeArtifact(w, result) +} + +func (h *HelmHandler) repositoryForRequest(r *http.Request) (name, upstreamURL string, ok bool) { + name = r.PathValue("repository") + upstreamURL, ok = h.repositories[name] + return name, upstreamURL, ok +} + +func (h *HelmHandler) fetchIndex(r *http.Request, repository, upstreamURL string) ([]byte, string, error) { + return h.proxy.FetchOrCacheMetadata( + r.Context(), + helmMetadataEcosystem, + h.indexCacheKey(repository, upstreamURL), + upstreamURL+"/"+helmIndexFilename, + "application/x-yaml, text/yaml;q=0.9, */*;q=0.1", + ) +} + +func (h *HelmHandler) indexCacheKey(repository, upstreamURL string) string { + identity := repository + "\x00" + upstreamURL + digest := sha256.Sum256([]byte(identity)) + return hex.EncodeToString(digest[:]) +} + +func (h *HelmHandler) serveIndexError(w http.ResponseWriter, err error) { + if errors.Is(err, ErrUpstreamNotFound) { + http.Error(w, "Helm repository not found", http.StatusNotFound) + return + } + h.proxy.Logger.Error("failed to fetch Helm index", "error", err) + http.Error(w, "failed to fetch Helm repository index", http.StatusBadGateway) +} + +func (h *HelmHandler) rewriteIndex(repository, upstreamURL string, body []byte) ([]byte, error) { + document, entries, err := parseHelmIndex(body) + if err != nil { + return nil, err + } + + for i := 0; i < len(entries.Content); i += 2 { + chartName := entries.Content[i].Value + releases := entries.Content[i+1] + if releases.Kind != yaml.SequenceNode { + return nil, fmt.Errorf("chart %q releases must be a sequence", chartName) + } + + filtered := make([]*yaml.Node, 0, len(releases.Content)) + for _, release := range releases.Content { + chart, err := h.parseChartRelease(chartName, upstreamURL, release) + if err != nil { + return nil, err + } + if h.chartOnCooldown(chartName, chart.created) { + continue + } + for _, download := range chart.downloads { + download.node.Value = h.chartProxyURL(repository, chart.digest, download.filename) + } + filtered = append(filtered, release) + } + releases.Content = filtered + } + + return yaml.Marshal(document) +} + +func (h *HelmHandler) findChartDownload(upstreamURL string, body []byte, digest, filename string) (string, error) { + _, entries, err := parseHelmIndex(body) + if err != nil { + return "", err + } + + for i := 0; i < len(entries.Content); i += 2 { + chartName := entries.Content[i].Value + releases := entries.Content[i+1] + if releases.Kind != yaml.SequenceNode { + return "", fmt.Errorf("chart %q releases must be a sequence", chartName) + } + for _, release := range releases.Content { + chart, err := h.parseChartRelease(chartName, upstreamURL, release) + if err != nil { + return "", err + } + if chart.digest != digest || h.chartOnCooldown(chartName, chart.created) { + continue + } + for _, download := range chart.downloads { + if download.filename == filename { + return download.url, nil + } + } + } + } + + return "", errHelmChartNotFound +} + +func (h *HelmHandler) chartOnCooldown(chartName string, created time.Time) bool { + return !created.IsZero() && h.proxy.Cooldown != nil && h.proxy.Cooldown.Enabled() && + !h.proxy.Cooldown.IsAllowed(helmMetadataEcosystem, canonicalPackagePURL(helmMetadataEcosystem, chartName), created) +} + +type helmChartDownload struct { + node *yaml.Node + url string + filename string +} + +type helmChartRelease struct { + created time.Time + digest string + downloads []helmChartDownload +} + +var errHelmChartNotFound = errors.New("chart not found in Helm index") + +func (h *HelmHandler) parseChartRelease(chartName, upstreamURL string, release *yaml.Node) (helmChartRelease, error) { + digestNode := helmMappingValue(release, "digest") + urlsNode := helmMappingValue(release, "urls") + if digestNode == nil || urlsNode == nil || urlsNode.Kind != yaml.SequenceNode || len(urlsNode.Content) == 0 { + return helmChartRelease{}, fmt.Errorf("chart %q has no digest or URLs", chartName) + } + digest, ok := normalizeHelmDigest(digestNode.Value) + if !ok { + return helmChartRelease{}, fmt.Errorf("chart %q has invalid digest", chartName) + } + + baseURL, err := url.Parse(upstreamURL + "/" + helmIndexFilename) + if err != nil { + return helmChartRelease{}, fmt.Errorf("parsing Helm repository URL: %w", err) + } + + chart := helmChartRelease{digest: digest} + if createdNode := helmMappingValue(release, "created"); createdNode != nil && createdNode.Value != "" { + chart.created, err = time.Parse(time.RFC3339Nano, createdNode.Value) + if err != nil { + return helmChartRelease{}, fmt.Errorf("chart %q has invalid creation time: %w", chartName, err) + } + } + + for _, urlNode := range urlsNode.Content { + if urlNode.Kind != yaml.ScalarNode { + return helmChartRelease{}, fmt.Errorf("chart %q has invalid URL", chartName) + } + reference, err := url.Parse(urlNode.Value) + if err != nil { + return helmChartRelease{}, fmt.Errorf("parsing chart %q URL: %w", chartName, err) + } + downloadURL := baseURL.ResolveReference(reference) + if (downloadURL.Scheme != "http" && downloadURL.Scheme != "https") || downloadURL.Host == "" { + return helmChartRelease{}, fmt.Errorf("chart %q URL must be HTTP(S)", chartName) + } + filename := path.Base(downloadURL.Path) + if filename == "." || filename == "/" || filename == "" || !strings.HasSuffix(filename, ".tgz") { + return helmChartRelease{}, fmt.Errorf("chart %q URL must point to a .tgz file", chartName) + } + chart.downloads = append(chart.downloads, helmChartDownload{ + node: urlNode, + url: downloadURL.String(), + filename: filename, + }) + } + return chart, nil +} + +func (h *HelmHandler) chartProxyURL(repository, digest, filename string) string { + return fmt.Sprintf("%s/helm/%s/charts/%s/%s", h.proxyURL, + url.PathEscape(repository), digest, url.PathEscape(filename)) +} + +func parseHelmIndex(body []byte) (*yaml.Node, *yaml.Node, error) { + var document yaml.Node + if err := yaml.Unmarshal(body, &document); err != nil { + return nil, nil, fmt.Errorf("parsing Helm index: %w", err) + } + entries, err := helmIndexEntries(&document) + if err != nil { + return nil, nil, err + } + return &document, entries, nil +} + +func helmIndexEntries(document *yaml.Node) (*yaml.Node, error) { + if document == nil { + return nil, errors.New("helm index is empty") + } + if len(document.Content) != 1 || document.Content[0].Kind != yaml.MappingNode { + return nil, errors.New("helm index must be a mapping") + } + entries := helmMappingValue(document.Content[0], "entries") + if entries == nil || entries.Kind != yaml.MappingNode { + return nil, errors.New("helm index has no entries mapping") + } + if len(entries.Content)%2 != 0 { + return nil, errors.New("helm index entries mapping has an incomplete key-value pair") + } + return entries, nil +} + +func helmMappingValue(mapping *yaml.Node, key string) *yaml.Node { + if mapping == nil || mapping.Kind != yaml.MappingNode { + return nil + } + for i := 0; i+1 < len(mapping.Content); i += 2 { + if mapping.Content[i].Value == key { + return mapping.Content[i+1] + } + } + return nil +} + +func normalizeHelmDigest(value string) (string, bool) { + digest := strings.TrimPrefix(strings.ToLower(value), "sha256:") + if len(digest) != sha256HexLength { + return "", false + } + for _, char := range digest { + if (char < '0' || char > '9') && (char < 'a' || char > 'f') { + return "", false + } + } + return digest, true +} diff --git a/internal/handler/helm_test.go b/internal/handler/helm_test.go new file mode 100644 index 0000000..ec8d4a5 --- /dev/null +++ b/internal/handler/helm_test.go @@ -0,0 +1,337 @@ +package handler + +import ( + "crypto/sha256" + "encoding/hex" + "fmt" + "net/http" + "net/http/httptest" + "strings" + "sync/atomic" + "testing" + "time" + + "github.com/git-pkgs/cooldown" + upstreamhttp "github.com/git-pkgs/proxy/internal/httpclient" + "github.com/git-pkgs/proxy/internal/storage" + "github.com/git-pkgs/registries/fetch" + "gopkg.in/yaml.v3" +) + +func TestHelmHandler_RewritesIndexAndCachesChart(t *testing.T) { + chart := []byte("a Helm chart") + digest := helmSHA256Hex(chart) + var available atomic.Bool + available.Store(true) + var indexRequests atomic.Int32 + var chartRequests atomic.Int32 + + var upstream *httptest.Server + upstream = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + if !available.Load() { + http.Error(w, "unavailable", http.StatusServiceUnavailable) + return + } + switch r.URL.Path { + case "/charts/index.yaml": + indexRequests.Add(1) + w.Header().Set("Content-Type", "application/x-yaml") + _, _ = fmt.Fprintf(w, `apiVersion: v1 +entries: + demo: + - annotations: + example.com/retained: "true" + created: 2020-01-02T03:04:05Z + digest: %s + name: demo + urls: + - demo-1.0.0.tgz + - %s/charts/mirror/demo-1.0.0.tgz + version: 1.0.0 +generated: 2020-01-02T03:04:05Z +`, digest, upstream.URL) + case "/charts/demo-1.0.0.tgz", "/charts/mirror/demo-1.0.0.tgz": + chartRequests.Add(1) + w.Header().Set("Content-Type", "application/gzip") + _, _ = w.Write(chart) + default: + http.NotFound(w, r) + } + })) + defer upstream.Close() + + proxy, _, _, _ := setupTestProxy(t) + proxy.CacheMetadata = true + proxy.MetadataTTL = time.Hour + proxy.HTTPClient = upstream.Client() + fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0)) + proxy.Fetcher = fetcher + t.Cleanup(func() { _ = fetcher.Close() }) + + h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"stable": upstream.URL + "/charts"}) + + indexResponse := serveHelmRequest(h, "/stable/index.yaml") + if indexResponse.Code != http.StatusOK { + t.Fatalf("index status = %d, want 200: %s", indexResponse.Code, indexResponse.Body.String()) + } + if got := indexResponse.Header().Get("Content-Type"); got != "application/x-yaml" { + t.Errorf("index Content-Type = %q, want application/x-yaml", got) + } + if strings.Contains(indexResponse.Body.String(), upstream.URL) { + t.Errorf("rewritten index contains upstream URL: %s", indexResponse.Body.String()) + } + if !strings.Contains(indexResponse.Body.String(), "example.com/retained") { + t.Errorf("rewritten index lost an unrelated field: %s", indexResponse.Body.String()) + } + + var index map[string]any + if err := yaml.Unmarshal(indexResponse.Body.Bytes(), &index); err != nil { + t.Fatalf("parse rewritten index: %v", err) + } + entries := index["entries"].(map[string]any) + release := entries["demo"].([]any)[0].(map[string]any) + urls := release["urls"].([]any) + wantURL := "http://proxy.example/helm/stable/charts/" + digest + "/demo-1.0.0.tgz" + for _, rawURL := range urls { + if rawURL != wantURL { + t.Errorf("rewritten URL = %q, want %q", rawURL, wantURL) + } + } + + firstChart := serveHelmRequest(h, "/stable/charts/"+digest+"/demo-1.0.0.tgz") + if firstChart.Code != http.StatusOK { + t.Fatalf("chart status = %d, want 200: %s", firstChart.Code, firstChart.Body.String()) + } + if got := firstChart.Body.String(); got != string(chart) { + t.Errorf("chart body = %q, want %q", got, chart) + } + if got := firstChart.Header().Get("Content-Type"); got != "application/gzip" { + t.Errorf("chart Content-Type = %q, want application/gzip", got) + } + + // Artifact cache availability must not depend on metadata caching or a + // reachable index upstream. + proxy.CacheMetadata = false + available.Store(false) + cachedChart := serveHelmRequest(h, "/stable/charts/"+digest+"/demo-1.0.0.tgz") + if cachedChart.Code != http.StatusOK { + t.Fatalf("cached chart status = %d, want 200: %s", cachedChart.Code, cachedChart.Body.String()) + } + if got := cachedChart.Body.String(); got != string(chart) { + t.Errorf("cached chart body = %q, want %q", got, chart) + } + if got := indexRequests.Load(); got != 1 { + t.Errorf("index requests = %d, want 1", got) + } + if got := chartRequests.Load(); got != 1 { + t.Errorf("chart requests = %d, want 1", got) + } +} + +func TestHelmHandler_RejectsChartDigestMismatch(t *testing.T) { + chart := []byte("tampered chart") + digest := helmSHA256Hex([]byte("expected chart")) + requests := 0 + + upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + switch r.URL.Path { + case "/index.yaml": + _, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", digest) + case "/demo.tgz": + requests++ + _, _ = w.Write(chart) + default: + http.NotFound(w, r) + } + })) + defer upstream.Close() + + proxy, _, store, _ := setupTestProxy(t) + proxy.CacheMetadata = true + proxy.MetadataTTL = time.Hour + proxy.HTTPClient = upstream.Client() + fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0)) + proxy.Fetcher = fetcher + t.Cleanup(func() { _ = fetcher.Close() }) + h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"test": upstream.URL}) + + for range 2 { + response := serveHelmRequest(h, "/test/charts/"+digest+"/demo.tgz") + if response.Code != http.StatusBadGateway { + t.Errorf("status = %d, want 502: %s", response.Code, response.Body.String()) + } + } + if requests != 2 { + t.Errorf("chart requests = %d, want 2 after invalid cache entry is cleared", requests) + } + storagePath := storage.ArtifactPath(helmMetadataEcosystem, "", "test", digest, "demo.tgz") + if exists, err := store.Exists(t.Context(), storagePath); err != nil { + t.Fatalf("checking rejected chart storage: %v", err) + } else if exists { + t.Errorf("rejected chart remains in storage at %q", storagePath) + } +} + +func TestHelmHandler_IndexCacheChangesWithUpstreamURL(t *testing.T) { + firstDigest := strings.Repeat("a", sha256HexLength) + secondDigest := strings.Repeat("b", sha256HexLength) + firstRequests := 0 + secondRequests := 0 + first := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + firstRequests++ + _, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", firstDigest) + })) + defer first.Close() + second := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + secondRequests++ + _, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", secondDigest) + })) + defer second.Close() + + proxy, db, store, _ := setupTestProxy(t) + proxy.CacheMetadata = true + proxy.MetadataTTL = time.Hour + proxy.HTTPClient = first.Client() + firstHandler := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"stable": first.URL}) + if response := serveHelmRequest(firstHandler, "/stable/index.yaml"); response.Code != http.StatusOK { + t.Fatalf("first index status = %d, want 200: %s", response.Code, response.Body.String()) + } + + // Model a restarted server with the same database and storage but a changed + // repository URL. Its cache key must not reuse the previous index or ETag. + restartedProxy := NewProxy(db, store, &mockFetcher{}, fetch.NewResolver(), nil) + restartedProxy.CacheMetadata = true + restartedProxy.MetadataTTL = time.Hour + restartedProxy.HTTPClient = second.Client() + secondHandler := NewHelmHandler(restartedProxy, "http://proxy.example", map[string]string{"stable": second.URL}) + response := serveHelmRequest(secondHandler, "/stable/index.yaml") + if response.Code != http.StatusOK { + t.Fatalf("second index status = %d, want 200: %s", response.Code, response.Body.String()) + } + if !strings.Contains(response.Body.String(), secondDigest) { + t.Errorf("second index did not use the new upstream: %s", response.Body.String()) + } + if firstRequests != 1 { + t.Errorf("first upstream requests = %d, want 1", firstRequests) + } + if secondRequests != 1 { + t.Errorf("second upstream requests = %d, want 1", secondRequests) + } +} + +func TestHelmHandler_UsesConfiguredUpstreamAuthentication(t *testing.T) { + chart := []byte("private Helm chart") + digest := helmSHA256Hex(chart) + upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + if r.Header.Get("Authorization") != "Bearer private-token" { + http.Error(w, "unauthorized", http.StatusUnauthorized) + return + } + switch r.URL.Path { + case "/index.yaml": + _, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", digest) + case "/demo.tgz": + _, _ = w.Write(chart) + default: + http.NotFound(w, r) + } + })) + defer upstream.Close() + + proxy, _, _, _ := setupTestProxy(t) + proxy.CacheMetadata = true + proxy.MetadataTTL = time.Hour + authClient := &http.Client{Transport: upstreamhttp.NewTransport(http.DefaultTransport, + upstreamhttp.AuthFunc(func(string) (string, string) { + return "Authorization", "Bearer private-token" + }))} + proxy.HTTPClient = authClient + fetcher := fetch.NewFetcher(fetch.WithHTTPClient(authClient), fetch.WithMaxRetries(0)) + proxy.Fetcher = fetcher + t.Cleanup(func() { _ = fetcher.Close() }) + h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"private": upstream.URL}) + + response := serveHelmRequest(h, "/private/charts/"+digest+"/demo.tgz") + if response.Code != http.StatusOK { + t.Fatalf("status = %d, want 200: %s", response.Code, response.Body.String()) + } + if got := response.Body.String(); got != string(chart) { + t.Errorf("body = %q, want %q", got, chart) + } +} + +func TestHelmHandler_FiltersNewChartsFromIndex(t *testing.T) { + oldDigest := strings.Repeat("a", 64) + newDigest := strings.Repeat("b", 64) + proxy := &Proxy{Cooldown: &cooldown.Config{Default: "3d"}} + h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"test": "https://charts.example"}) + + body := fmt.Sprintf(`apiVersion: v1 +entries: + demo: + - created: %s + digest: %s + urls: [demo-old.tgz] + - created: %s + digest: %s + urls: [demo-new.tgz] +`, time.Now().Add(-10*24*time.Hour).Format(time.RFC3339), oldDigest, + time.Now().Add(-time.Hour).Format(time.RFC3339), newDigest) + + rewritten, err := h.rewriteIndex("test", "https://charts.example", []byte(body)) + if err != nil { + t.Fatalf("rewriteIndex() error = %v", err) + } + if strings.Contains(string(rewritten), newDigest) { + t.Errorf("rewritten index includes a chart still in cooldown: %s", rewritten) + } + if !strings.Contains(string(rewritten), oldDigest) { + t.Errorf("rewritten index omitted an old chart: %s", rewritten) + } +} + +func TestNormalizeHelmDigest(t *testing.T) { + digest := strings.Repeat("a", 64) + for _, input := range []string{digest, "sha256:" + digest, "SHA256:" + strings.ToUpper(digest)} { + if got, ok := normalizeHelmDigest(input); !ok || got != digest { + t.Errorf("normalizeHelmDigest(%q) = %q, %t; want %q, true", input, got, ok, digest) + } + } + if _, ok := normalizeHelmDigest("bad"); ok { + t.Error("normalizeHelmDigest accepted an invalid digest") + } +} + +func TestHelmIndexEntriesRejectsIncompleteMapping(t *testing.T) { + entries := &yaml.Node{ + Kind: yaml.MappingNode, + Content: []*yaml.Node{ + {Kind: yaml.ScalarNode, Value: "demo"}, + }, + } + document := &yaml.Node{ + Kind: yaml.DocumentNode, + Content: []*yaml.Node{{ + Kind: yaml.MappingNode, + Content: []*yaml.Node{ + {Kind: yaml.ScalarNode, Value: "entries"}, + entries, + }, + }}, + } + + if _, err := helmIndexEntries(document); err == nil { + t.Fatal("helmIndexEntries() error = nil, want incomplete mapping error") + } +} + +func serveHelmRequest(h *HelmHandler, target string) *httptest.ResponseRecorder { + w := httptest.NewRecorder() + h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodGet, target, nil)) + return w +} + +func helmSHA256Hex(data []byte) string { + digest := sha256.Sum256(data) + return hex.EncodeToString(digest[:]) +} diff --git a/internal/handler/integrity.go b/internal/handler/integrity.go index bb29a21..07963b9 100644 --- a/internal/handler/integrity.go +++ b/internal/handler/integrity.go @@ -1,140 +1,100 @@ package handler import ( - "crypto/sha256" - "crypto/sha512" - "crypto/subtle" - "encoding/base64" - "encoding/hex" "fmt" - "hash" "io" - "strings" + + "github.com/git-pkgs/integrity" ) -// parseSRI parses a Subresource Integrity string (e.g. "sha512-abc==") into -// an algorithm name and raw digest bytes. Returns ok=false for empty, -// malformed, or unsupported entries. Only the first hash in a multi-hash -// SRI string is considered. -func parseSRI(s string) (algo string, digest []byte, ok bool) { - s = strings.TrimSpace(s) - if s == "" { - return "", nil, false +type integrityChecks struct { + contentHash integrity.SRI + native integrity.SRI + algorithms []integrity.Algorithm +} + +func newIntegrityChecks(contentHash, native string) (integrityChecks, error) { + checks := integrityChecks{} + + if contentHash != "" { + digest, err := integrity.ParseHex(integrity.SHA256, contentHash) + if err != nil { + return integrityChecks{}, fmt.Errorf("parse content_hash: %w", err) + } + checks.contentHash = integrity.SRI{digest} + checks.algorithms = append(checks.algorithms, integrity.SHA256) } - if i := strings.IndexByte(s, ' '); i >= 0 { - s = s[:i] + + if native != "" { + digests, err := integrity.ParseSRI(native) + if err != nil { + return integrityChecks{}, fmt.Errorf("parse integrity: %w", err) + } + checks.native = digests + for _, digest := range digests { + checks.algorithms = append(checks.algorithms, digest.Algorithm()) + } } - algo, b64, found := strings.Cut(s, "-") - if !found { - return "", nil, false + + return checks, nil +} + +func (c integrityChecks) wrap(source io.ReadCloser, onMismatch func(string)) (io.ReadCloser, error) { + if len(c.algorithms) == 0 { + return source, nil } - d, err := base64.StdEncoding.DecodeString(b64) + reader, err := integrity.NewReader(source, c.algorithms...) if err != nil { - return "", nil, false - } - switch algo { - case "sha256", "sha384", "sha512": - return algo, d, true - default: - return "", nil, false + return nil, fmt.Errorf("create integrity reader: %w", err) } + return &verifyingReader{ + source: source, + reader: reader, + checks: c, + onMismatch: onMismatch, + }, nil } -func newSRIHash(algo string) hash.Hash { - switch algo { - case "sha256": - return sha256.New() - case "sha384": - return sha512.New384() - case "sha512": - return sha512.New() - } - return nil -} - -// verifyingReader wraps an io.ReadCloser and computes SHA256 (and optionally -// a second SRI hash) as bytes are read. When the underlying reader reaches -// EOF it compares the digests against the expected values and calls -// onMismatch for each failure. Verification is skipped if the stream was -// not fully consumed (e.g. client disconnect) to avoid false positives. +// verifyingReader forwards Close to its source and reports completed digest +// mismatches after its shared integrity reader observes EOF. type verifyingReader struct { - r io.ReadCloser - sha256 hash.Hash - wantSHA256 string - sri hash.Hash - sriAlgo string - wantSRI []byte + source io.ReadCloser + reader *integrity.Reader + checks integrityChecks onMismatch func(reason string) - eof bool verified bool } -func newVerifyingReader(r io.ReadCloser, contentHash, sri string, onMismatch func(string)) io.ReadCloser { - if contentHash == "" && sri == "" { - return r - } - v := &verifyingReader{ - r: r, - onMismatch: onMismatch, - } - if contentHash != "" { - v.sha256 = sha256.New() - v.wantSHA256 = contentHash - } - if algo, digest, ok := parseSRI(sri); ok { - v.sri = newSRIHash(algo) - v.sriAlgo = algo - v.wantSRI = digest - } - if v.sha256 == nil && v.sri == nil { - return r - } - return v -} - -func (v *verifyingReader) Read(p []byte) (int, error) { - n, err := v.r.Read(p) - if n > 0 { - if v.sha256 != nil { - v.sha256.Write(p[:n]) - } - if v.sri != nil { - v.sri.Write(p[:n]) - } - } +func (r *verifyingReader) Read(p []byte) (int, error) { + n, err := r.reader.Read(p) if err == io.EOF { - v.eof = true - v.verify() + r.verify() } return n, err } -func (v *verifyingReader) Close() error { - if v.eof { - v.verify() - } - return v.r.Close() +func (r *verifyingReader) Close() error { + return r.source.Close() } -func (v *verifyingReader) verify() { - if v.verified { +func (r *verifyingReader) verify() { + if r.verified { + return + } + r.verified = true + result := r.reader.Result() + if !result.Complete { return } - v.verified = true - if v.sha256 != nil { - got := hex.EncodeToString(v.sha256.Sum(nil)) - if subtle.ConstantTimeCompare([]byte(got), []byte(v.wantSHA256)) != 1 { - v.onMismatch(fmt.Sprintf("content_hash mismatch: stored=%s computed=%s", v.wantSHA256, got)) + if len(r.checks.contentHash) > 0 { + if err := result.Verify(r.checks.contentHash); err != nil { + r.onMismatch("content_hash: " + err.Error()) } } - if v.sri != nil { - got := v.sri.Sum(nil) - if subtle.ConstantTimeCompare(got, v.wantSRI) != 1 { - v.onMismatch(fmt.Sprintf("integrity mismatch: %s expected=%s computed=%s", - v.sriAlgo, - base64.StdEncoding.EncodeToString(v.wantSRI), - base64.StdEncoding.EncodeToString(got))) + if len(r.checks.native) > 0 { + if err := result.Verify(r.checks.native); err != nil { + r.onMismatch("integrity: " + err.Error()) } } } diff --git a/internal/handler/integrity_test.go b/internal/handler/integrity_test.go index 93c448c..95992c0 100644 --- a/internal/handler/integrity_test.go +++ b/internal/handler/integrity_test.go @@ -5,6 +5,7 @@ import ( "crypto/sha512" "encoding/base64" "encoding/hex" + "errors" "io" "strings" "testing" @@ -15,42 +16,68 @@ func sha256Hex(data string) string { return hex.EncodeToString(sum[:]) } +func sha256SRI(data string) string { + sum := sha256.Sum256([]byte(data)) + return "sha256-" + base64.StdEncoding.EncodeToString(sum[:]) +} + +func sha384SRI(data string) string { + sum := sha512.Sum384([]byte(data)) + return "sha384-" + base64.StdEncoding.EncodeToString(sum[:]) +} + func sha512SRI(data string) string { sum := sha512.Sum512([]byte(data)) return "sha512-" + base64.StdEncoding.EncodeToString(sum[:]) } -func TestParseSRI(t *testing.T) { - tests := []struct { - name string - input string - algo string - ok bool - }{ - {"sha512", sha512SRI("hello"), "sha512", true}, - {"sha256", "sha256-" + base64.StdEncoding.EncodeToString([]byte("0123456789012345678901234567890123456789")), "sha256", true}, - {"empty", "", "", false}, - {"no dash", "sha512abc", "", false}, - {"bad base64", "sha512-not!base64", "", false}, - {"unsupported algo", "md5-" + base64.StdEncoding.EncodeToString([]byte("x")), "", false}, - {"multi hash takes first", sha512SRI("a") + " " + sha512SRI("b"), "sha512", true}, - {"whitespace", " " + sha512SRI("x") + " ", "sha512", true}, +func wrapIntegrityReader(t *testing.T, source io.ReadCloser, contentHash, native string, onMismatch func(string)) io.ReadCloser { + t.Helper() + checks, err := newIntegrityChecks(contentHash, native) + if err != nil { + t.Fatalf("newIntegrityChecks: %v", err) } + reader, err := checks.wrap(source, onMismatch) + if err != nil { + t.Fatalf("wrap: %v", err) + } + return reader +} - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - algo, digest, ok := parseSRI(tt.input) - if ok != tt.ok { - t.Fatalf("ok = %v, want %v", ok, tt.ok) - } - if !tt.ok { - return - } - if algo != tt.algo { - t.Errorf("algo = %q, want %q", algo, tt.algo) - } - if len(digest) == 0 { - t.Error("digest is empty") +func TestNewIntegrityChecksCollectsAlgorithms(t *testing.T) { + checks, err := newIntegrityChecks( + sha256Hex("hello"), + strings.Join([]string{sha256SRI("first"), sha512SRI("second"), sha384SRI("third"), sha512SRI("alternative")}, " "), + ) + if err != nil { + t.Fatal(err) + } + if len(checks.algorithms) != 5 { + t.Fatalf("algorithms = %v, want 5 entries", checks.algorithms) + } + if len(checks.native) != 4 { + t.Errorf("native digests = %d, want 4", len(checks.native)) + } +} + +func TestNewIntegrityChecksRejectsMalformedMetadata(t *testing.T) { + tests := []struct { + name string + contentHash string + native string + }{ + {name: "short content hash", contentHash: "abc123"}, + {name: "non-hex content hash", contentHash: strings.Repeat("z", sha256.Size*2)}, + {name: "missing SRI separator", native: "sha512"}, + {name: "malformed SRI base64", native: "sha512-not!base64"}, + {name: "wrong SRI length", native: "sha512-" + base64.StdEncoding.EncodeToString([]byte("short"))}, + {name: "unsupported SRI algorithm", native: "md5-1B2M2Y8AsgTpgAmY7PhCfg=="}, + {name: "invalid SRI alternative", native: sha512SRI("valid") + " sha384-nope"}, + } + for _, test := range tests { + t.Run(test.name, func(t *testing.T) { + if _, err := newIntegrityChecks(test.contentHash, test.native); err == nil { + t.Fatal("newIntegrityChecks returned nil error") } }) } @@ -67,69 +94,156 @@ func TestVerifyingReader(t *testing.T) { sri string wantCalls int }{ - {"both match", goodSHA, goodSRI, 0}, - {"sha256 only match", goodSHA, "", 0}, - {"sri only match", "", goodSRI, 0}, - {"sha256 mismatch", sha256Hex("other"), "", 1}, - {"sri mismatch", "", sha512SRI("other"), 1}, - {"both mismatch", sha256Hex("other"), sha512SRI("other"), 2}, - {"no checks", "", "", 0}, - {"unparseable sri ignored", goodSHA, "garbage", 0}, + {name: "both match", hash: goodSHA, sri: goodSRI}, + {name: "SHA-256 only match", hash: goodSHA}, + {name: "SRI only match", sri: goodSRI}, + {name: "SHA-256 mismatch", hash: sha256Hex("other"), wantCalls: 1}, + {name: "SRI mismatch", sri: sha512SRI("other"), wantCalls: 1}, + {name: "both mismatch", hash: sha256Hex("other"), sri: sha512SRI("other"), wantCalls: 2}, + {name: "no checks"}, } - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { + for _, test := range tests { + t.Run(test.name, func(t *testing.T) { var calls []string - r := newVerifyingReader(io.NopCloser(strings.NewReader(data)), tt.hash, tt.sri, + reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader(data)), test.hash, test.sri, func(reason string) { calls = append(calls, reason) }) - got, err := io.ReadAll(r) + got, err := io.ReadAll(reader) if err != nil { t.Fatalf("ReadAll: %v", err) } if string(got) != data { t.Errorf("data corrupted: got %q", got) } - if err := r.Close(); err != nil { + if err := reader.Close(); err != nil { t.Fatalf("Close: %v", err) } - - if len(calls) != tt.wantCalls { - t.Errorf("onMismatch called %d times, want %d: %v", len(calls), tt.wantCalls, calls) + if len(calls) != test.wantCalls { + t.Errorf("onMismatch called %d times, want %d: %v", len(calls), test.wantCalls, calls) } }) } } -func TestVerifyingReaderPassthrough(t *testing.T) { - src := io.NopCloser(strings.NewReader("x")) - r := newVerifyingReader(src, "", "", func(string) { t.Fatal("should not be called") }) - if r != src { - t.Error("expected passthrough when no hashes provided") +func TestVerifyingReaderUsesStrongestNativeAlgorithm(t *testing.T) { + const data = "artifact" + tests := []struct { + name string + native string + wantCalls int + }{ + { + name: "weaker match does not override stronger mismatch", + native: sha256SRI(data) + " " + sha512SRI("other"), + wantCalls: 1, + }, + { + name: "stronger match ignores weaker mismatch", + native: sha256SRI("other") + " " + sha512SRI(data), + }, + { + name: "same algorithm alternative matches", + native: sha512SRI("other") + " " + sha512SRI(data), + }, + } + for _, test := range tests { + t.Run(test.name, func(t *testing.T) { + var calls int + reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader(data)), "", test.native, func(string) { calls++ }) + if _, err := io.Copy(io.Discard, reader); err != nil { + t.Fatal(err) + } + if calls != test.wantCalls { + t.Errorf("onMismatch called %d times, want %d", calls, test.wantCalls) + } + }) } } -func TestVerifyingReaderPartialRead(t *testing.T) { - var calls int - r := newVerifyingReader(io.NopCloser(strings.NewReader("hello world")), - sha256Hex("hello world"), "", func(string) { calls++ }) +func TestVerifyingReaderMismatchMessages(t *testing.T) { + const data = "actual" + wantHash := sha256Hex("expected") + wantSRI := sha512SRI("expected") + var reasons []string + reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader(data)), wantHash, wantSRI, + func(reason string) { reasons = append(reasons, reason) }) + if _, err := io.Copy(io.Discard, reader); err != nil { + t.Fatal(err) + } + if len(reasons) != 2 { + t.Fatalf("reasons = %v, want two", reasons) + } + wantContentReason := "content_hash: integrity mismatch: expected " + sha256SRI("expected") + ", calculated " + sha256SRI(data) + if reasons[0] != wantContentReason { + t.Errorf("content reason = %q, want %q", reasons[0], wantContentReason) + } + wantNativeReason := "integrity: integrity mismatch: expected " + wantSRI + ", calculated " + sha512SRI(data) + if reasons[1] != wantNativeReason { + t.Errorf("native reason = %q, want %q", reasons[1], wantNativeReason) + } +} - buf := make([]byte, 5) - _, _ = r.Read(buf) - _ = r.Close() +func TestVerifyingReaderPassthrough(t *testing.T) { + source := io.NopCloser(strings.NewReader("x")) + reader := wrapIntegrityReader(t, source, "", "", func(string) { t.Fatal("should not be called") }) + if reader != source { + t.Error("expected passthrough when no hashes were provided") + } +} + +type closeTrackingReader struct { + io.Reader + closed bool +} + +func (r *closeTrackingReader) Close() error { + r.closed = true + return nil +} + +func TestVerifyingReaderPartialRead(t *testing.T) { + source := &closeTrackingReader{Reader: strings.NewReader("hello world")} + var calls int + reader := wrapIntegrityReader(t, source, sha256Hex("other"), "", func(string) { calls++ }) + + buffer := make([]byte, 5) + _, _ = reader.Read(buffer) + _ = reader.Close() if calls != 0 { t.Errorf("onMismatch called %d times for partial read, want 0", calls) } + if !source.closed { + t.Error("Close was not forwarded to the source") + } +} + +func TestVerifyingReaderNonEOFError(t *testing.T) { + var calls int + reader := wrapIntegrityReader(t, io.NopCloser(errorFixtureReader{}), sha256Hex("data"), "", func(string) { calls++ }) + if _, err := io.ReadAll(reader); !errors.Is(err, errIntegrityReadFixture) { + t.Fatalf("ReadAll error = %v", err) + } + if calls != 0 { + t.Errorf("onMismatch called %d times after non-EOF error", calls) + } +} + +var errIntegrityReadFixture = errors.New("integrity read fixture") + +type errorFixtureReader struct{} + +func (errorFixtureReader) Read(p []byte) (int, error) { + return copy(p, "data"), errIntegrityReadFixture } func TestVerifyingReaderVerifyOnce(t *testing.T) { var calls int - r := newVerifyingReader(io.NopCloser(strings.NewReader("x")), sha256Hex("y"), "", - func(string) { calls++ }) - _, _ = io.ReadAll(r) - _ = r.Close() - _ = r.Close() + reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader("x")), sha256Hex("y"), "", func(string) { calls++ }) + _, _ = io.ReadAll(reader) + _ = reader.Close() + _ = reader.Close() if calls != 1 { t.Errorf("onMismatch called %d times, want 1", calls) } diff --git a/internal/httpclient/access_log.go b/internal/httpclient/access_log.go new file mode 100644 index 0000000..8e13f23 --- /dev/null +++ b/internal/httpclient/access_log.go @@ -0,0 +1,74 @@ +package httpclient + +import ( + "log/slog" + "net/http" + "net/url" + "strings" + "time" + + "github.com/git-pkgs/proxy/internal/accesslog" +) + +type accessLogTransport struct { + base http.RoundTripper + accessLog *accesslog.Logger + logger *slog.Logger +} + +// NewAccessLogTransport records each upstream HTTP exchange around base. +func NewAccessLogTransport(base http.RoundTripper, log *accesslog.Logger, logger *slog.Logger) http.RoundTripper { + if base == nil { + base = http.DefaultTransport + } + if logger == nil { + logger = slog.Default() + } + if log == nil { + return base + } + return &accessLogTransport{ + base: base, + accessLog: log, + logger: logger, + } +} + +func (t *accessLogTransport) RoundTrip(req *http.Request) (*http.Response, error) { + start := time.Now() + resp, err := t.base.RoundTrip(req) + + entry := accesslog.Entry{ + Event: accesslog.EventUpstream, + RequestID: accesslog.RequestID(req.Context()), + Method: req.Method, + URL: accesslog.URLWithoutSecrets(req.URL), + DurationMS: time.Since(start).Milliseconds(), + } + if resp != nil { + entry.StatusCode = resp.StatusCode + } + if err != nil { + entry.Error = errorWithoutSecrets(err, req.URL) + } + if writeErr := t.accessLog.Write(entry); writeErr != nil { + t.logger.Error("failed to write access log", "error", writeErr) + } + + return resp, err +} + +func errorWithoutSecrets(err error, requestURL *url.URL) string { + message := err.Error() + if requestURL == nil { + return message + } + + cleanURL := accesslog.URLWithoutSecrets(requestURL) + for _, value := range []string{requestURL.String(), requestURL.Redacted()} { + if value != "" { + message = strings.ReplaceAll(message, value, cleanURL) + } + } + return message +} diff --git a/internal/httpclient/access_log_test.go b/internal/httpclient/access_log_test.go new file mode 100644 index 0000000..aa3a43c --- /dev/null +++ b/internal/httpclient/access_log_test.go @@ -0,0 +1,121 @@ +package httpclient + +import ( + "bufio" + "encoding/json" + "errors" + "io" + "log/slog" + "net/http" + "os" + "path/filepath" + "strings" + "testing" + + "github.com/git-pkgs/proxy/internal/accesslog" +) + +type roundTripFunc func(*http.Request) (*http.Response, error) + +func (f roundTripFunc) RoundTrip(req *http.Request) (*http.Response, error) { + return f(req) +} + +func TestAccessLogTransportRecordsUpstreamStatus(t *testing.T) { + path := filepath.Join(t.TempDir(), "access.jsonl") + accessLogger, err := accesslog.Open(path) + if err != nil { + t.Fatal(err) + } + + base := roundTripFunc(func(req *http.Request) (*http.Response, error) { + return &http.Response{ + StatusCode: http.StatusTooManyRequests, + Body: io.NopCloser(strings.NewReader("rate limited")), + Request: req, + }, nil + }) + client := &http.Client{Transport: NewAccessLogTransport(base, accessLogger, slog.Default())} + req, err := http.NewRequest(http.MethodGet, "https://user:password@registry.example/package.tgz?token=secret", nil) + if err != nil { + t.Fatal(err) + } + req = req.WithContext(accesslog.WithRequestID(req.Context(), "request-123")) + + resp, err := client.Do(req) + if err != nil { + t.Fatal(err) + } + _ = resp.Body.Close() + if err := accessLogger.Close(); err != nil { + t.Fatal(err) + } + + entry := readAccessLogEntry(t, path) + if entry.Event != accesslog.EventUpstream { + t.Errorf("event = %q, want %q", entry.Event, accesslog.EventUpstream) + } + if entry.RequestID != "request-123" { + t.Errorf("request_id = %q, want %q", entry.RequestID, "request-123") + } + if entry.StatusCode != http.StatusTooManyRequests { + t.Errorf("status_code = %d, want %d", entry.StatusCode, http.StatusTooManyRequests) + } + if entry.URL != "https://registry.example/package.tgz" { + t.Errorf("url = %q, want URL without credentials or query", entry.URL) + } +} + +func TestAccessLogTransportRecordsUpstreamError(t *testing.T) { + path := filepath.Join(t.TempDir(), "access.jsonl") + accessLogger, err := accesslog.Open(path) + if err != nil { + t.Fatal(err) + } + + wantErr := errors.New("GET https://user:password@registry.example/package.tgz?token=secret: connection refused") + base := roundTripFunc(func(*http.Request) (*http.Response, error) { + return nil, wantErr + }) + client := &http.Client{Transport: NewAccessLogTransport(base, accessLogger, slog.Default())} + + _, err = client.Get("https://user:password@registry.example/package.tgz?token=secret") + if !errors.Is(err, wantErr) { + t.Fatalf("GET error = %v, want %v", err, wantErr) + } + if err := accessLogger.Close(); err != nil { + t.Fatal(err) + } + + entry := readAccessLogEntry(t, path) + if entry.StatusCode != 0 { + t.Errorf("status_code = %d, want 0", entry.StatusCode) + } + if strings.Contains(entry.Error, "password") || strings.Contains(entry.Error, "secret") { + t.Errorf("error contains URL credentials or query: %q", entry.Error) + } + if !strings.Contains(entry.Error, "connection refused") { + t.Errorf("error = %q, want connection failure", entry.Error) + } +} + +func readAccessLogEntry(t *testing.T, path string) accesslog.Entry { + t.Helper() + + file, err := os.Open(path) + if err != nil { + t.Fatal(err) + } + defer func() { _ = file.Close() }() + + scanner := bufio.NewScanner(file) + if !scanner.Scan() { + t.Fatalf("access log is empty: %v", scanner.Err()) + } + + var entry accesslog.Entry + if err := json.Unmarshal(scanner.Bytes(), &entry); err != nil { + t.Fatalf("decoding access log: %v", err) + } + return entry +} diff --git a/internal/metrics/metrics.go b/internal/metrics/metrics.go index f23a5a9..df47222 100644 --- a/internal/metrics/metrics.go +++ b/internal/metrics/metrics.go @@ -6,6 +6,7 @@ import ( "strconv" "time" + "github.com/git-pkgs/purl" "github.com/prometheus/client_golang/prometheus" "github.com/prometheus/client_golang/prometheus/promhttp" ) @@ -173,12 +174,12 @@ func RecordRequest(ecosystem string, status int, duration time.Duration) { // RecordCacheHit increments cache hit counter. func RecordCacheHit(ecosystem string) { - CacheHits.WithLabelValues(ecosystem).Inc() + CacheHits.WithLabelValues(purl.NormalizeEcosystem(ecosystem)).Inc() } // RecordCacheMiss increments cache miss counter. func RecordCacheMiss(ecosystem string) { - CacheMisses.WithLabelValues(ecosystem).Inc() + CacheMisses.WithLabelValues(purl.NormalizeEcosystem(ecosystem)).Inc() } // RecordUpstreamFetch tracks upstream fetch duration. diff --git a/internal/metrics/metrics_test.go b/internal/metrics/metrics_test.go index 445a715..a445467 100644 --- a/internal/metrics/metrics_test.go +++ b/internal/metrics/metrics_test.go @@ -6,6 +6,7 @@ import ( "time" "github.com/prometheus/client_golang/prometheus" + "github.com/prometheus/client_golang/prometheus/testutil" dto "github.com/prometheus/client_model/go" ) @@ -191,22 +192,45 @@ func TestMetricsEndpointOutput(t *testing.T) { func TestMetricsLabeling(t *testing.T) { // Test that different ecosystems are properly labeled - ecosystems := []string{"npm", "pypi", "cargo", "gem"} + ecosystems := []struct { + input string + label string + }{ + {input: "npm", label: "npm"}, + {input: "pypi", label: "pypi"}, + {input: "cargo", label: "cargo"}, + {input: "gem", label: "rubygems"}, + } for _, eco := range ecosystems { - RecordRequest(eco, 200, 10*time.Millisecond) - RecordCacheHit(eco) + RecordRequest(eco.input, 200, 10*time.Millisecond) + RecordCacheHit(eco.input) } // Verify each ecosystem has metrics for _, eco := range ecosystems { - val := getMetricValue(t, CacheHits, eco) + val := getMetricValue(t, CacheHits, eco.label) if val == 0 { - t.Errorf("no cache hits recorded for %s", eco) + t.Errorf("no cache hits recorded for %s", eco.label) } } } +func TestCacheMetricLabelsAreNormalized(t *testing.T) { + rubyHitsBefore := testutil.ToFloat64(CacheHits.WithLabelValues("rubygems")) + composerMissesBefore := testutil.ToFloat64(CacheMisses.WithLabelValues("packagist")) + + RecordCacheHit("gem") + RecordCacheMiss("composer") + + if diff := testutil.ToFloat64(CacheHits.WithLabelValues("rubygems")) - rubyHitsBefore; diff != 1 { + t.Errorf("rubygems cache hits delta = %.0f, want 1", diff) + } + if diff := testutil.ToFloat64(CacheMisses.WithLabelValues("packagist")) - composerMissesBefore; diff != 1 { + t.Errorf("packagist cache misses delta = %.0f, want 1", diff) + } +} + func TestMetricNames(t *testing.T) { // Verify metric names follow Prometheus naming conventions expectedMetrics := []string{ diff --git a/internal/mirror/registry.go b/internal/mirror/registry.go deleted file mode 100644 index 6b2c449..0000000 --- a/internal/mirror/registry.go +++ /dev/null @@ -1,16 +0,0 @@ -package mirror - -import ( - "context" - "fmt" -) - -// RegistrySource enumerates all packages in a registry for full mirroring. -// Registry enumeration is not yet implemented for any ecosystem. -type RegistrySource struct { - Ecosystem string -} - -func (s *RegistrySource) Enumerate(_ context.Context, _ func(PackageVersion) error) error { - return fmt.Errorf("registry enumeration is not yet implemented for ecosystem %q", s.Ecosystem) -} diff --git a/internal/mirror/registry_test.go b/internal/mirror/registry_test.go deleted file mode 100644 index 363bfea..0000000 --- a/internal/mirror/registry_test.go +++ /dev/null @@ -1,46 +0,0 @@ -package mirror - -import ( - "context" - "testing" -) - -func TestRegistrySourceUnsupported(t *testing.T) { - source := &RegistrySource{Ecosystem: "golang"} - err := source.Enumerate(context.Background(), func(pv PackageVersion) error { - return nil - }) - if err == nil { - t.Fatal("expected error for unsupported ecosystem") - } -} - -func TestRegistrySourceNPMNotImplemented(t *testing.T) { - source := &RegistrySource{Ecosystem: "npm"} - err := source.Enumerate(context.Background(), func(pv PackageVersion) error { - return nil - }) - if err == nil { - t.Fatal("expected not-implemented error") - } -} - -func TestRegistrySourcePyPINotImplemented(t *testing.T) { - source := &RegistrySource{Ecosystem: "pypi"} - err := source.Enumerate(context.Background(), func(pv PackageVersion) error { - return nil - }) - if err == nil { - t.Fatal("expected not-implemented error") - } -} - -func TestRegistrySourceCargoNotImplemented(t *testing.T) { - source := &RegistrySource{Ecosystem: "cargo"} - err := source.Enumerate(context.Background(), func(pv PackageVersion) error { - return nil - }) - if err == nil { - t.Fatal("expected not-implemented error") - } -} diff --git a/internal/server/browse_test.go b/internal/server/browse_test.go index 3cc37c8..f4f2f9a 100644 --- a/internal/server/browse_test.go +++ b/internal/server/browse_test.go @@ -430,6 +430,10 @@ func TestHandleBrowseSourcePage(t *testing.T) { } } + if !strings.Contains(body, "proxy test-version (test-commit)") { + t.Error("browse source footer should contain proxy build information, not the package version") + } + // Check that the escapeHTML function is present for XSS protection if !strings.Contains(body, "function escapeHTML(str)") { t.Error("browse source page missing escapeHTML function for XSS protection") diff --git a/internal/server/eviction_test.go b/internal/server/eviction_test.go index 9fa9e6b..80badbe 100644 --- a/internal/server/eviction_test.go +++ b/internal/server/eviction_test.go @@ -15,7 +15,7 @@ import ( "github.com/git-pkgs/proxy/internal/storage" ) -func setupEvictionTest(t *testing.T) (*database.DB, *storage.Filesystem) { +func setupEvictionTest(t *testing.T) (*database.DB, *storage.Blob) { t.Helper() tempDir := t.TempDir() @@ -27,7 +27,7 @@ func setupEvictionTest(t *testing.T) (*database.DB, *storage.Filesystem) { t.Fatalf("failed to create database: %v", err) } - store, err := storage.NewFilesystem(storagePath) + store, err := storage.OpenBucket(context.Background(), "file://"+storagePath) if err != nil { _ = db.Close() t.Fatalf("failed to create storage: %v", err) @@ -243,7 +243,7 @@ func TestStartEvictionLoop_UnlimitedSkips(t *testing.T) { } defer func() { _ = db.Close() }() - store, err := storage.NewFilesystem(storagePath) + store, err := storage.OpenBucket(context.Background(), "file://"+storagePath) if err != nil { t.Fatalf("failed to create storage: %v", err) } @@ -280,7 +280,7 @@ func defaultTestConfig(storagePath, dbPath string) *config.Config { return &config.Config{ Listen: ":8080", BaseURL: "http://localhost:8080", - Storage: config.StorageConfig{Path: storagePath, MaxSize: ""}, + Storage: config.StorageConfig{URL: "file://" + storagePath, MaxSize: ""}, Database: config.DatabaseConfig{ Driver: "sqlite", Path: dbPath, diff --git a/internal/server/health_test.go b/internal/server/health_test.go index c0f70c9..3b7eae8 100644 --- a/internal/server/health_test.go +++ b/internal/server/health_test.go @@ -32,7 +32,7 @@ type fakeStorage struct { // Failure injection. storeErr error openErr error - readErr error // returned by the io.ReadCloser.Read after partial bytes + readErr error // returned by the io.ReadCloser.Read after partial bytes deleteErr error // Misbehavior knobs. @@ -132,8 +132,8 @@ func (f *fakeStorage) SignedURL(ctx context.Context, path string, expiry time.Du return "", storage.ErrSignedURLUnsupported } func (f *fakeStorage) UsedSpace(ctx context.Context) (int64, error) { return 0, nil } -func (f *fakeStorage) URL() string { return "fake://" } -func (f *fakeStorage) Close() error { return nil } +func (f *fakeStorage) URL() string { return "fake://" } +func (f *fakeStorage) Close() error { return nil } // --- Tests follow. First test: happy path --- diff --git a/internal/server/layout.go b/internal/server/layout.go index ef39858..2da9469 100644 --- a/internal/server/layout.go +++ b/internal/server/layout.go @@ -2,17 +2,24 @@ package server import "net/http" -// Layout carries per-request fields consumed by the shared base template -// (canonical URL, og:url). It is embedded in every page data struct so that -// templates can reference {{.UIBaseURL}} and {{.CanonicalPath}} alongside the -// page's own fields. +// BuildInfo identifies the running proxy binary. +type BuildInfo struct { + Version string + Commit string +} + +// Layout carries shared fields consumed by the base template. It is embedded +// in every page data struct so templates can access canonical URL and build +// information alongside the page's own fields. type Layout struct { + BuildInfo BuildInfo UIBaseURL string CanonicalPath string } func (s *Server) layoutFor(r *http.Request) Layout { return Layout{ + BuildInfo: s.buildInfo, UIBaseURL: s.cfg.UIBaseURL, CanonicalPath: r.URL.Path, } diff --git a/internal/server/middleware.go b/internal/server/middleware.go index 9b81254..b6d483f 100644 --- a/internal/server/middleware.go +++ b/internal/server/middleware.go @@ -3,16 +3,15 @@ package server import ( "context" "net/http" + "strings" "sync/atomic" "time" + "github.com/git-pkgs/proxy/internal/accesslog" + "github.com/git-pkgs/proxy/internal/metrics" "github.com/go-chi/chi/v5/middleware" ) -type contextKey string - -const requestIDKey contextKey = "request_id" - var requestCounter atomic.Uint64 // RequestIDMiddleware adds a sequential request ID to the context and response headers. @@ -23,7 +22,7 @@ func RequestIDMiddleware(next http.Handler) http.Handler { requestID := middleware.GetReqID(r.Context()) // Store formatted ID in context - ctx := context.WithValue(r.Context(), requestIDKey, requestID) + ctx := accesslog.WithRequestID(r.Context(), requestID) // Add to response header for client tracking w.Header().Set("X-Request-ID", requestID) @@ -34,10 +33,7 @@ func RequestIDMiddleware(next http.Handler) http.Handler { // GetRequestID retrieves the request ID from context. func GetRequestID(ctx context.Context) string { - if id, ok := ctx.Value(requestIDKey).(string); ok { - return id - } - return "" + return accesslog.RequestID(ctx) } // LoggerMiddleware logs HTTP requests with request ID correlation. @@ -48,27 +44,51 @@ func (s *Server) LoggerMiddleware(next http.Handler) http.Handler { rw := &responseWriter{ResponseWriter: w, status: http.StatusOK} next.ServeHTTP(rw, r) + duration := time.Since(start) s.logger.Info("request", "request_id", requestID, "method", r.Method, "path", r.URL.Path, "status", rw.status, - "duration", time.Since(start), + "duration", duration, "remote", r.RemoteAddr) - }) -} -// ActiveRequestsMiddleware tracks the number of active requests using Prometheus metrics. -func ActiveRequestsMiddleware(next http.Handler) http.Handler { - return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - // Don't track metrics endpoint itself - if r.URL.Path == "/metrics" { - next.ServeHTTP(w, r) - return + if r.URL.Path != "/metrics" { + metrics.RecordRequest(requestEcosystem(r.URL.Path), rw.status, duration) } - // Implemented in server.go where metrics package is imported - next.ServeHTTP(w, r) + if s.accessLog != nil { + if err := s.accessLog.Write(accesslog.Entry{ + Event: accesslog.EventRequest, + RequestID: requestID, + Method: r.Method, + Path: r.URL.EscapedPath(), + StatusCode: rw.status, + DurationMS: duration.Milliseconds(), + RemoteAddr: r.RemoteAddr, + }); err != nil { + s.logger.Error("failed to write access log", "error", err) + } + } }) } + +func requestEcosystem(path string) string { + segment, _, _ := strings.Cut(strings.TrimPrefix(path, "/"), "/") + switch segment { + case "npm", "cargo", "hex", "pub", "pypi", "maven", "gradle", "nuget", + "conan", "conda", "cran", "julia", "debian", "rpm": + return segment + case "gem": + return "rubygems" + case "go": + return "golang" + case "composer": + return "packagist" + case "v2": + return "oci" + default: + return "other" + } +} diff --git a/internal/server/middleware_test.go b/internal/server/middleware_test.go index 75c6ccd..38905b2 100644 --- a/internal/server/middleware_test.go +++ b/internal/server/middleware_test.go @@ -2,13 +2,21 @@ package server import ( "context" + "encoding/json" "io" "log/slog" "net/http" "net/http/httptest" + "os" + "path/filepath" "testing" + "github.com/git-pkgs/proxy/internal/accesslog" + "github.com/git-pkgs/proxy/internal/metrics" "github.com/go-chi/chi/v5/middleware" + "github.com/prometheus/client_golang/prometheus" + "github.com/prometheus/client_golang/prometheus/testutil" + dto "github.com/prometheus/client_model/go" ) func TestRequestIDMiddleware(t *testing.T) { @@ -45,7 +53,7 @@ func TestGetRequestID(t *testing.T) { }{ { name: "with request ID", - ctx: context.WithValue(context.Background(), requestIDKey, "test-123"), + ctx: accesslog.WithRequestID(context.Background(), "test-123"), expected: "test-123", }, { @@ -65,36 +73,6 @@ func TestGetRequestID(t *testing.T) { } } -func TestActiveRequestsMiddleware(t *testing.T) { - handler := ActiveRequestsMiddleware(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - w.WriteHeader(http.StatusOK) - })) - - req := httptest.NewRequest(http.MethodGet, "/test", nil) - rec := httptest.NewRecorder() - - handler.ServeHTTP(rec, req) - - if rec.Code != http.StatusOK { - t.Errorf("expected status 200, got %d", rec.Code) - } -} - -func TestActiveRequestsMiddleware_SkipsMetricsEndpoint(t *testing.T) { - handler := ActiveRequestsMiddleware(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - w.WriteHeader(http.StatusOK) - })) - - req := httptest.NewRequest(http.MethodGet, "/metrics", nil) - rec := httptest.NewRecorder() - - handler.ServeHTTP(rec, req) - - if rec.Code != http.StatusOK { - t.Errorf("expected status 200, got %d", rec.Code) - } -} - func TestLoggerMiddleware(t *testing.T) { logger := slog.New(slog.NewTextHandler(io.Discard, nil)) s := &Server{logger: logger} @@ -121,6 +99,133 @@ func TestLoggerMiddleware(t *testing.T) { } } +func TestLoggerMiddlewareRecordsRequestMetrics(t *testing.T) { + before := testutil.ToFloat64(metrics.RequestsTotal.WithLabelValues("rubygems", "404")) + durationMetric := metrics.RequestDuration.WithLabelValues("rubygems", "404") + beforeDurationCount := histogramSampleCount(t, durationMetric) + + logger := slog.New(slog.NewTextHandler(io.Discard, nil)) + s := &Server{logger: logger} + handler := s.LoggerMiddleware(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { + w.WriteHeader(http.StatusNotFound) + })) + + req := httptest.NewRequest(http.MethodGet, "/gem/downloads/missing.gem", nil) + rec := httptest.NewRecorder() + handler.ServeHTTP(rec, req) + + after := testutil.ToFloat64(metrics.RequestsTotal.WithLabelValues("rubygems", "404")) + if got := after - before; got != 1 { + t.Errorf("request counter delta = %.0f, want 1", got) + } + afterDurationCount := histogramSampleCount(t, durationMetric) + if got := afterDurationCount - beforeDurationCount; got != 1 { + t.Errorf("request duration sample delta = %d, want 1", got) + } +} + +func histogramSampleCount(t *testing.T, observer prometheus.Observer) uint64 { + t.Helper() + + metric, ok := observer.(prometheus.Metric) + if !ok { + t.Fatal("histogram observer does not implement prometheus.Metric") + } + + var value dto.Metric + if err := metric.Write(&value); err != nil { + t.Fatalf("writing histogram metric: %v", err) + } + return value.GetHistogram().GetSampleCount() +} + +func TestLoggerMiddlewareSkipsMetricsEndpointMetrics(t *testing.T) { + before := testutil.ToFloat64(metrics.RequestsTotal.WithLabelValues("other", "200")) + + logger := slog.New(slog.NewTextHandler(io.Discard, nil)) + s := &Server{logger: logger} + handler := s.LoggerMiddleware(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { + w.WriteHeader(http.StatusOK) + })) + + req := httptest.NewRequest(http.MethodGet, "/metrics", nil) + rec := httptest.NewRecorder() + handler.ServeHTTP(rec, req) + + after := testutil.ToFloat64(metrics.RequestsTotal.WithLabelValues("other", "200")) + if got := after - before; got != 0 { + t.Errorf("request counter delta = %.0f, want 0", got) + } +} + +func TestRequestEcosystem(t *testing.T) { + tests := []struct { + path string + want string + }{ + {path: "/npm/lodash", want: "npm"}, + {path: "/gem/downloads/rails.gem", want: "rubygems"}, + {path: "/go/example.com/module/@v/list", want: "golang"}, + {path: "/composer/vendor/package", want: "packagist"}, + {path: "/v2/library/alpine/manifests/latest", want: "oci"}, + {path: "/ui/", want: "other"}, + {path: "/api/package/npm/lodash", want: "other"}, + {path: "/", want: "other"}, + } + + for _, tt := range tests { + t.Run(tt.path, func(t *testing.T) { + if got := requestEcosystem(tt.path); got != tt.want { + t.Errorf("requestEcosystem(%q) = %q, want %q", tt.path, got, tt.want) + } + }) + } +} + +func TestLoggerMiddlewareWritesAccessLog(t *testing.T) { + path := filepath.Join(t.TempDir(), "access.jsonl") + activityLog, err := accesslog.Open(path) + if err != nil { + t.Fatal(err) + } + + logger := slog.New(slog.NewTextHandler(io.Discard, nil)) + s := &Server{logger: logger, accessLog: activityLog} + next := http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { + w.WriteHeader(http.StatusNotFound) + }) + handler := middleware.RequestID(RequestIDMiddleware(s.LoggerMiddleware(next))) + + req := httptest.NewRequest(http.MethodGet, "/packages/example?token=secret", nil) + rec := httptest.NewRecorder() + handler.ServeHTTP(rec, req) + + if err := activityLog.Close(); err != nil { + t.Fatal(err) + } + data, err := os.ReadFile(path) + if err != nil { + t.Fatal(err) + } + + var entry accesslog.Entry + if err := json.Unmarshal(data, &entry); err != nil { + t.Fatalf("decoding access log: %v", err) + } + if entry.Event != accesslog.EventRequest { + t.Errorf("event = %q, want %q", entry.Event, accesslog.EventRequest) + } + if entry.RequestID == "" { + t.Error("request_id is empty") + } + if entry.Path != "/packages/example" { + t.Errorf("path = %q, want query string omitted", entry.Path) + } + if entry.StatusCode != http.StatusNotFound { + t.Errorf("status_code = %d, want %d", entry.StatusCode, http.StatusNotFound) + } +} + func TestResponseWriter_WriteHeader(t *testing.T) { tests := []struct { name string diff --git a/internal/server/server.go b/internal/server/server.go index e677bc9..bb964e8 100644 --- a/internal/server/server.go +++ b/internal/server/server.go @@ -61,6 +61,7 @@ import ( "github.com/git-pkgs/cooldown" swaggerdoc "github.com/git-pkgs/proxy/docs/swagger" + "github.com/git-pkgs/proxy/internal/accesslog" "github.com/git-pkgs/proxy/internal/config" "github.com/git-pkgs/proxy/internal/database" "github.com/git-pkgs/proxy/internal/enrichment" @@ -91,14 +92,31 @@ type Server struct { db *database.DB storage storage.Storage logger *slog.Logger + buildInfo BuildInfo http *http.Server templates *Templates cancel context.CancelFunc healthCache *healthCache + accessLog *accesslog.Logger } // New creates a new Server with the given configuration. -func New(cfg *config.Config, logger *slog.Logger) (*Server, error) { +func New(cfg *config.Config, logger *slog.Logger, buildInfo BuildInfo) (*Server, error) { + var activityLog *accesslog.Logger + if cfg.AccessLog.Path != "" { + var err error + activityLog, err = accesslog.Open(cfg.AccessLog.Path) + if err != nil { + return nil, fmt.Errorf("initializing access log: %w", err) + } + } + closeAccessLog := true + defer func() { + if closeAccessLog && activityLog != nil { + _ = activityLog.Close() + } + }() + // Initialize database var db *database.DB var err error @@ -147,14 +165,18 @@ func New(cfg *config.Config, logger *slog.Logger) (*Server, error) { return nil, fmt.Errorf("initializing health cache: %w", err) } - return &Server{ + server := &Server{ cfg: cfg, db: db, storage: store, logger: logger, + buildInfo: buildInfo, templates: &Templates{}, healthCache: hc, - }, nil + accessLog: activityLog, + } + closeAccessLog = false + return server, nil } // Start starts the HTTP server. @@ -162,7 +184,11 @@ func (s *Server) Start() error { // Use one authentication-aware transport for metadata and artifacts so // configured credentials and cached OCI challenges apply consistently. safeClient := safehttp.New(nil, safehttp.Options{}) - authTransport := upstreamhttp.NewTransport(safeClient.Transport, upstreamhttp.AuthFunc(s.authForURL)) + baseTransport := safeClient.Transport + if s.accessLog != nil { + baseTransport = upstreamhttp.NewAccessLogTransport(baseTransport, s.accessLog, s.logger) + } + authTransport := upstreamhttp.NewTransport(baseTransport, upstreamhttp.AuthFunc(s.authForURL)) metadataClient := *safeClient metadataClient.Timeout = s.cfg.ParseHTTPTimeout() metadataClient.Transport = authTransport @@ -235,7 +261,8 @@ func (s *Server) Start() error { condaHandler := handler.NewCondaHandler(proxy, s.cfg.BaseURL) cranHandler := handler.NewCRANHandler(proxy, s.cfg.BaseURL) juliaHandler := handler.NewJuliaHandler(proxy, s.cfg.BaseURL) - containerHandler := handler.NewContainerHandler(proxy, s.cfg.BaseURL) + containerHandler := handler.NewContainerHandler(proxy, s.cfg.BaseURL, s.cfg.Upstream.OCI) + helmHandler := handler.NewHelmHandler(proxy, s.cfg.BaseURL, s.cfg.Upstream.Helm) debianHandler := handler.NewDebianHandler(proxy, s.cfg.BaseURL, s.cfg.Upstream.Debian) rpmHandler := handler.NewRPMHandler(proxy, s.cfg.BaseURL) @@ -255,6 +282,7 @@ func (s *Server) Start() error { r.Mount("/cran", http.StripPrefix("/cran", cranHandler.Routes())) r.Mount("/julia", http.StripPrefix("/julia", juliaHandler.Routes())) r.Mount("/v2", http.StripPrefix("/v2", containerHandler.Routes())) + r.Mount("/helm", http.StripPrefix("/helm", helmHandler.Routes())) r.Mount("/debian", http.StripPrefix("/debian", debianHandler.Routes())) r.Mount("/rpm", http.StripPrefix("/rpm", rpmHandler.Routes())) @@ -373,6 +401,12 @@ func (s *Server) Shutdown(ctx context.Context) error { } } + if s.accessLog != nil { + if err := s.accessLog.Close(); err != nil { + errs = append(errs, fmt.Errorf("access log close: %w", err)) + } + } + if s.db != nil { if err := s.db.Close(); err != nil { errs = append(errs, fmt.Errorf("database close: %w", err)) diff --git a/internal/server/server_test.go b/internal/server/server_test.go index 98b58cc..77c32ae 100644 --- a/internal/server/server_test.go +++ b/internal/server/server_test.go @@ -1,6 +1,7 @@ package server import ( + "context" "database/sql" "encoding/json" "fmt" @@ -51,7 +52,7 @@ func newTestServer(t *testing.T) *testServer { t.Fatalf("failed to create database: %v", err) } - store, err := storage.NewFilesystem(storagePath) + store, err := storage.OpenBucket(context.Background(), "file://"+storagePath) if err != nil { _ = db.Close() _ = os.RemoveAll(tempDir) @@ -65,7 +66,7 @@ func newTestServer(t *testing.T) *testServer { cfg := &config.Config{ BaseURL: "http://localhost:8080", - Storage: config.StorageConfig{Path: storagePath}, + Storage: config.StorageConfig{URL: "file://" + storagePath}, Database: config.DatabaseConfig{Path: dbPath}, } @@ -104,6 +105,7 @@ func newTestServer(t *testing.T) *testServer { db: db, storage: store, logger: logger, + buildInfo: BuildInfo{Version: "test-version", Commit: "test-commit"}, templates: &Templates{}, healthCache: hc, } @@ -313,6 +315,9 @@ func TestDashboard(t *testing.T) { if !strings.Contains(body, "Cached Artifacts") { t.Error("dashboard should contain stats") } + if !strings.Contains(body, "proxy test-version (test-commit)") { + t.Error("dashboard footer should contain build information") + } if !strings.Contains(body, "Popular Packages") { t.Error("dashboard should contain popular packages section") } @@ -598,6 +603,9 @@ func TestVersionShowWithHitCount(t *testing.T) { if !strings.Contains(body, "42 cache hits") { t.Error("expected page to show hit count") } + if !strings.Contains(body, "proxy test-version (test-commit)") { + t.Error("version show footer should contain proxy build information, not the package version") + } } func TestSearchWithNullValues(t *testing.T) { @@ -1327,10 +1335,14 @@ func TestNewServer_StorageConnectivityCheck(t *testing.T) { logger := slog.New(slog.NewTextHandler(io.Discard, nil)) - srv, err := New(cfg, logger) + buildInfo := BuildInfo{Version: "test-version", Commit: "test-commit"} + srv, err := New(cfg, logger, buildInfo) if err != nil { t.Fatalf("New() failed: %v", err) } + if srv.buildInfo != buildInfo { + t.Errorf("build info = %#v, want %#v", srv.buildInfo, buildInfo) + } // On Windows, OpenBucket normalises to file:///C:/path; on Unix the // absolute path already starts with /, so file:// + /path == file:///path. @@ -1344,6 +1356,27 @@ func TestNewServer_StorageConnectivityCheck(t *testing.T) { _ = srv.db.Close() } +func TestNewServer_InvalidAccessLogFailsBeforeDatabaseInit(t *testing.T) { + tempDir := t.TempDir() + dbPath := filepath.Join(tempDir, "test.db") + cfg := &config.Config{ + Storage: config.StorageConfig{URL: "file://" + filepath.Join(tempDir, "artifacts")}, + Database: config.DatabaseConfig{Path: dbPath}, + AccessLog: config.AccessLogConfig{Path: filepath.Join(tempDir, "missing", "access.jsonl")}, + } + + logger := slog.New(slog.NewTextHandler(io.Discard, nil)) + if _, err := New(cfg, logger, BuildInfo{}); err == nil { + t.Fatal("New() succeeded with invalid access log path") + } else if !strings.Contains(err.Error(), "initializing access log") { + t.Fatalf("New() error = %v, want access log initialization error", err) + } + + if _, err := os.Stat(dbPath); !os.IsNotExist(err) { + t.Errorf("database initialized before access log validation: %v", err) + } +} + func TestStatsEndpoint_StorageURL(t *testing.T) { ts := newTestServer(t) defer ts.close() diff --git a/internal/server/templates/layout/footer.html b/internal/server/templates/layout/footer.html index 5aa970d..33daddf 100644 --- a/internal/server/templates/layout/footer.html +++ b/internal/server/templates/layout/footer.html @@ -12,6 +12,11 @@ github.com/git-pkgs/proxy
+ {{if .BuildInfo.Version}} ++ proxy {{.BuildInfo.Version}}{{if .BuildInfo.Commit}} ({{.BuildInfo.Commit}}){{end}} +
+ {{end}}