The previous cleanup deleted every isExtensionCaller() site, including the one in cookie/storage detectors that did fire reliably for the residual case: page-world extensions (MV3 main world, userscripts with @grant none) whose stack contains a chrome-/moz-/safari-web-extension frame at the synchronous write. Recover that signal for free by returning fromExtension from getInitiatorURL (it already walks the stack and discards extension frames via continue), and have the cookie and storage detectors report source: "extension" instead of "script" when the flag is set. End-to-end plumbing reuses the existing source column: extend the cookie_source Postgres enum with EXTENSION, add the CookieSourceExtension constant with a doc block describing each bucket's actual semantics, add the handler.go switch cases, expose EXTENSION on the GraphQL and MCP CookieSource enums, and add the Extension option to the console source filter. Update bestSource in the pattern analysis worker so a glob merging only extension-attributed exact patterns is no longer silently rolled up to PRE_EXISTING. New precedence is SCRIPT > EXTENSION > PRE_EXISTING, matching the upsert SQL's "page-script wins" rule and the asymmetric signal strength of each bucket. Out of scope: any behavioural use of EXTENSION (auto-exclusion, denylist classification, dashboard surfacing) -- that belongs in the follow-up backend denylist plan. Signed-off-by: Émile Ré <emile@probo.com>
Probo is an open-source compliance platform built for startups that helps you achieve SOC-2 compliance quickly and efficiently. Unlike traditional solutions, Probo is designed to be accessible, transparent, and community-driven.
🚀 Getting Started
Prerequisites
- Go 1.21+
- Node.js 22+
- Docker
- mkcert
Quick Start
-
Clone the repository:
git clone --recurse-submodules https://github.com/getprobo/probo.git cd probo -
Install dependencies:
# Install Go dependencies go mod download # Install Node.js dependencies npm ci -
Start the development environment:
# Start infrastructure services make stack-up # Build the project make build # Generate the local dev config (writes cfg/dev.yaml) make dev-config # Start the application using development settings bin/probod -cfg-file cfg/dev.yaml
The application will be available at:
- Application: http://localhost:8080
Testing Custom Domains
To test the custom domains feature locally, add the CNAME target to your hosts file:
# Add this line to /etc/hosts (macOS/Linux) or C:\Windows\System32\drivers\etc\hosts (Windows)
127.0.0.1 custom.getprobo.com
This allows you to test custom trust center domains on your local machine. The generated cfg/dev.yaml sets the CNAME target via custom-domains.cname-target; change CUSTOM_DOMAINS_CNAME_TARGET before running make dev-config to override it.
For detailed setup instructions, see our Contributing Guide.
🏗️ Current Status
Probo is in early development, focusing on building a solid foundation for compliance management.
🛠️ Tech Stack
Backend
- Go - API server
- PostgreSQL - Data storage
- GraphQL - API layer
Frontend
- React with TypeScript
- Relay - Data fetching
- TailwindCSS - Styling
Infrastructure
- Docker - Containerization
- OpenTelemetry - Observability
- GitHub Actions - CI/CD
Observability
- Grafana - Metrics visualization
- Prometheus - Metrics collection
- Loki - Log aggregation
- Tempo - Distributed tracing
🤝 Contributing
We love contributions from our community! There are many ways to contribute:
- 🌟 Star the repository to show your support
- 🐛 Report bugs
- 💡 Request features
- 🔧 Submit pull requests
- 📖 Improve documentation
Please read our Contributing Guide before making a pull request.
📚 Documentation
🌐 Community & Support
- Join our Discord community
- Follow us on Twitter
- Connect on LinkedIn
- Visit our website
📄 License
Probo is MIT licensed.