The pattern-analysis worker dropped two signals on every run. When InsertIfNotExists hit a pre-existing glob, the computed bestSource was discarded by the LoadByBannerIDTypeAndPattern fallback, so the SCRIPT > EXTENSION > PRE_EXISTING precedence advertised on bestSource was only ever enforced at first insert. Subsequent batches with stronger sources could not promote the glob, even though the page-script-wins rule already lives in detected_trackers at the row level. Separately, adoptUncategorisedPatterns returned an adopted bool that the worker discarded; the function moves detected trackers from uncategorised exact patterns into categorised globs, which is a real consent transition, but no draft banner version was created on adoption-only runs. Add a focused TrackerPattern.PromoteSource that only updates the source and updated_at columns. Express the precedence as a pure-Go shouldPromoteSource helper alongside bestSource so the rule is unit-testable without a database. The worker now calls InsertIfNotExists, then on conflict loads, skips when the slot is held by an exact pattern or a user-recategorised glob, and only calls PromoteSource when the candidate source ranks above the existing one. The skip branch is now documented: adoptUncategorisedPatterns is the safety net that re-homes uncategorised exacts into the existing glob via globMatch. Capture its adopted return value and use it (instead of the previous over-eager consentChanged flag) to gate ensureDraftVersionForBanner. Merging exacts into a glob in their own category never changes visitor consent, so the prior flag produced redundant draft versions on every non-uncategorised merge. Cover the new pieces with three test layers: pure-unit cases for shouldPromoteSource (precedence matrix including HTTP/nil collapse and equal-rank no-write), DB-backed tests for PromoteSource (touch only source + updated_at, ErrResourceNotFound for missing rows), and end-to-end worker tests for source promotion on an existing glob, draft-on-adoption, and the merge-only no-draft case. Signed-off-by: Émile Ré <emile@probo.com>
Probo is an open-source compliance platform built for startups that helps you achieve SOC-2 compliance quickly and efficiently. Unlike traditional solutions, Probo is designed to be accessible, transparent, and community-driven.
🚀 Getting Started
Prerequisites
- Go 1.21+
- Node.js 22+
- Docker
- mkcert
Quick Start
-
Clone the repository:
git clone --recurse-submodules https://github.com/getprobo/probo.git cd probo -
Install dependencies:
# Install Go dependencies go mod download # Install Node.js dependencies npm ci -
Start the development environment:
# Start infrastructure services make stack-up # Build the project make build # Generate the local dev config (writes cfg/dev.yaml) make dev-config # Start the application using development settings bin/probod -cfg-file cfg/dev.yaml
The application will be available at:
- Application: http://localhost:8080
Testing Custom Domains
To test the custom domains feature locally, add the CNAME target to your hosts file:
# Add this line to /etc/hosts (macOS/Linux) or C:\Windows\System32\drivers\etc\hosts (Windows)
127.0.0.1 custom.getprobo.com
This allows you to test custom trust center domains on your local machine. The generated cfg/dev.yaml sets the CNAME target via custom-domains.cname-target; change CUSTOM_DOMAINS_CNAME_TARGET before running make dev-config to override it.
For detailed setup instructions, see our Contributing Guide.
🏗️ Current Status
Probo is in early development, focusing on building a solid foundation for compliance management.
🛠️ Tech Stack
Backend
- Go - API server
- PostgreSQL - Data storage
- GraphQL - API layer
Frontend
- React with TypeScript
- Relay - Data fetching
- TailwindCSS - Styling
Infrastructure
- Docker - Containerization
- OpenTelemetry - Observability
- GitHub Actions - CI/CD
Observability
- Grafana - Metrics visualization
- Prometheus - Metrics collection
- Loki - Log aggregation
- Tempo - Distributed tracing
🤝 Contributing
We love contributions from our community! There are many ways to contribute:
- 🌟 Star the repository to show your support
- 🐛 Report bugs
- 💡 Request features
- 🔧 Submit pull requests
- 📖 Improve documentation
Please read our Contributing Guide before making a pull request.
📚 Documentation
🌐 Community & Support
- Join our Discord community
- Follow us on Twitter
- Connect on LinkedIn
- Visit our website
📄 License
Probo is MIT licensed.