Documentation
¶
Overview ¶
Package tools installs and manages the pnpm and Trivy binaries that sealift's jobs run as subprocesses.
Index ¶
- Variables
- type Manager
- func (m *Manager) ActivateTrivy(version string) error
- func (m *Manager) EnsurePnpm(ctx context.Context, version string) (string, error)
- func (m *Manager) InstalledPnpm() ([]string, error)
- func (m *Manager) InstalledTrivy() ([]string, error)
- func (m *Manager) Ready() (ready bool, missing []string)
- func (m *Manager) TrivyState(ctx context.Context) (TrivyState, error)
- func (m *Manager) UpdateTrivy(ctx context.Context, version string, force bool) (string, error)
- type TrivyState
- type Volume
Constants ¶
This section is empty.
Variables ¶
var ErrChecksumMismatch = errors.New("trivy asset checksum mismatch")
ErrChecksumMismatch reports a downloaded Trivy asset whose sha256 does not match the release's checksums file.
var ErrInvalidTrivyVersion = errors.New("trivy version must be a release number such as 0.74.0")
ErrInvalidTrivyVersion reports a requested Trivy version that is not a plain X.Y.Z release number.
ErrReleaseSourceUnavailable reports that GitHub, where Trivy releases come from, did not answer usefully: unreachable, rate-limited or down.
var ErrReleaseTooRecent = errors.New("trivy release is too recent")
ErrReleaseTooRecent reports a Trivy release younger than the configured minimum age, refused unless the caller forces the install.
Functions ¶
This section is empty.
Types ¶
type Manager ¶
type Manager struct {
// NPMRegistry overrides the npm registry base URL. Empty uses the
// public registry; tests point it at an httptest server.
NPMRegistry string
// GitHubAPI overrides the GitHub API base URL. Empty uses the public
// API; tests point it at an httptest server.
GitHubAPI string
// Arch overrides the host CPU architecture used to pick the Trivy
// release asset. Empty uses runtime.GOARCH.
Arch string
// contains filtered or unexported fields
}
Manager installs pnpm and Trivy under the data volume and switches which installed Trivy version is active.
func NewManager ¶
NewManager returns a Manager that installs tools into vol's data volume, using httpClient for every registry and release request.
func (*Manager) ActivateTrivy ¶
ActivateTrivy points tools/trivy/current at an installed version, rolling back when version is an older one already on disk. The switch is a single rename of a relative symlink, so it never leaves the directory in a half-updated state.
func (*Manager) EnsurePnpm ¶
EnsurePnpm installs the given pnpm version from the npm registry if it is not already present, and returns the path to its package/bin/pnpm.cjs. The minimum release age does not apply: the caller pins the version.
It takes the same lock UpdateTrivy and ActivateTrivy do: two concurrent installs of the same version would otherwise share the one fixed "<version>.tmp" staging directory installDir uses. Today the queue only ever runs one job at a time, which is the only caller, so this is not yet reachable; tools.Manager still needs to enforce its own safety rather than depend on that.
func (*Manager) InstalledPnpm ¶
InstalledPnpm lists every pnpm version present under tools/pnpm/, sorted.
func (*Manager) InstalledTrivy ¶
InstalledTrivy lists every Trivy version present under tools/trivy/, sorted, excluding the current symlink.
func (*Manager) Ready ¶ added in v0.2.0
Ready reports whether an analysis or export can run without sealift installing anything on its own: an active Trivy, a vulnerability database and a signature key, all already on the data volume. It never reaches the network: what an analysis needs is what is already there, not what GitHub currently offers.
func (*Manager) TrivyState ¶
func (m *Manager) TrivyState(ctx context.Context) (TrivyState, error)
TrivyState reports the active and installed Trivy versions, the latest release on GitHub and its age, and the vulnerability database's date. A GitHub outage leaves Latest and LatestAge zero rather than failing the whole call: the installed and active versions, and the database date, come from the data volume alone and stay meaningful without GitHub.
func (*Manager) UpdateTrivy ¶
UpdateTrivy installs a Trivy release and activates it: the latest one when version is empty, or the named one, such as the Recommended TrivyState reported, otherwise. It refuses a release younger than Settings().MinReleaseAgeDays unless force is true. The checksum catches corruption, not a compromised release; the minimum age is the protection against that, so a caller offering a specific version keeps the user in control of trading it away, the same as force does for the latest.
type TrivyState ¶
type TrivyState struct {
Active string // version behind tools/trivy/current, empty if none
Installed []string // every version present under tools/trivy/, sorted
Latest string // latest version on GitHub
LatestAge time.Duration // time since the latest release was published
LatestSizeBytes int64 // size of the release asset for this host, 0 if unknown
DBDate time.Time // last update of the vulnerability database, zero if unknown
// Recommended is the newest release old enough to install without
// force, set only while Latest itself is younger than the minimum
// age: installing it needs no force and keeps the age check's
// purpose (not the newest possible code, code that has had time for
// a compromised release to be caught) intact. Empty when Latest is
// already old enough, or when none of the releases this checks is.
Recommended string
RecommendedAge time.Duration
}
TrivyState summarizes the installed and available Trivy versions.