GitHub
09/03/2026, 8:23 AM0.5.8
Bump to dependencies
Other changes: Docs
README.md — the project tree was missing pkg/alerts/, the only package not
listed. Added it, plus an alerting capability bullet and a Current Highlights
entry (rule scopes, webhook/email channels, Redis cooldown/dedupe, dispatched
history, hot reload, rule creation from a node's page). The operator-UI bullet now
names the surfaces that shipped since it was written — tags, enrollment, audit
log, service config, log sinks, auth providers, alerting — and servicecommands
is relabelled as restart and hot-reload handoff. Version claims were checked
against the tree, not assumed: Go 1.26.5, osquery 5.23.1, Node 22 and the frontend
majors all still match.
frontend/README.md — the purpose paragraph now lists what the SPA actually
manages (alerting, log sinks, auth providers, profile/MFA, audit log, enrollment,
service config). Added components/charts, alerts, and scripts/ to the
directory map; documented that `predev`/`prebuild` run copy-monaco.mjs so Monaco
is self-hosted rather than CDN-loaded; and filled in the stack list with visx +
d3-array/d3-shape, motion, @number-flow/react, react-icons, and
jest-dom/user-event.
make swagger / make openapi-check were failing
swag cannot resolve json.RawMessage at --parseDependencyLevel 1, so
generation died on the first DTO carrying one (handlers.logSinkDTO) and both
targets exited non-zero. Added swaggo's swaggertype:"object" to all nine
json.RawMessage field declarations in the parsed packages — accurate, since each
holds a JSON object:
• `handlers`: logSinkDTO, alertChannelDTO, authProviderDTO (+ three inline
request structs), WebAuthn Credential
• `types`: LogSinkCreateRequest, LogSinkUpdateRequest,
AlertChannelCreateRequest, AlertChannelTestRequest,
ServiceConfigUpdateRequest
Regenerated osctrl-api.yaml as the check instructs. That diff is large
(+944 lines) because the tracked spec had been stale for as long as generation
was broken: it was missing the entire alerts surface (including
/api/v1/alerts/channels/test), log sinks, and auth providers. make openapi-check
now passes.
Go build clean; pkg/types and cmd/api/handlers tests pass. No behavior change —
struct tags and docs only.
jmpsec/osctrlGitHub
09/03/2026, 8:31 AM