tools

package
v0.2.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 23, 2026 License: GPL-3.0 Imports: 23 Imported by: 0

Documentation

Overview

Package tools installs and manages the pnpm and Trivy binaries that sealift's jobs run as subprocesses.

Index

Constants

This section is empty.

Variables

View Source
var ErrChecksumMismatch = errors.New("trivy asset checksum mismatch")

ErrChecksumMismatch reports a downloaded Trivy asset whose sha256 does not match the release's checksums file.

View Source
var ErrInvalidTrivyVersion = errors.New("trivy version must be a release number such as 0.74.0")

ErrInvalidTrivyVersion reports a requested Trivy version that is not a plain X.Y.Z release number.

View Source
var ErrReleaseSourceUnavailable = errors.New("could not reach GitHub to look up Trivy releases")

ErrReleaseSourceUnavailable reports that GitHub, where Trivy releases come from, did not answer usefully: unreachable, rate-limited or down.

View Source
var ErrReleaseTooRecent = errors.New("trivy release is too recent")

ErrReleaseTooRecent reports a Trivy release younger than the configured minimum age, refused unless the caller forces the install.

Functions

This section is empty.

Types

type Manager

type Manager struct {

	// NPMRegistry overrides the npm registry base URL. Empty uses the
	// public registry; tests point it at an httptest server.
	NPMRegistry string
	// GitHubAPI overrides the GitHub API base URL. Empty uses the public
	// API; tests point it at an httptest server.
	GitHubAPI string
	// Arch overrides the host CPU architecture used to pick the Trivy
	// release asset. Empty uses runtime.GOARCH.
	Arch string
	// contains filtered or unexported fields
}

Manager installs pnpm and Trivy under the data volume and switches which installed Trivy version is active.

func NewManager

func NewManager(vol Volume, httpClient *http.Client, log *slog.Logger) *Manager

NewManager returns a Manager that installs tools into vol's data volume, using httpClient for every registry and release request.

func (*Manager) ActivateTrivy

func (m *Manager) ActivateTrivy(version string) error

ActivateTrivy points tools/trivy/current at an installed version, rolling back when version is an older one already on disk. The switch is a single rename of a relative symlink, so it never leaves the directory in a half-updated state.

func (*Manager) EnsurePnpm

func (m *Manager) EnsurePnpm(ctx context.Context, version string) (string, error)

EnsurePnpm installs the given pnpm version from the npm registry if it is not already present, and returns the path to its package/bin/pnpm.cjs. The minimum release age does not apply: the caller pins the version.

It takes the same lock UpdateTrivy and ActivateTrivy do: two concurrent installs of the same version would otherwise share the one fixed "<version>.tmp" staging directory installDir uses. Today the queue only ever runs one job at a time, which is the only caller, so this is not yet reachable; tools.Manager still needs to enforce its own safety rather than depend on that.

func (*Manager) InstalledPnpm

func (m *Manager) InstalledPnpm() ([]string, error)

InstalledPnpm lists every pnpm version present under tools/pnpm/, sorted.

func (*Manager) InstalledTrivy

func (m *Manager) InstalledTrivy() ([]string, error)

InstalledTrivy lists every Trivy version present under tools/trivy/, sorted, excluding the current symlink.

func (*Manager) Ready added in v0.2.0

func (m *Manager) Ready() (ready bool, missing []string)

Ready reports whether an analysis or export can run without sealift installing anything on its own: an active Trivy, a vulnerability database and a signature key, all already on the data volume. It never reaches the network: what an analysis needs is what is already there, not what GitHub currently offers.

func (*Manager) TrivyState

func (m *Manager) TrivyState(ctx context.Context) (TrivyState, error)

TrivyState reports the active and installed Trivy versions, the latest release on GitHub and its age, and the vulnerability database's date. A GitHub outage leaves Latest and LatestAge zero rather than failing the whole call: the installed and active versions, and the database date, come from the data volume alone and stay meaningful without GitHub.

func (*Manager) UpdateTrivy

func (m *Manager) UpdateTrivy(ctx context.Context, version string, force bool) (string, error)

UpdateTrivy installs a Trivy release and activates it: the latest one when version is empty, or the named one, such as the Recommended TrivyState reported, otherwise. It refuses a release younger than Settings().MinReleaseAgeDays unless force is true. The checksum catches corruption, not a compromised release; the minimum age is the protection against that, so a caller offering a specific version keeps the user in control of trading it away, the same as force does for the latest.

type TrivyState

type TrivyState struct {
	Active          string        // version behind tools/trivy/current, empty if none
	Installed       []string      // every version present under tools/trivy/, sorted
	Latest          string        // latest version on GitHub
	LatestAge       time.Duration // time since the latest release was published
	LatestSizeBytes int64         // size of the release asset for this host, 0 if unknown
	DBDate          time.Time     // last update of the vulnerability database, zero if unknown
	// Recommended is the newest release old enough to install without
	// force, set only while Latest itself is younger than the minimum
	// age: installing it needs no force and keeps the age check's
	// purpose (not the newest possible code, code that has had time for
	// a compromised release to be caught) intact. Empty when Latest is
	// already old enough, or when none of the releases this checks is.
	Recommended    string
	RecommendedAge time.Duration
}

TrivyState summarizes the installed and available Trivy versions.

type Volume

type Volume interface {
	Root() string
	Settings() store.Settings
}

Volume is the narrow view of the data volume that Manager needs. The store package builds it; a caller outside the container can supply any implementation with the same root and settings.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL