Skip to content

Conversation

@mbg
Copy link
Member

@mbg mbg commented Feb 2, 2026

This PR adds a new diagnostic for when the Go extractor successfully discovers private registries. The goal of this is to make this easy to see on the Tool Status Page, rather than requiring users to follow the process in https://docs.github.com/en/code-security/how-tos/view-and-interpret-data/viewing-code-scanning-logs#determining-whether-code-scanning-default-setup-used-any-private-registries

@mbg mbg self-assigned this Feb 2, 2026
@github-actions github-actions bot added the Go label Feb 2, 2026
@mbg mbg marked this pull request as ready for review February 2, 2026 16:03
@mbg mbg requested review from a team as code owners February 2, 2026 16:03
Copilot AI review requested due to automatic review settings February 2, 2026 16:03
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a Go extractor diagnostic that surfaces detected private registry usage on the Tool Status Page, and refactors the proxy/registry helpers into a dedicated package.

Changes:

  • Move the registry proxy logic from util into a new registries package and update the toolchain to use it.
  • Emit a new diagnostic when Go-relevant private registry configurations are detected.
  • Add/adjust tests to cover the new diagnostic behavior.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
go/extractor/util/BUILD.bazel Removes the registry proxy sources/tests from util after the move.
go/extractor/toolchain/toolchain.go Switches GoCommand to apply proxy env vars via the new registries package.
go/extractor/toolchain/BUILD.bazel Adds Bazel dependency on //go/extractor/registries.
go/extractor/registries/registryproxy.go Hosts proxy env-var parsing and now emits the private-registry diagnostic.
go/extractor/registries/registryproxy_test.go Updates test package name to registries after the move.
go/extractor/registries/BUILD.bazel Introduces Bazel targets for the new registries package and its tests.
go/extractor/diagnostics/diagnostics.go Adds EmitPrivateRegistryUsed diagnostic emitter.
go/extractor/diagnostics/diagnostics_test.go Adds a unit test for EmitPrivateRegistryUsed.

owen-mc
owen-mc previously approved these changes Feb 3, 2026
Copy link
Contributor

@owen-mc owen-mc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Two very minor nits about efficiency, which only really matter if you expect the slices to be long.

owen-mc
owen-mc previously approved these changes Feb 3, 2026
Copy link
Contributor

@owen-mc owen-mc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM (pending tests passing - it's possible my suggestions don't compile or something)

Co-authored-by: Owen Mansel-Chan <62447351+owen-mc@users.noreply.github.com>
@mbg mbg force-pushed the mbg/go/private-registry-diagnostic branch from d238988 to d5c4a19 Compare February 3, 2026 10:34
@mbg mbg requested a review from owen-mc February 3, 2026 10:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants