Skip to content

PKG-Defender v1.0.5

Choose a tag to compare

@github-actions github-actions released this 08 Jul 06:27
· 102 commits to main since this release
v1.0.5
cf31727
PKG-Defender logo

PKG-Defender v1.0.5

Released July 8, 2026


What's Changed

Added

  • Timing instrumentation in pre-install check: Phase-level timing logging via time.monotonic() in _run_pre_install_check_async for instant diagnosis of future timeout issues.

Changed

  • Feed sync error handling: added FeedSyncError exception class and error_callback parameter to sync_all() — callers can now handle per-feed errors without relying solely on the progress callback.
  • Added retry_on_busy decorator with exponential backoff for SQLite OperationalError: database is locked — retries up to 3 times with jittered delays (1 s, 2 s, 4 s) before failing.
  • DB corruption detection: replaced the soft PRAGMA integrity_check warning with a fatal DatabaseCorruptionError exception — corrupted databases are now rejected immediately rather than silently serving stale/partial data.
  • Removed sub_feed_progress parameter from OSSF feed progress reporting; replaced click.echo with console.print for consistent Rich-formatted output.
  • Setup wizard: replaced the OSSF feed skip/exclusion menu with a GHSA token recommendation. When no GitHub token is configured, the wizard now warns about slower GHSA sync (~2–5 min vs ~1–2 sec), recommends daemon setup (pkgd daemon start), and offers another chance to add the token. OSSF feed now syncs in ~25 seconds via tarball regardless of token status.

Fixed

  • PRAGMA quick_check on every connection open (root cause of timeout bugs): get_connection() executed PRAGMA quick_check on every call, running 5–7 times per pip install check against the 668 MB database — cumulative overhead of 30–84 s, exhausting the command timeout budget. Fixed by caching the quick_check result per database path within a process.

  • Dead, never-used connection in cache-write path: dispatcher.py opened a second connection in write_threat that was never actually used. Removed the unused connection.

  • Cache-write busy_timeout now 1 s (was 30 s): Cache-write connections are documented as best-effort; a 30-second busy wait was inconsistent with that contract. Shortened to 1 s to match the best-effort semantics.

  • Snapshot retrieval system used stale release tag URL construction from previous system design: fetch_latest_release() queried /releases/latest instead of /releases/tags/snapshot-latest via a fragile git remote subprocess — --latest displayed N/A and 0 for real metadata. Fixed by replacing the subprocess approach with hardcoded repo constants and querying the correct tag endpoint.

  • Feed sync progress callback emitted a misleading "completed" message ((feed_name, 0)) on error paths — changed to emit -1 as a sentinel; handle_feed_complete now checks for -1 and reports the failure without claiming zero threats found.

  • Stack trace leakage: logger.error(exc_info=result) printed full tracebacks at ERROR level for expected failures (e.g., network timeouts, rate limits). Split into a short ERROR message for the user and a DEBUG-level message with the full exception info for operators.

  • Exception handler cascade in intel sync: reordered handlers so KeyboardInterrupt is caught before the generic Exception block, preventing tracebacks on Ctrl+C; downgraded error-state write failure from ERROR to WARNING since it's non-critical.


📖 4 Commits since v1.0.4
Commit Description Author
768e5c6 chore(release): bump version for v1.0.5 release Division 7
235b517 fix(core): cache PRAGMA quick_check per process to fix 30s timeout; remove dead connection; reduce busy_timeout 30s to 5s; update docs Division 7
d6f260a fix(db-snapshot): query correct GitHub release tag for database snapshots; fix snapshot-body.md doc links Division 7
da3bd1e fix(intel-sync): fix error handling, stack traces, DB contention, stale OSSF feed delay warnings, docs update Division 7

View Complete Changelog →