MCPcopy Create free account
hub / github.com/cli/cli / checkUpstreamProvenance

Function checkUpstreamProvenance

pkg/cmd/skills/install/install.go:1292–1367  ·  view source on GitHub ↗

checkUpstreamProvenance fetches the skill's SKILL.md via the contents API to check if it contains github-repo metadata pointing to a different repository, indicating the skill was re-published from an upstream source. In interactive mode, the user is asked whether to install from the re-publisher or

(opts *InstallOptions, client *api.Client, hostname string, skill discovery.Skill, commitSHA string)

Source from the content-addressed store, hash-verified

1290// installs from the re-publisher.
1291// Returns (repo to redirect to, whether upstream was detected, error).
1292func checkUpstreamProvenance(opts *InstallOptions, client *api.Client, hostname string, skill discovery.Skill, commitSHA string) (ghrepo.Interface, bool, error) {
1293 u, err := safeurl.JoinPath("repos", opts.repo.RepoOwner(), opts.repo.RepoName(), "contents", skill.Path+"/SKILL.md")
1294 if err != nil {
1295 return nil, false, err
1296 }
1297 u.SetQuery("ref", commitSHA)
1298 var fileResp struct {
1299 Content string `json:"content"`
1300 Encoding string `json:"encoding"`
1301 }
1302 if err := client.REST(hostname, "GET", u.String(), nil, &fileResp); err != nil {
1303 return nil, false, nil //nolint:nilerr // best-effort check; failing to fetch is not fatal
1304 }
1305 if fileResp.Encoding != "base64" {
1306 return nil, false, nil
1307 }
1308 decoded, decodeErr := io.ReadAll(base64.NewDecoder(base64.StdEncoding, strings.NewReader(fileResp.Content)))
1309 if decodeErr != nil {
1310 return nil, false, nil //nolint:nilerr // best-effort; decode failure is not fatal
1311 }
1312 content := string(decoded)
1313
1314 result, parseErr := frontmatter.Parse(content)
1315 if parseErr != nil || result.Metadata.Meta == nil {
1316 //nolint:nilerr // unparsable frontmatter means no upstream to detect
1317 return nil, false, nil
1318 }
1319
1320 existingRepo, _ := result.Metadata.Meta["github-repo"].(string)
1321 if existingRepo == "" {
1322 return nil, false, nil
1323 }
1324
1325 currentRepoURL := source.BuildRepoURL(hostname, opts.repo.RepoOwner(), opts.repo.RepoName())
1326 if existingRepo == currentRepoURL {
1327 return nil, false, nil
1328 }
1329
1330 upstreamRepo, parseErr := source.ParseRepoURL(existingRepo)
1331 if parseErr != nil {
1332 //nolint:nilerr // invalid repo URL means we can't redirect; install normally
1333 return nil, false, nil
1334 }
1335
1336 cs := opts.IO.ColorScheme()
1337 upstreamLabel := ghrepo.FullName(upstreamRepo)
1338 repoSource := ghrepo.FullName(opts.repo)
1339
1340 fmt.Fprintf(opts.IO.ErrOut, "%s This skill was originally published in %s\n", cs.WarningIcon(), upstreamLabel)
1341
1342 if opts.Upstream {
1343 fmt.Fprintf(opts.IO.ErrOut, "Redirecting install to %s...\n", upstreamLabel)
1344 return upstreamRepo, true, nil
1345 }
1346
1347 if !opts.IO.CanPrompt() {
1348 fmt.Fprintf(opts.IO.ErrOut, " Installing from %s (use --upstream or interactive mode to choose upstream)\n", repoSource)
1349 return nil, true, nil

Callers 1

installRunFunction · 0.85

Calls 14

JoinPathFunction · 0.92
ParseFunction · 0.92
BuildRepoURLFunction · 0.92
ParseRepoURLFunction · 0.92
FullNameFunction · 0.92
SetQueryMethod · 0.80
ColorSchemeMethod · 0.80
WarningIconMethod · 0.80
CanPromptMethod · 0.80
RepoOwnerMethod · 0.65
RepoNameMethod · 0.65
RESTMethod · 0.65

Tested by

no test coverage detected