• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

zentralopensource / zentral / 32727838240
91%

Build:
DEFAULT BRANCH: main
Ran 24 Aug 2026 12:45PM UTC
Jobs 1
Files 1030
Run time 2min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

24 Aug 2026 12:21PM UTC coverage: 90.064% (+0.02%) from 90.048%
32727838240

push

github

np5
osquery: split the pack import events

An import of a standard pack changes a pack, its pack queries, the queries they
schedule and their compliance checks, in one request. It reported that with two
event types of its own, written two years before AuditEvent existed, under a
comment that called them the audit trail.

They did two jobs at once. One of them, the report of the import, only this event
can do: the result of the import as a whole, including "present", which says that
the import ran and changed nothing, and the counts of the pack queries created,
updated, deleted and left alone. AuditEvent has no action for a change that did
not happen, and describes one object at a time.

The other job, the record of each object, AuditEvent does better. The removed
events carried a partial difference instead of the two values, they never
declared their linked objects, so they did not reach the page of the object they
reported, and one of them reported a pack query and the query it schedules
together, with the SQL of the query under a "query" key.

So the report keeps the first job, and audit events take the second.
osquery_pack_query_update is removed. The import publishes one report and one
audit event per changed object, under one event UUID, the report first.

The response of the endpoint does not change. It still carries the difference
under "updates", which the report does not carry anymore: the two values of the
audit event of the pack say more.

The import used to save a query it adopted from another pack whatever the file
said, because the flag that recorded the change was set before the comparison and
not inside it. That write was invisible. As an audit event it would be a change
whose value before and after are the same, published on every import.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

51 of 51 new or added lines in 4 files covered. (100.0%)

7 existing lines in 1 file now uncovered.

51212 of 56862 relevant lines covered (90.06%)

0.9 hits per line

Coverage Regressions

Lines Coverage ∆ File
7
95.6
0.02% zentral/contrib/osquery/models.py
Jobs
ID Job ID Ran Files Coverage
1 32727838240.1 24 Aug 2026 12:45PM UTC 1030
90.06
GitHub Action Run
Source Files on build 32727838240
  • Tree
  • List 1030
  • Changed 4
  • Source Changed 4
  • Coverage Changed 4
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #32727838240
  • e6834da4 on github
  • Prev Build on main (#32724645246)
  • Next Build on main (#32747338681)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc