feat(github): add NewGithubResolvedPackageURL — SHA+originalRef fragment convention helper - #100
Open
marcellodesales wants to merge 2 commits into
Open
marcellodesales wants to merge 2 commits into
marcellodesales wants to merge 2 commits into
Conversation
… vionix-proj
Adds two new candidate PURL types for GitOps-native packaging:
TypeKustomize = "kustomize"
Kustomize overlays where versioning maps to a git ref (commit SHA, tag,
or branch). Qualifier `overlay` specifies the relative path within the
repo to the kustomization file; qualifier `url` carries the full git
clone URL when not derivable from namespace+name.
Example: pkg:kustomize/github.com/vionix-proj/k8s-config@main?overlay=overlays/production
TypeGit = "git"
Bare git repository references used as package sources — e.g. Kustomize
remote bases or Flux HelmRepository GitOps sources. The namespace is the
git host + org path; the version is the git ref.
Example: pkg:git/github.com/vionix-proj/k8s-config@abc1234
Both types are added to CandidateTypes (not KnownTypes) to reflect their
proposed-but-not-formally-registered status in the upstream PURL spec.
Module path renamed from github.com/package-url/packageurl-go to
github.com/vionix-proj/packageurl-go for this fork. All self-referential
imports in test files updated accordingly.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…ment convention Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR proposes a new helper function
NewGithubResolvedPackageURLthat implements a convention for representing resolved GitHub action/repo references as a single, unambiguous PURL.The problem
GitHub Actions (and other tooling) often pin dependencies using a mutable ref such as a tag (
v4) or branch (main). Security best practice is to resolve these to an immutable commit SHA for supply-chain integrity. However, a bare SHA PURL like:is opaque — a reader cannot tell what human-readable tag or branch it corresponds to without a lookup.
The convention
Encode the original mutable ref as the PURL subpath fragment (
#), so both pieces of information travel together in a single PURL:For reusable workflow references (where the workflow file path also needs to be captured), a
path=qualifier is added:This convention is inspired by purl-spec discussions around canonicalizing resolved VCS references. See the purl-spec issue for the spec proposal (link to be added once a purl-spec issue is opened).
What changed
packageurl.go: AddedNewGithubResolvedPackageURL(owner, repo, resolvedSHA, originalRef, path string) *PackageURL— a thin constructor that wiresTypeGithub, sets the SHA as the version, the original mutable ref as the subpath (fragment), and optionally adds apath=qualifier.packageurl_test.go: AddedTestNewGithubResolvedPackageURLcovering: simple tag ref, branch ref, slash-containing branch ref, and reusable workflow with path qualifier.Backwards compatibility
This is a pure addition — no existing types, constants, or functions are changed.
Test plan
go test ./...passes (all spec fixture tests + new unit tests)NewGithubResolvedPackageURL("actions", "checkout", "<sha>", "v4", "").ToString()returnspkg:github/actions/checkout@<sha>#v4path, thepath=qualifier appears percent-encoded in the output🤖 Generated with Claude Code