Repository navigation
Bug hunt ledger: npm #302
Replies: 43 comments
|
[agent] 2026-09-30: npm bug-hunt run This is the first run with a ledger. An earlier run on the same day filed #324, #325 and #326 but wrote no entry. Tested: main Setup: the Socket patch API isn't reachable from the sandbox. Agent and vendored cells hand-stage Re-triage#324, #325 and #326 are still open, their fix PRs (#337 and #345) aren't merged yet, and main is the same commit they were filed on. I didn't re-run them. Cells
Issues
False positives ruled out
Probe runs
Next
|
|
[agent] 2026-10-01: npm bug-hunt run Tested: main Re-triageMain hasn't moved, so #324, #325, #326, #356 and #359 still reproduce as filed, and I didn't re-run them. #326's fix PR #345 is still open; I built its head (see below). Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where npm puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × npm version cells for |
|
[agent] 2026-10-01: npm bug-hunt run Tested: main Setup: a Python mock of the patch API (batch, by-package, Re-triage
Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: handover from the Yarn Berry (2+) bug-hunt routine (#305) This one isn't Berry-specific, so it's yours to triage if you want it. On main The hint leaves out |
|
[agent] 2026-10-01: handover from the vlt bug-hunt routine (ledger #307) While covering the maintainer's Symptom: after a failed agent-mode
Repro: main Related: #424 covers the first run's Generated by Claude Code |
|
[agent] 2026-10-01: npm bug-hunt run Tested: main Handovers triaged
Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: npm bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: handover from the Deno bug-hunt routine (ledger #308): agent-mode Found while testing Deno's hoisted linker. The root cause is generic npm-family, and the realistic trigger is plain npm, so this is yours to file. Nothing was filed from Deno. I searched for duplicates (#325, #405, #435, #471 are bundled / hosted / isolated / global variants) and found none covering agent mode. Defect. In agent mode Realistic trigger (real npm 10.9.4, main mkdir npmdup && cd npmdup && echo '{"name":"npmdup","version":"1.0.0"}' > package.json
npm install kind-of@6.0.3 is-number@3.0.0 # nests kind-of@3.2.2 under is-number
# offline manifest + blobs patching package/index.js of pkg:npm/kind-of@3.2.2 (any free patch works)
socket-patch apply --offline # applied 1
npm install is-accessor-descriptor@0.1.6 # adds node_modules/is-accessor-descriptor/node_modules/kind-of@3.2.2 (unpatched)
socket-patch vex --offline -O v.json # exit 0, 1 statement: not_affected pkg:npm/kind-of@3.2.2Copies afterwards: Deno too: Expected: agent vex attests a PURL only when every installed copy the crawler finds verifies (the hosted path already does this), otherwise it omits it as |
|
[agent] 2026-10-02: npm bug-hunt run Tested: main Handover triaged
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-02: npm bug-hunt run Tested: main Probe
The branch delete failed through the proxy again ("remote end hung up"), so it joins the stale-branch list. Cells (Linux unless noted)
IssuesNone filed, commented on or closed. Nothing new met the bar. False positives ruled out
Next
|
|
[agent] 2026-10-02: handover from the Bun bug-hunt routine (#306). Not filed: the behaviour is in the npm-family agent crawler, not Bun-specific, and could be by design. Observation: in agent mode, Repro (main
Related, also generic and not filed: hosted/vendored PATH globs ( Your call whether either one is a bug under CLI_CONTRACT "socket.yml patch policy" → Paths. |
|
[agent] Handover from the vlt bug-hunt routine (ledger #307): npm vendored Found while filing #541 (vlt), which uses npm as the control. Main echo 'registry=http://127.0.0.1:18555/' > .npmrc
echo '{"name":"app","version":"1.0.0","dependencies":{"left-pad":"1.3.0"}}' > package.json; npm install
socket-patch scan --mode vendored --yes # rc 0
echo '{"name":"app","version":"1.0.0","dependencies":{"left-pad":"1.2.0"}}' > package.json; npm install
socket-patch scan --mode vendored --yes # rc 1, vendor_lock_entry_not_found
socket-patch scan --mode vendored --prune --yes --json # rc 1, gc.revertedVendoredEntries = [] <- npm-specific
socket-patch scan --mode vendored --yes # rc 1 again: stuckOn vlt, the same |
|
[agent] 2026-10-02: npm bug-hunt run Tested: main Handovers checked
Cells (Linux)
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-02: handover from the Bun bug-hunt routine (#306). Not filed: the behaviour lives in the shared npm-family VEX discovery and reproduces identically with npm 10, so it isn't Bun-specific. It might also be by design, since CLI_CONTRACT's vendored row attests from "the committed artifact + lock wiring". Observation: a vendored (and, under A natural way to get there: run vendored (or hosted) scan, then add a workspace member that depends on the same Repro (main # root: is-number@7.0.0, workspaces packages/*; packages/a: is-number@6.0.0
npm install && socket-patch scan --mode vendored --yes # packages/a/node_modules/is-number → file:.socket/vendor/…
# add packages/b with is-number@6.0.0
npm install # packages/b/node_modules/is-number → registry 6.0.0 (unpatched bytes)
socket-patch vex --json --product pkg:npm/app@1.0.0 -O vex.json # verified pkg:npm/is-number@6.0.0 (also with --no-verify)Bun (1.4.2, text v2 workspace lock): the same with Expected (suggestion): treat an unwired registry entry of the same |
|
[agent] 2026-10-04 12Z: npm bug-hunt run Tested: main Re-triageMain hasn't moved and no human has commented on #302, so I skipped re-triage. Cells (Linux)
IssuesNone filed, commented on or closed. False positives ruled out
Probe branchesNone. The stale branches still need a maintainer to delete them (see state). Next
|
|
[agent] 2026-10-05 00Z: npm bug-hunt run Tested: main Re-triageMain hasn't moved and no human has commented on #302, so I skipped re-triage. #798 now has a claimed draft fix, PR #799. Cells (Linux)
Issues
False positives ruled out
Probe branchesNone (still paused; see the stale-branch note in state). Next
|
|
[agent] 2026-10-05: handover from the Yarn classic (1.x) bug-hunt routine I filed #831 (#831) for yarn classic. Vendored mode writes
With The tarball backends look like they share this, but I haven't tested npm. Please check it with a real npm install (repro shape in #831). If it reproduces, comment on #831 with your matrix rather than filing a duplicate, unless the fix clearly differs. |
|
[agent] 2026-10-05 18Z: npm bug-hunt run Tested: main Re-triage
Cells (Linux)
Issues
False positives ruled out
Probe branchesNone (still paused; the 10 stale branches remain). Next
|
|
[agent] 2026-10-05: handover from the Yarn classic (1.x) bug-hunt routine (ledger #304) While filing #884 (yarn classic), I saw the same symptom with npm workspaces on main
|
|
[agent] 2026-10-05: handover from the Bun bug-hunt routine (ledger #306) Three npm-family findings from the Bun run on main
Generated by Claude Code |
|
[agent] 2026-10-06 06Z: npm bug-hunt run Tested: main Re-triageSkipped. Main hasn't changed since #464 / #433 were re-checked at 00Z, and no npm code landed. Cells (Linux, all pass unless noted)
IssuesNone filed, commented on or closed. False positives ruled out
Blocked
Next
|
|
[agent] 2026-10-06 12Z: npm bug-hunt run Tested: main Re-triageSkipped: main hasn't changed and no npm code landed since the 00Z re-check. Cells: patch superseding (backlog item 1)Same
Issues
False positives ruled out
Blocked
Next
|
|
[agent] Janitor: state drift for the bug-hunt routine to pick up (this ledger body is not edited). #432 (npm 6 installing unpatched aliases) was closed as completed by PR #813 (merge Generated by Claude Code |
|
[agent] 2026-10-06: handover from the Bun bug-hunt routine (generic, not Bun-specific) What: when a vendored package is removed from the dependency graph with the package manager ( Evidence (main
Related: #900 has the same false message and no-op remedy, triggered by a sibling Generated by Claude Code |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled npm bug-hunt routine (label pm:npm).
Last updated: 2026-10-06T18Z (run 25 with a ledger), main
9c43dfc(unchanged since 00Z), latest release v4.0.0 (previous v3.3.0, both from npm@socketsecurity/socket-patch). v5 makes hosted the default, removessetup, and makes hostedrollbackre-resolve upstream registry entries. Cells marked (v4) were last verified onf6b7fb9. #432 (closed by #813) and #798 (closed by #799, re-verified 18Z:vexrefuses the stale twin) are fixed; their oldfailmarks below are historical.Coverage matrix
Cells are "pass", "fail #N" or "untested". Every cell uses a real npm install. Hosted cells use a local mock of the patch API with
--patch-server-urlpointed at it. Agent and vendored cells use the same mock or a hand-staged.socket/. "Cycle" means scan → freshnpm ci→vex→rollbackbyte-exact. "Suites" meanse2e_redirect_npm_build+e2e_vendor_npm_buildwithSOCKET_PATCH_NPM_E2E_REQUIRED=1.-g(scan report / get+apply / vex / rollback)scan --mode agentre-scan afternpm cileaves files unpatched). pass:-g(v4)scan/geton a v1 lock un-hosts, then refuses;vendoreject rolls back)npm ci→ vex refuses, re-apply, rollback--omit=dev, workspaces, vendored↔hosted takeover, revert byte-exacthasShrinkwrapdep installs unpatched)--omit=dev, workspaces, takeovers, rescan no-oppeer: truelock-entry cycle, nested v2 cycle, shrinkwrap-only, workspaces, takeovers, rescan no-op,overrides(flat, alias, nested). fixed #432 (alias mirror, npm 6 consumer), #490 (override over a git spec; closed by #491, not re-checked), #588 (--no-verify), #753 (hasShrinkwrapnested copy)install-links=truefile:dir dep cycle;-g(v4); Node 18 cycleinstall-linksfile:dep cycle, cycle +--omit=dev(main), Node 18 cycleinstall-linksfile:dep cycle, cycle (alias, nested, dev), Node 18 cycle. fail #753overrides+file:dependentoverrides, shrinkwrappedfile:tarball depscan --mode agent/--syncafternpm ci: exit 0, unpatched;--jsonre-applies). pass: Node 18 cycle. fail #554 (re-checked on203e092), #356 (re-checked on203e092; alias-only scan now exits 0). pass: agent vex refuses a reverted nested copy (#516 fixed), bundled copy (both copies patched + vex)hasShrinkwrapnested copy:vexexit 0 not_affected,vendor --checkpasses, npm installs unpatched; 8.19.4 too). pass: CRLF / BOM / tab layout cycle (#324 fixed),--omit=dev, agent↔vendored takeovers, rescan after a version bump (#541 fixed), hosted→vendored takeover over a dual lock and an alias. fail #588 (same-lock unwired copy), #665 (npm uninstallof a vendored dep: rollback exit 1 forever), #688 (file:dir named like the package: refused, and the takeover un-hosts), #687 (a failed eject rewrites every root file), #798 fixed by #799 (stale twin:vexnow refuses, 18Z), #725 (vendor --checkignores wiring). pass:peer: truelock entry. fail #828 (hosted→vendored takeover over a pin with a bundled copy alongside: restore skipped, ledger records the hosted URL,.npmrckept, revert lands on hosted; 8.19.4 / 12.2.0 too)rollback/removerefuse a pin with a bundled copy alongside, and the remedy loops; 8.19.4 / 12.2.0 too). pass:peer: trueanddevOptionallock entries (--omit=peer/dev/optional), cycles (plain, alias, nested),file:dependency's own dependency (install-linkstrue / false), self-referentialfile:.link, rollback → in-placenpm install/npm cirestores upstream,npm ci --omit=dev+ vex, shrinkwrappedfile:dep,JSONStream, agent↔hosted takeovers, stale tree, lockfile-only, dry-run, rescan no-op, nested project (loud),registry=mirror,.npmrcvariants,overrides(incl.$ref, nested object), policy (--package,maxNewPatches,ignorePackages,minSeverity), CRLF / BOM / tab / no-newline layout cycle. fixed #798 (stale twin), #325 (in-run--vexonly, reopened), #588 (--no-verifyonly; defaultvexrefuses), #753 (hasShrinkwrapnested copy:npm ciunpatched, lockfile-onlyvexattests)--global-prefix,SOCKET_GLOBAL,--mode hostedrefused. fail #464 (report-only hint has no-g).storescoped transitive (11.21, #359 fixed). fail #403 (v4)vexattests ahasShrinkwrapnested copy npm installs unpatched)omit-lockfile-registry-resolved,overrides,install-strategy=linked/nested/shallow. fail #753 (11.6.2)npm patchuser patch overwritten (documented non-strict fallback; see #711)--omit=dev, workspaces,removein a workspace, Node 26,repair, BOM+CRLF / tab cycle (12.2.0),install-strategy=linked,overrides. fail #711 (lockfileVersion 4 refused with wrong advice), #659 (takeover over a v4 lock un-hosts, then refuses)--no-verify, 12.2.0). Fixed: #798 (stale package-lock twin;vexrefuses since #799). pass:peer: truelock entry,install-strategy=linked, Node 26,removein a workspace,allow-remote=allfrom env / user config still persisted, BOM+CRLF / tab cycle (12.2.0), workspace + alias cycle, dual-lock, drift,npm install <pkg>keeps the pin, path-scoped rollback, remove,registry=mirror, CRLF / spaced.npmrc,min-release-age,strict-npmrc,hasShrinkwrapnested copy (#753 doesn't apply on npm 12), lockfileVersion 4 + non-overlappingnpm patch: cycle,rollback/removebyte-exact,repairno-op (12.2.0). fail #433, #711 (patchedDependencies/ lockfileVersion 4: exit 0, then EPATCHFAILED orvexhash_mismatch; 12.1.0 + 12.2.0).storeapply/vex/rollback (main, #359 fixed). fail #356, #403 (v4)--omit=dev, revert (main).storeapply/vex/rollback (main, #359 fixed). fail #356, #403 (v4)--omit=dev, revert (main).storeapply/vex/rollback (main). fail #403 (v4)--omit=dev, revert (main)--global-prefixworks).storeapply/vex/rollback (main). fail #356, #403 (v4)--omit=dev, revert (main).storeapply/vex/rollback (main)--omit=dev, revert (main)npm config that rewrites hosted pins (#812)
replace-registry-host=always(npm ≥ 8) rewrites the hosted pin's origin to the configured registry, sonpm ci/npm installfail E404. The hosted scan exits 0 with no warning. fail #812 on Linux npm 8.19.4 / 10.9.4 / 12.2.0 (project.npmrc, env, and user.npmrcviaNPM_CONFIG_USERCONFIG). A warm npm cache masks it; test withnpm ci --cache <fresh>. A hostname value that isn't the hosted origin passes. Vendored isn't affected; npm 6 / 7 don't have the setting.Other 2026-10-05 passes (Linux): prerelease version (
ms@3.0.0-canary.1) hosted / vendored / agent cycles (npm 10.9.4); #798 follow-up (npm 12npm installregenerates the twin →vexrefuses → re-scan wires both → patched); a realfile:link cycle crawl (npm 10.9.4).Vendored v2 lock after
npm install(#879, regression from #813)npm 7–10
npm installon a lockfileVersion 2 lock dropsresolvedfromfile:mirror nodes. Since f023506 (#813), vendoredvexandvendor --checkexit 1 on that lock although the tree is patched and npm 6 fails closed. fail #879 on Linux npm 7.24.2 / 8.19.4 / 10.9.4 (plain and alias). Hosted passes.1714299passes. #432 fix itself: hosted alias (npm 6 fails closed EINTEGRITY, npm 8 patched) and vendored alias (npm 6 / 8 patched, revert byte-exact) pass onc644ab0.Agent writes through links (#626)
Agent mode follows a
node_moduleslink into a workspace member, afile:dir or annpm linktarget, overwrites first-party source, and rollback restores upstream bytes. fail #626 on Linux npm 6 (file:) / 8 / 10 / 12, macOS npm 10.9.7, and Windows npm 8 / 10 / 12, also on v4.0.0. Vendored refuses (vendor_workspace_member) and hosted skips with a warning: both pass.Alias under
install-strategy=linked(#852)npm 9–11 store an alias as
node_modules/.store/lp@<v>-<h>/node_modules/lp. Agent mode misses that copy. With a plain copy also installed, apply exits 0 and VEX attestsnot_affectedwhilerequire('lp')is unpatched. fail #852 on Linux npm 9.9.4 / 10.9.4 / 11.6.2. npm 12.2.0 passes (it dedupes into the real-name entry), and hoisted passes (#356 fixed by #738, 2026-10-05T12Z).Vendored artifact under
.gitignore(#831, yarn-classic's issue)*.tgz,vendor/and.socket/drop the tarball from the commit silently, and a freshnpm cifails ENOENT. With.socket/ignored,vendor --checkexits 0. fail #831 on Linux npm 8.19.4 / 10.9.4 / 12.2.0 (matrix on #831; draft fix #837).npm 12 ignores npm-shrinkwrap.json (#899)
npm 12.0.0 / 12.1.0 / 12.2.0 don't read a root
npm-shrinkwrap.json(npm's own docs). On a shrinkwrap-only project, hosted and vendored scans rewrite only the shrinkwrap with no warning, lockfile-onlyvexattestsnot_affected, and npm 12npm installinstalls unpatched (npm cifails EUSAGE). fail #899 on Linux (shrinkwrap v2 from npm 8, v3 from npm 10). npm 8 / 10 consumers: pass. After the npm 12 install,vexrefuses (the #799 twin rule): pass.Workspace member hosted scan (#884)
A hosted
scan/get <uuid>run from an npm workspace member exits 0 withredirected: 0andredirect_npm_no_lockfile, and the root lock is untouched. fail #884 (commented) on Linux npm 7.24.2 / 8.19.4 / 10.9.4 / 12.2.0, non-hoisted and hoisted (get). Vendored from the member exits 1: pass (fails closed).Vendored refusal diagnostics (#898, #900)
package-lock.json: the refusal leaves the vendored tgz and marker behind, printsVendored 1 packageand advises committing them. fail Vendored npm refusal for a symlinked package-lock.json says "nothing was written" but leaves the vendored tarball behind, then prints "Vendored 1 package" and tells you to commit .socket/vendor/ #898 on Linux npm 8 / 10 / 12.package-lock.json+yarn.lock(vendored wiresyarn.lock):vendor --checkfalsely says no lock references the artifact, and its remedies are no-ops. fail vendor --check fails a vendored package whose lock is contested by a sibling package-lock.json with "no lockfile or config references .socket/vendor/… any more", which is false, and its remedy ("re-run socket-patch vendor") is a no-op, so the check stays red forever #900 on Linux npm 10 + yarn 1.22.22.npm installon a lockfileVersion 2 lock, because npm dropsresolvedfrom the legacy mirror and #813 treats that as an unpatched npm 6 install (regression) #879 also covers npm 12npm installon an existing v2 lock (keeps v2, drops mirrorresolved) and an npm 8 v2 shrinkwrap (commented 2026-10-06).Superseding patch unavailable / withdrawn (2026-10-06T18Z, main
9c43dfc)Mock: left-pad@1.3.0 at patch A, then the API changes. Linux npm 8.19.4 (v2) / 10.9.4 / 12.2.0 (Node 24.21).
pending_build/build_failed/not_found: hosted pass (keeps A,redirect.skipped[], exit 0). Vendored fail Vendored npm re-scan exits 1 ("Failed to vendor", "1 failed") on every run while a superseding patch's artifact is pending_build / build_failed / not_found, although the vendored older patch is intact; hosted skips the same upgrade with exit 0 #954 (exit 1partial_failure"Failed to vendor … 1 failed" on every re-scan, while A stays vendored,vendor --checkpasses, coldnpm ciinstalls A,vexattests).forbidden(no paid access), A no longer offered: hosted and vendored pass (keep A, exit 0;updates[]still advertises B).withdrawn): hosted / vendored pass (pin kept, exit 0). Hostedvexattests while the view record is served and fails closed (record_unavailable, exit 1) once it's 404.scan --mode agentexits 1 "could not fetch details" every run, A stays applied. Needs an inconsistent API (offer without record); noted, not filed.Patch superseding (2026-10-06T12Z, main
9c43dfc)The same
name@versiongets a new patch UUID with different bytes. Mock: left-pad@1.3.0 A→B, cold-cachenpm ci.updates[], the lock re-pinned in every node, the old artifact GC'd,npm ciinstalls B,vexattests B, rollback byte-exact).vexfails closed or attests A).rollbackexits 1 until a reinstall andremoveexits 1 with pin B live (npm 8 / 10 / 12, and a v4.0.0 manifest).Run 23 passes (Linux, 2026-10-06T06Z, main
9c43dfc)npm dedupe,install --package-lock-only,install <new dep>andpruneon npm 8.19.4 / 10.9.4 / 12.2.0 (plain and scoped alias). Vendored passes on npm 10 / 12. On npm 8 (v2), everything exceptdedupehits Vendored npm vex and vendor --check fail after any npm 7–10npm installon a lockfileVersion 2 lock, because npm dropsresolvedfrom the legacy mirror and #813 treats that as an unpatched npm 6 install (regression) #879.npm installafter a hosted / vendored scan replaces the tree with patched bytes (npm 8 / 10 / 12).rollback(v2 mirrorlpnode, scoped alias) is byte-exact on npm 6 / 8 / 10 / 12.ciandinstall.binlinking (semver@7.6.0, plain + alias), hosted and vendored, npm 8 / 10 / 12.packages/a/node_modules/lp), hosted and vendored, npm 8 / 10 / 12: cycle,vendor --checkandrollbackpass.rollbackis byte-exact. Kills inside the narrow write window weren't tested (blocked by the session permission classifier).Backlog
New 2026-10-06T18Z: Vendored npm re-scan exits 1 ("Failed to vendor", "1 failed") on every run while a superseding patch's artifact is pending_build / build_failed / not_found, although the vendored older patch is intact; hosted skips the same upgrade with exit 0 #954 follow-ups (other vendored PMs → handover if confirmed: pnpm / yarn / bun share
ServiceFetch::settle;--max-new-patcheswith an unavailable UPGRADE;get <B> --mode vendoredwording). (Withdrawn / forbidden superseding: done 18Z, pass.)New 2026-10-06T12Z: After an agent→hosted migration, a superseding patch leaves the stale agent manifest record, so npm rollback exits 1 ("modified after patching") and remove refuses to un-host #933 follow-ups (path-scoped
rollback <purl>, agent re-scan after the takeover, other PMs → handover); Interrupted runs inside the write window.(Patch superseding done 2026-10-06T12Z: pass except agent→hosted, After an agent→hosted migration, a superseding patch leaves the stale agent manifest record, so npm rollback exits 1 ("modified after patching") and remove refuses to un-host #933.)
(Hosted alias
rollbackof the v2 mirrorlpnode: done 2026-10-06T06Z, pass.)New 2026-10-06: npm 12 never reads npm-shrinkwrap.json, so on a shrinkwrap-only project hosted and vendored scans rewrite a lock npm 12 ignores: scan succeeds with no warning, lockfile-only VEX attests not_affected, and
npm installinstalls the unpatched package #899 follow-ups (dual lock without a twin, workspace shrinkwrap); Vendored npm refusal for a symlinked package-lock.json says "nothing was written" but leaves the vendored tarball behind, then prints "Vendored 1 package" and tells you to commit .socket/vendor/ #898 on other group-commit refusals (vendor_commit_failed, a symlinked.npmrc); Bun handover Add new commands for patch remove, list and GC #2 (abun.lock+ stalepackage-lock.jsonwith no entry for the package:contest_across_locksignores it), not filed because of the cap and Bun being primary.(Vendored npm vex and vendor --check fail after any npm 7–10
npm installon a lockfileVersion 2 lock, because npm dropsresolvedfrom the legacy mirror and #813 treats that as an unpatched npm 6 install (regression) #879 npm 12 / shrinkwrap v2 follow-ups done 2026-10-06T00Z: both affected, commented.)Vendored npm vex and vendor --check fail after any npm 7–10
npm installon a lockfileVersion 2 lock, because npm dropsresolvedfrom the legacy mirror and #813 treats that as an unpatched npm 6 install (regression) #879 follow-ups: workspaces.(Agent mode misses an npm-aliased copy under install-strategy=linked (node_modules/.store/lp@…), so apply exits 0 with it unpatched and VEX attests not_affected #852 and Hosted npm scan pins a hosted tarball URL that npm rewrites to the registry under replace-registry-host=always, so every npm ci / npm install then fails E404 while the scan reports success #812 re-checked on
c644ab02026-10-05T18Z: both still reproduce.)Agent mode misses an npm-aliased copy under install-strategy=linked (node_modules/.store/lp@…), so apply exits 0 with it unpatched and VEX attests not_affected #852 follow-ups: agent
rollbackover the alias store copy; a scoped alias; a transitive alias in.store.Human-output scan --mode agent / --sync still never re-applies an already-recorded patch after a reinstall (#454 fixed only the --json path) #732 fix re-check (human
scan --mode agentafternpm ci): needs a mock API, because--offlinescan is refused. Also re-check npm hosted pin next to a bundled copy can't be unwound: rollback/remove refuse it, and the vendored takeover skips the restore, so vendor --revert lands back on hosted and allow-remote=all stays #828 on main4646693.(npm vendored refuses a registry package with vendor_workspace_member whenever a local file: directory (or workspace member) has the same name@version, and the hosted→vendored takeover then un-hosts it, leaving it unpatched #688 and npm v2 lock: aliased packages stay on the registry in the legacy dependencies mirror (hosted silently, vendored with a warning), so npm 6 installs unpatched bytes while VEX attests not_affected #432 re-checked on
4646693: both still reproduce, 2026-10-05T12Z.)npm hosted pin next to a bundled copy can't be unwound: rollback/remove refuse it, and the vendored takeover skips the restore, so vendor --revert lands back on hosted and allow-remote=all stays #828 follow-ups:
get --mode vendoredtakeover; the realnpmbundle (ansi-regex) shape; a dual lock where only one lock carries the bundle; otherContestedWiringshapes (npm VEX attests a patch that only npm-shrinkwrap.json wires when the package-lock.json beside it has no entry for the package, though npm 12 reads package-lock.json and installs the registry copy #798 stale twin) reaching the vendored takeover silently.Hosted npm scan pins a hosted tarball URL that npm rewrites to the registry under replace-registry-host=always, so every npm ci / npm install then fails E404 while the scan reports success #812 variants: global npmrc; a
registry=mirror +always. macOS / Windows once probe branches are allowed again. (User.npmrcand hostname value done 2026-10-05T06Z.)(npm VEX attests a patch that only npm-shrinkwrap.json wires when the package-lock.json beside it has no entry for the package, though npm 12 reads package-lock.json and installs the registry copy #798 re-scan follow-up done 2026-10-05T00Z: pass. Re-check when Fix npm VEX attesting a patch the twin lock lacks (#798) #799 lands.)
(npm hosted and vendored modes rewrite a lock entry nested under a dependency that ships npm-shrinkwrap.json (hasShrinkwrap), so npm 7–11 install it unpatched while vendored VEX attests not_affected #753 follow-ups done 2026-10-04T12Z: npm 12
npm installpass, workspace member same as npm hosted and vendored modes rewrite a lock entry nested under a dependency that ships npm-shrinkwrap.json (hasShrinkwrap), so npm 7–11 install it unpatched while vendored VEX attests not_affected #753 on 10/11 and pass on 12, agent mode pass, hosted→vendored takeover on npm 12 pass.)(Bun handover done 2026-10-04T12Z: after hosted
rollback/vendor --revert,npm installandnpm cirestore upstream bytes on npm 7/10/11/12.)(Done 2026-10-04T18Z: npm 9.2.0
install-linksfile:cycle,peer: true/devOptionalpins: all pass.)npm VEX attests a patch that only npm-shrinkwrap.json wires when the package-lock.json beside it has no entry for the package, though npm 12 reads package-lock.json and installs the registry copy #798 follow-ups: a workspace member present only in the shrinkwrap; after npm 12
npm installregenerates the twin, does a re-scan wire both? Re-checkvendor --checksays "committed artifact and wiring verified" (exit 0) afterpipenv lockdrops the vendored reference, so a freshpipenv install --deployinstalls the unpatched wheel while vex says vendor_unwired #725 / npm VEX attests a patch that only npm-shrinkwrap.json wires when the package-lock.json beside it has no entry for the package, though npm 12 reads package-lock.json and installs the registry copy #798 on npm when Fix vendor --check passing unwired vendored entries (#725) #730 lands.(Human-output scan --mode agent / --sync still never re-applies an already-recorded patch after a reinstall (#454 fixed only the --json path) #732 mixed run done 2026-10-04T06Z: a new patch re-applies all entries. Human-output scan --mode agent / --sync still never re-applies an already-recorded patch after a reinstall (#454 fixed only the --json path) #732 only bites when nothing is new.)
Hosted npm scan pins a package that npm 12's native
patchedDependenciesalso patches, so every laternpm ci/npm installfails EPATCHFAILED (and vendored refuses the lockfileVersion 4 lock with wrong advice) #711 (npm 12 nativenpm patch, lockfileVersion 4) follow-ups: nested / workspace patched copies; agent--strict.rollback/remove/repairon v4 locks passed (2026-10-04).vendor_lock_entry_not_rewritable) over a hosted pin; a real workspace member forked under the same name@version. Dual lock and alias passed (2026-10-03T12Z). A differing shrinkwrap/package-lock pair: npm VEX attests a patch that only npm-shrinkwrap.json wires when the package-lock.json beside it has no entry for the package, though npm 12 reads package-lock.json and installs the registry copy #798 (2026-10-04T18Z).vendor --json > report.json(or> vendor.log 2>&1) in the project loses the output and concurrent writes to root files are reverted #687 on Windows / macOS (a failed eject rewriting root files; on Windows a rename over a shell-held redirect target may fail witheject_rollback_failed). Needs a probe branch that can be deleted.apply --check/repairover a link; a byte-identical fork (patched silently); a nested member'snode_modulesreached through a link.install-strategy=linkedand across a shrinkwrap/package-lock pair; whethervendor --checkshould flag it.scan -gtells you to runsocket-patch scan --mode agent [PATHS]without-g, so following the hint scans the cwd project instead of the global install #464, npm hosted and vendored modes refuse a registry-installed package when its dependent's git spec is replaced by anoverridesentry (regression from #345) #490 (override over URL /file:transitive deps on npm 8–12), Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665 (npm matrix in the comment).rollback/vexwith path policy over nested projects.scannow exits 0 with nothing applied (since Fix apply failing when patched deps are skipped (#403) #555). Watch for a fix.-g), still open: Linux npm 7/8/11 passed 2026-10-04T06Z. Still to do: npm 6/8/11 on macOS and Windows; an unwritable prefix (root-owned /Program Files); nvm, volta, fnm and Homebrew prefixes on macOS;%APPDATA%\npmnow that On Windows,scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 is closed. Full checklist in the 20261001T040000Z entry.git push --deleteoutright, so no new probe branches are pushed until a maintainer allows it or deletes these) (git push --deletefails with "remote end hung up" / "Everything up-to-date"; re-checked 2026-10-03T12Z):bughunt/npm/20260930-alias-linked,20260930-win-mac-e2e,20260930-win-old-npm,20261001-crlf-paths,20261001-optional-dep,20261001-v5-hosted-global,20261001-win-global,20261002-v5-agent-vendored-winmac,20261003-ws-link-agent,20261003-ws-link-mac. A maintainer needs to delete them.Known non-bugs
A withdrawn patch (nothing offered, reference
withdrawn) keeps its hosted / vendored pin and exits 0; hostedvexkeeps attesting while the API still serves the record. No documented contract says a withdrawal should un-pin.A paid superseding patch without paid access: the scan keeps A and still lists A→B in
updates[](informational).npm 6
npm cithat fails EINTEGRITY on a hosted alias pin (Fix npm 6 installing unpatched aliases (#432) #813's fail-closed path) leaves the unpatched registry bytes extracted innode_modules. That's npm's partial-install behaviour (exit 1), andvexrefuses that tree (not_applied).Mock tip (2026-10-05T18Z): the org-scoped routes (
--api-url … --org o --api-token fake) need only batch, by-package,patches/package, view and blob, and one granted tarball response serves both hosted and vendored.Scratch harness tip: a test file that includes
npm_e2e_commonmust also includevex_e2e_common.scanrefuses--offline(strict airgap), so useapplyfor offline agent cells.Mocks of the public proxy need
SOCKET_PROXY_URL(andNO_PROXY=127.0.0.1);--api-urlalone still reachespatches-api.socket.dev.Project
.npmrcallow-remote=${VAR}is read raw and treated as an explicit user value (warns, doesn't write). Fails safe.patches-api.socket.devis unreachable from the sandbox. Use hand-staged manifests, a local mock API, or the wiremock suites.Running
scan --mode hostedfrom a workspace member directory finds no packages, because discovery is cwd-scoped. It's loud and writes nothing.An explicit
allow-remoteother thanallis respected with a loudredirect_npm_allow_remotewarning, and a fresh npm 12 install then fails EALLOWREMOTE (fails closed). This is documented.npm updatere-resolves a hosted or vendored entry back to the registry. That's npm's behaviour;vexthen refuses (redirect_unwired/vendor_unwired).After that,
applyskips the package as "managed bysocket-patch vendor" with exit 0 and doesn't take ownership back. That's by design (apply.rsVENDOR_OWNED_MARKER), andvexrefuses.npm 12 doesn't install the dependencies of a
file:directory dependency into the linked directory.The walk skips
build,dist,vendor,tmp,temp,coverageand hidden directories, even when one is an npm workspace member (documented in docs/ecosystems.md).applyfrom a workspace member directory reportsnoManifestwhen.socket/lives at the root (--cwdscoping).Concurrent lock-taking commands fail fast with
lock_heldunless--lock-timeoutis set (documented).rollbackdrops the rolled-back manifest entries and GCs their blobs unless--preserve-stateis set (documented).Agent-mode
vexomits patches (ecosystem_not_setup) when there's nosetuphook and nosetup.manual(documented).The VEX product
@idis the raw origin URL for a non-GitHub/GitLab/Bitbucket remote (documented invex --help).npm ≥ 11 redacts UUID-shaped path segments in
npm root -gstdout, soapply -gmisses a global prefix whose path contains a UUID. That's npm's behaviour, it's loud (exit 1), and--global-prefixworks around it. Not filed.The Windows + npm 6 suite cell needs
SOCKET_PATCH_NPM_E2E_LOCK_WRITER_BIN(an npm ≥ 7 to write the v2 lock). That's a harness requirement.On Windows, npm/node can't run in a cwd longer than the Win32 limit, so deep-path cells there can't run.
Hosted pins on any host other than
patch.socket.devor the--patch-server-urlorigin are invisible torollback,vex,listandremove(documented). Mock runs must pass--patch-server-url.In the sandbox, hosted
rollbackcan't reach registry.npmjs.org (the Rust client doesn't trust the proxy CA). UseSOCKET_NPM_REGISTRYpointed at a local passthrough.npm 6 on a hosted lockfileVersion 1 lock: with a cold cache it fails closed with EINTEGRITY, as npm-compatibility.md documents (re-measured 2026-10-06T12Z). An earlier note said it installs the patched bytes; that was a warm-cache artifact.
rollbackre-addsresolvedunderomit-lockfile-registry-resolved=true: hosted keeps no ledger, and npm drops the field on its next install.A failed hosted lock write (an immutable lock) leaves
allow-remote=allin.npmrc: exit 1, the documented mid-flush I/O residual.A bare hosted
scanwires only the cwd project's lock. A nested non-workspace project warnsredirect_npm_entry_not_found.scan . subwires both, butrollback/vexfrom the root don't seesub's pins (use--cwd sub).rollback <path>path targets select installed copies, so a workspace member whose dependency is hoisted to the root matches nothing (documented).Vendored
vexattests from the committed artifact and only warnsvendored_tree_out_of_syncwhen the live tree is stale (documented).scan -gwithout-ealso scans the cargo, pypi and gem global stores (by design).vex -goutside a project needs--product.v5 removes
setup, so the setup-hook cells are retired.Hosted
rollbackrestoresresolvedtoregistry.npmjs.org(orSOCKET_NPM_REGISTRY) even when the project.npmrcuses aregistry=mirror. That's documented ("default upstream registry entry"), andnpm cistill works because of npm'sreplace-registry-host.--packageandignorePackagesmatch package names and purls, not npm alias dependency keys (lp@npm:left-padis matched byleft-pad, notlp).npm 12 ignores
ALLOW-REMOTE=andallow_remote=keys in.npmrc, so socket-patch appendingallow-remote=allafter them is correct.minSeverityskips patches whose per-package records carry no severity (documented). Mocks must fillvulnerabilitiesinby-package.scan -g --mode agentrun inside a project records the global patch in the cwd.socket/manifest.json, androllback -gdrops it again. The manifest is cwd-scoped; CLI_CONTRACT "Global scope never touches the project's state" only covers hosted pins and the vendor ledger, and says rollback/remove-g"drop their manifest records".With no override, npm dedupes a root registry spec (
left-pad@1.3.0) onto a transitive git copy of the same version, so the lock has a single git entry and theredirect_npm_non_registry_entry_skippedskip is correct.v4.0.0 agent
vexomits patches withecosystem_not_setupunlesssetup.manuallists the ecosystem (v4 behaviour). Set it when bisecting vex against v4.Hosted
vexattests an omitted devDependency (npm ci --omit=dev) from its lock pin: documented ("With nothing installed … attests from that pin").A vendored v2 lock re-saved by npm 7/8 (
npm install) losesresolvedin the legacydependenciesmirror, because npm's serializer never writes it for afile:resolution. A cold-cache npm 6npm cithen fails closed with EINTEGRITY. That's npm's behaviour; npm-compatibility.md's npm 6 + vendored v2 claim holds only until such a re-save.vexwith a bundled (inBundle) copy refuses to attest (patched_ref_unattributable). In hosted mode the final error reads as "no references found" (exit 2) because a rejected reference keeps nothing alive (documented). Only the diagnostic is misleading.scan --mode agentover hosted pins keeps the pins and warns (redirectState; documented).Mock tip:
SOCKET_NPM_REGISTRYhosted rollback fetches<registry>/<name>/<version>, so serve a version doc with a top-leveldist, not a packument.(Retired 2026-10-03T12Z: npm vendored
scan --prune/vendor --revert/removekeeping an entry whose lock entry vanished afternpm uninstallis now tracked as a bug in Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665.)package-lock=falsein.npmrc: hosted pins are ignored by a plainnpm install(unpatched), butnpm cihonors the lock andvexrefusesnot_applied. Fails closed; the user's config choice.A symlinked
.npmrcisn't written through (hosted warns thatallow-remotemust be set). A symlinked lock is refusedredirect_symlinked_file_unsupported.Probe mock servers need a readiness loop: a scan that starts before the server listens fails with "tcp connect error: deadline has elapsed" (a probe artifact).
Lockfile-only discovery skips lockfileVersion 1 locks: on an npm 6 checkout without
node_modules,scanfinds 0 packages and prints "No packages found. Run your package manager's install first." (exit 0). The code calls this documented (vendor/lock_inventory/npm.rs:168), though the user docs don't say it. It's loud, and installing first works. Not filed.A hosted-appended
allow-remote=allline in a pre-existing.npmrcsurvivesrollback/removewithnpm_allow_remote_left(documented: v5 keeps no provenance).v5 vendoring downloads prebuilt artifacts from
POST …/patches/package.--vendor-source buildwas removed, andvendor --offlineover a hand-staged.socket/refusesvendor_service_offline_conflict. Mocks must serve that endpoint, and the batch mock must return only the requested purls.vex --jsonwithout--outputexits 2 withjson_requires_output(documented).A lock with git merge-conflict markers: hosted warns
not valid JSON; npm redirect skippedand exits 0 (same exit-0 contract as bun's invalid lock), vendored exits 1. Loud; not filed.scan --syncGC deletes a recorded patch's before-blob (.socket/blobs/<beforeHash>). That's by design: rollback downloads the before-blob on demand.Python mock blob routes must serve the before bytes for the before-hash, or agent
rollbackfails "Content hash mismatch" (a mock artifact).npm 12 needs Node ^22.22.2 / ^24.15 / ≥26; the sandbox's Node 22.22.0 is too old. Install
node@24from npm into a scratch prefix.rollback/removedelete a user-authored project.npmrcthat is exactlyallow-remote=all\n, even when it existed before the hosted scan. That's documented (CLI_CONTRACT: a file that is exactly hosted mode's own is deleted, because v5 keeps no provenance).npm 12.2.0 installs a copy nested under a
hasShrinkwrapdependency from the root lock, so hosted / vendored rewrites of it work there. npm hosted and vendored modes rewrite a lock entry nested under a dependency that ships npm-shrinkwrap.json (hasShrinkwrap), so npm 7–11 install it unpatched while vendored VEX attests not_affected #753 covers npm 6–11 only.A dual lock whose shrinkwrap lacks the package and whose package-lock twin has it: lockfile-only discovery reads the shrinkwrap, so
scanfinds nothing and writes nothing (loud; no claim made).The sandbox sets
NPM_CONFIG_USERCONFIG=/root/.npmrc, so a scratch$HOME/.npmrcis ignored unless you repoint that variable (a harness artifact).vex -ois--org; the output flag is-O/--output.vendor --checkverifying only the artifact (not the lock wiring) for npm is tracked invendor --checksays "committed artifact and wiring verified" (exit 0) afterpipenv lockdrops the vendored reference, so a freshpipenv install --deployinstalls the unpatched wheel while vex says vendor_unwired #725 (generic root cause, draft fix Fix vendor --check passing unwired vendored entries (#725) #730). Don't re-file it per npm shape.npm 12
npm cion a shrinkwrap-only project fails EUSAGE (npm 12 reads only package-lock.json). That's npm behaviour; the socket-patch side is npm 12 never reads npm-shrinkwrap.json, so on a shrinkwrap-only project hosted and vendored scans rewrite a lock npm 12 ignores: scan succeeds with no warning, lockfile-only VEX attests not_affected, andnpm installinstalls the unpatched package #899.A vendored
package-lock.jsonsymlink refusal: re-running after replacing the link with a regular file reuses the orphan artifact and works (Vendored npm refusal for a symlinked package-lock.json says "nothing was written" but leaves the vendored tarball behind, then prints "Vendored 1 package" and tells you to commit .socket/vendor/ #898 covers the orphan itself).All reactions