Add detection pack registry and publishing workflows - #36
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ccb9760777
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| install_dir.mkdir(parents=True, exist_ok=True) | ||
|
|
||
| with tarfile.open(archive_path, "r:gz") as tar: | ||
| tar.extractall(path=install_dir) |
There was a problem hiding this comment.
Reject unsafe tar members before extraction
When install_pack is used on a pack archive from a registry or another user, tar.extractall on the supported Python 3.11/3.12 targets will honor member names such as ../../... and can overwrite files outside .detlab/registry. Please validate that every member resolves under install_dir (and handle links/devices appropriately) or use a safe extraction filter before unpacking downloaded packs.
Useful? React with 👍 / 👎.
| ### Build Detection Pack | ||
|
|
||
| ```bash | ||
| detlab pack build packs/windows-core |
There was a problem hiding this comment.
Wire the documented pack CLI before advertising it
These new workflows are documented as detlab pack ..., but I checked the actual console entry point (pyproject.toml points detlab at detlab.main:app) and detlab/main.py still only registers the existing top-level commands; there is no pack Typer sub-app or command. As a result, users following this README will get an unknown-command error instead of being able to build, publish, or install packs.
Useful? React with 👍 / 👎.
Summary
Implements registry-oriented detection pack distribution workflows.
Changes
Example Workflows