Repository navigation
PKG-Defender v1.0.5
PKG-Defender v1.0.5
Released July 8, 2026
What's Changed
Added
- Timing instrumentation in pre-install check: Phase-level timing logging via
time.monotonic()in_run_pre_install_check_asyncfor instant diagnosis of future timeout issues.
Changed
- Feed sync error handling: added
FeedSyncErrorexception class anderror_callbackparameter tosync_all()— callers can now handle per-feed errors without relying solely on the progress callback. - Added
retry_on_busydecorator with exponential backoff for SQLiteOperationalError: database is locked— retries up to 3 times with jittered delays (1 s, 2 s, 4 s) before failing. - DB corruption detection: replaced the soft
PRAGMA integrity_checkwarning with a fatalDatabaseCorruptionErrorexception — corrupted databases are now rejected immediately rather than silently serving stale/partial data. - Removed
sub_feed_progressparameter from OSSF feed progress reporting; replacedclick.echowithconsole.printfor consistent Rich-formatted output. - Setup wizard: replaced the OSSF feed skip/exclusion menu with a GHSA token recommendation. When no GitHub token is configured, the wizard now warns about slower GHSA sync (~2–5 min vs ~1–2 sec), recommends daemon setup (
pkgd daemon start), and offers another chance to add the token. OSSF feed now syncs in ~25 seconds via tarball regardless of token status.
Fixed
-
PRAGMA quick_checkon every connection open (root cause of timeout bugs):get_connection()executedPRAGMA quick_checkon every call, running 5–7 times perpip installcheck against the 668 MB database — cumulative overhead of 30–84 s, exhausting the command timeout budget. Fixed by caching the quick_check result per database path within a process. -
Dead, never-used connection in cache-write path:
dispatcher.pyopened a second connection inwrite_threatthat was never actually used. Removed the unused connection. -
Cache-write
busy_timeoutnow 1 s (was 30 s): Cache-write connections are documented as best-effort; a 30-second busy wait was inconsistent with that contract. Shortened to 1 s to match the best-effort semantics. -
Snapshot retrieval system used stale release tag URL construction from previous system design:
fetch_latest_release()queried/releases/latestinstead of/releases/tags/snapshot-latestvia a fragilegit remotesubprocess —--latestdisplayedN/Aand0for real metadata. Fixed by replacing the subprocess approach with hardcoded repo constants and querying the correct tag endpoint. -
Feed sync progress callback emitted a misleading "completed" message (
(feed_name, 0)) on error paths — changed to emit-1as a sentinel;handle_feed_completenow checks for-1and reports the failure without claiming zero threats found. -
Stack trace leakage:
logger.error(exc_info=result)printed full tracebacks at ERROR level for expected failures (e.g., network timeouts, rate limits). Split into a short ERROR message for the user and a DEBUG-level message with the full exception info for operators. -
Exception handler cascade in
intel sync: reordered handlers soKeyboardInterruptis caught before the genericExceptionblock, preventing tracebacks on Ctrl+C; downgraded error-state write failure from ERROR to WARNING since it's non-critical.
📖 4 Commits since v1.0.4
| Commit | Description | Author |
|---|---|---|
768e5c6 |
chore(release): bump version for v1.0.5 release | Division 7 |
235b517 |
fix(core): cache PRAGMA quick_check per process to fix 30s timeout; remove dead connection; reduce busy_timeout 30s to 5s; update docs |
Division 7 |
d6f260a |
fix(db-snapshot): query correct GitHub release tag for database snapshots; fix snapshot-body.md doc links |
Division 7 |
da3bd1e |
fix(intel-sync): fix error handling, stack traces, DB contention, stale OSSF feed delay warnings, docs update | Division 7 |