Skip to content

Latest commit

 

History

History
37 lines (28 loc) · 5.46 KB

File metadata and controls

37 lines (28 loc) · 5.46 KB

CodeArtifact

Parity grade: A · SDK aws-sdk-go-v2/service/codeartifact@v1.41.4 · last audited 2026-09-18 (1d121bbad)

Coverage

Metric Value
PARITY entries audited 48 (41 ok, 7 partial)
Feature families 4 (4 ok)
Known gaps 9
Deferred items 3
Resource leaks clean

Known gaps

  • Package-group 'weak match' confusable-character normalization (the third rule of AWS's dependency-confusion-protection algorithm, alongside casefolding and dash/dot/underscore-run collapsing — both of which ARE implemented this pass, see package_group_pattern_matching family note) is not implemented. It requires the full Unicode confusables table (real, external data — genuinely buildable, not structural, but this pass didn't have room to vendor and verify it faithfully). A package that differs from a group's exact pattern only by a confusable-character substitution (e.g. a Cyrillic look-alike) will not be detected as either a strong or weak match by this backend. (bd: gopherstack-u9e5 follow-up)
  • Origin-restriction configuration (PackageGroupOriginRestriction mode/ALLOW-BLOCK, weak-match blocking) is fully modeled and returned by the API (CreatePackageGroup/DescribePackageGroup/UpdatePackageGroupOriginConfiguration/GetAssociatedPackageGroup's associationType) but is NOT enforced anywhere: PublishPackageVersion and package-version ingestion never consult a package's associated group's origin restrictions, for either STRONG or WEAK-matched packages. Real AWS's core dependency-confusion protection is precisely this enforcement ("the package is blocked instead of applying the group's origin control configuration" for a WEAK match) — this backend computes the classification but does not act on it. Found this pass while implementing weak-match classification; pre-existing (not introduced this pass), and a materially larger feature (wiring restriction checks into the publish/ingestion path) than the classification logic itself. (bd: gopherstack-u9e5 follow-up)
  • This backend does not auto-create the implicit root package group ('/*') that real AWS attaches to every domain and forbids deleting. Adding it would change GetAssociatedPackageGroup/ListPackageGroups behavior on a domain with zero explicitly-created groups (several existing tests assert 'no groups yet' -> empty list / no match), so it was deliberately left out this pass rather than rewriting that test surface; flagged for a future pass. (bd: gopherstack-u9e5 follow-up)
  • DescribePackage / DescribePackageVersion auto-create a stub record when the resource doesn't exist, instead of returning ResourceNotFoundException like real AWS. This is pre-existing, intentionally-documented behavior, reconfirmed this pass to be extremely load-bearing test-seeding infrastructure (60+ call sites across handler_package_versions_test.go, handler_package_versions_assets_test.go, persistence_test.go, handler_packages_test.go use GET as a seed operation), so ripping it out remains a large, independently-scoped migration — not touched this pass either. Real behavioral divergence from AWS. (bd: gopherstack-u9e5 follow-up)
  • GetPackageVersionReadme / ListPackageVersionDependencies now parse real content from a published package.json asset (npm convention — see the ops table), but still return empty for any format/publish that doesn't include a standalone package.json asset (e.g. a real npm tarball, a Maven POM, or any non-npm format) — this backend's single-asset-per-call publish model doesn't unpack archives.
  • 2026-09-18 (gopherstack-xhu2t reqfielddiff tier-1): CopyPackageVersionsInput.IncludeFromUpstream (documented default false, api_op_CopyPackageVersions.go:69-71) is not declared on this op's request struct at all. Not fixed: Repository.UpstreamRepositories is real, stored, per-repository config (repositories.go), but it is inert bookkeeping everywhere else in this backend too — no op ever resolves a package version through an upstream repository chain (grepped every UpstreamRepositories call site, all are Create/UpdateRepository storage or DescribeRepository echo). CopyPackageVersions only ever looks up packageVersions in the literal source repository. There is no 'version available only via upstream' concept anywhere in this backend for the flag to toggle. Missing feature, not a narrow fix.
  • GetAuthorizationToken returns a fabricated token string rather than any real credential material; acceptable since nothing validates it downstream, but flagged in case a future op starts checking it.
  • domain-owner / cross-account query param is accepted by real AWS on nearly every op (for cross-account domain access) but is not read anywhere in this backend; single-account-only is assumed throughout.
  • ListPackageVersionsInput.OriginType (real filter member, serializers.go's SetQuery("originType")) is not honored -- this backend's PackageVersion model has no per-version origin concept at all (unlike status/sortBy, both fixed this pass, gopherstack-6flj) to filter on; fabricating one would be worse than the current no-op. (bd: gopherstack-6flj follow-up)

Deferred

  • Package-group weak-match confusable-character normalization and origin-restriction enforcement against publish/ingestion (see gaps above)
  • Root package-group auto-creation (see gaps above)
  • store_setup.go was read but not modified — no bugs found, not exhaustively re-audited

More