Add cooldown package pattern overrides - #407
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add
cooldown.package_patternsso operators can set cooldown durations for package families, such as exempting an npm scope withpkg:npm/@example/*. Exact package overrides take precedence over patterns, followed by ecosystem overrides and the global default.Keep pattern matching in the proxy and apply duration selection at the existing cooldown enforcement points, including NuGet metadata and downloads. Support
*and?wildcards that do not cross/separators. Reject character classes and backslash escapes before normalizing@to%40, so normalization cannot change which packages a pattern matches. Validate durations, reject conflicting aliases at startup, and document the order used when multiple patterns match. A cooldown exemption still respects the version denylist.Expose the library's full
Evaluatedecision, including the effective duration, eligibility time and reason, and use it forIsAllowed. This provides the policy result needed by the pending-cooldown report in #338. Publication-time persistence and consistent enforcement on cached downloads remain follow-up work there.This wrapper is a step toward the general version filter in #127. Namespace blocking in #128 needs recursive matching and rejection before upstream access; cooldown patterns use non-recursive wildcards. Filtering support for additional ecosystems is tracked separately in #132.
Replaces #243, building on its policy wrapper and addressing the normalized-pattern collision finding.