• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

zentralopensource / zentral / 32706729750
91%

Build:
DEFAULT BRANCH: main
Ran 24 Aug 2026 08:42AM UTC
Jobs 1
Files 1030
Run time 2min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

24 Aug 2026 08:10AM UTC coverage: 90.048% (+0.01%) from 90.034%
32706729750

push

github

np5
osquery: publish audit events from the management views

Osquery was the last large module with no zentral_audit event. Creating, updating
or deleting a configuration, a pack, a query, an automatic table construction, a
file category, an enrollment or a distributed query run from the web console left
no record at all, and no test in the module asserted a single event.

The Zentral Terraform provider manages seven of these objects: the automatic
table constructions, the configurations, the configuration packs, the
enrollments, the file categories, the packs and the queries. They are managed as
code, so the event that matters is the one for a change that did not come from
the Terraform configuration.

Runs are the exception: the provider does not manage them, and they are audited
for a different reason. A run executes operator SQL on the machines.

Twenty-four views move to the CreateViewWithAudit / UpdateViewWithAudit /
DeleteViewWithAudit bases. The two enrollment views that drive two forms or
implement post() themselves cannot, and call post_audit_event(). The pack upload
keeps the osquery_pack_update events for now, because it goes through
update_or_create_pack, which needs its own change.

"Halt current runs" ended every other active run of the query with a queryset
update: no save, no signal, no instance, and so no event from a view that only
knows its own object. Creating one run stopped three others and the trail
recorded one change. DistributedQuery.objects.halt_for_query() reads the rows
before the update and reports them, so each stopped run gets its own event. The
form receives the request to publish them, like UploadPackForm.

Five models had no serialize_for_event(): the automatic table constructions, the
configurations, the configuration packs, the file categories and the distributed
queries. AuditEvent.build() calls it with no fallback, so they come first. The
enrollments, the configuration packs and the runs also declare their linked
ob... (continued)

96 of 96 new or added lines in 9 files covered. (100.0%)

23 existing lines in 2 files now uncovered.

51203 of 56862 relevant lines covered (90.05%)

0.9 hits per line

Coverage Regressions

Lines Coverage ∆ File
20
95.37
0.83% zentral/contrib/osquery/models.py
3
89.59
0.0% zentral/contrib/inventory/models.py
Jobs
ID Job ID Ran Files Coverage
1 32706729750.1 24 Aug 2026 08:42AM UTC 1030
90.05
GitHub Action Run
Source Files on build 32706729750
  • Tree
  • List 1030
  • Changed 12
  • Source Changed 12
  • Coverage Changed 9
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #32706729750
  • a14e5e5d on github
  • Prev Build on main (#32590711602)
  • Next Build on main (#32709568252)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc