Skip to content

Add detection pack registry and publishing workflows - #36

Merged
egrexsec merged 3 commits into
mainfrom
feature/pack-registry
May 29, 2026
Merged

egrexsec merged 3 commits into
mainfrom
feature/pack-registry

Conversation

@egrexsec

Copy link
Copy Markdown
Owner

Summary

Implements registry-oriented detection pack distribution workflows.

Changes

  • Added detection pack build workflows
  • Added pack publishing support
  • Added pack installation support
  • Added checksum generation
  • Added semantic version metadata generation
  • Added local registry cache workflows
  • Added registry metadata manifests
  • Added registry workflow tests
  • Expanded documentation

Example Workflows

detlab pack build packs/windows-core

detlab pack publish packs/windows-core

detlab pack install windows-core

@egrexsec
egrexsec merged commit ab5980a into main May 29, 2026
1 check failed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ccb9760777

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread detlab/registry.py
install_dir.mkdir(parents=True, exist_ok=True)

with tarfile.open(archive_path, "r:gz") as tar:
tar.extractall(path=install_dir)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Reject unsafe tar members before extraction

When install_pack is used on a pack archive from a registry or another user, tar.extractall on the supported Python 3.11/3.12 targets will honor member names such as ../../... and can overwrite files outside .detlab/registry. Please validate that every member resolves under install_dir (and handle links/devices appropriately) or use a safe extraction filter before unpacking downloaded packs.

Useful? React with 👍 / 👎.

Comment thread README.md
### Build Detection Pack

```bash
detlab pack build packs/windows-core

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Wire the documented pack CLI before advertising it

These new workflows are documented as detlab pack ..., but I checked the actual console entry point (pyproject.toml points detlab at detlab.main:app) and detlab/main.py still only registers the existing top-level commands; there is no pack Typer sub-app or command. As a result, users following this README will get an unknown-command error instead of being able to build, publish, or install packs.

Useful? React with 👍 / 👎.

@egrexsec
egrexsec deleted the feature/pack-registry branch June 16, 2026 12:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant