Repository navigation
Issue & discussion janitor log #576
Mikola Lysenko (mikolalysenko)
started this conversation in
General
Replies: 1 comment
|
[agent] Janitor: bridge test. The janitor/ledger workflow posted this comment on the routine's behalf. Hourly runs log here from now on. Generated by Claude Code |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Janitor: the hourly issue and discussion janitor rewrites this log each run. It shows the last run, the actions it took with a reason for each, a rolling list of recent actions, deferred candidates, and anything that needs a human. The routine writes it to the
janitor/ledgerbranch, and a workflow on that branch applies it here.Last run
2026-10-07 13:30Z on origin/main
db83f014. 273 open issues, the issues closed since 2026-09-30, and the PRs updated in the last 14 days were reviewed. Since9c43dfc9, 33 PRs merged (2026-10-07 11:48–12:40Z). Every issue they say they fix auto-closed.This run
scan/get --mode vendored) restores the package to PyPI before the uv vendored refusals run, so an inline[tool.uv] sources = {…}table (or a #928 marker split) leaves it unpatched in both modes, while --dry-run previews would_vendor #944 (PR Keep the hosted pin when a vendored takeover is refused (#853, #944) #963,Refs) stay open for thescan/get --mode vendored --dry-runpreview slice. Vendored Gradle exits 0 when the project's .gitignore excludes *.jar, so the commit silently drops the patched jar and every fresh checkout fails to build #620, Hosted npm scan pins a package that npm 12's nativepatchedDependenciesalso patches, so every laternpm ci/npm installfails EPATCHFAILED (and vendored refuses the lockfileVersion 4 lock with wrong advice) #711, Vendored npm vex and vendor --check fail after any npm 7–10npm installon a lockfileVersion 2 lock, because npm dropsresolvedfrom the legacy mirror and #813 treats that as an unpatched npm 6 install (regression) #879 and Move canonicalize_pypi_name and the PEP 508 name scanner out of crawlers and vendor into one PyPI name module #883 are only mentioned as out of scope by merged PRs Fix vendored npm-family tarballs dropped by .gitignore (#831) #837, Fix Bun rewiring dropping the project's bun patch (#367) #873, Fix vendor --check unwired cause and remedy (#900) #970 and Fixget <name>missing PyPI names spelled with_or.(#926) #927. No exact duplicates were found among Fix VEX attesting beside an unpatched same-lock copy (#935, #938, #939) #940–Hosted yarn berry rollback/remove still drops a mirror's::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017: Hosted yarn classic offline-mirror refusal (#364 fix) only reads the project's own .yarnrc/.npmrc, so a mirror set in ~/.yarnrc, yarn's user config or a parent dir still breaks every install #1013 and Hosted yarn berry rollback/remove still drops a mirror's::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 are follow-ups to the closed Hosted yarn classic redirect breaks every install in projects with a yarn-offline-mirror: the mirror's upstream tarball shares the hosted URL's basename and fails the new integrity pin #364 and Hosted yarn berry rollback/remove still drops a custom registry's::__archiveUrl=binding (#817 fix incomplete): the restore looks updist.tarballon npmjs, not the project'snpmRegistryServer, so cold installs 404 #908, Vendoredvendor --dry-runpreviews success on a uv project with an inline[tool.uv]/sourcestable, but the real run refusespypi_uv_lock_parse_failed(exit 1) #979 isvendor --dry-run(not the uv hosted → vendored takeover (scan/get --mode vendored) restores the package to PyPI before the uv vendored refusals run, so an inline[tool.uv] sources = {…}table (or a #928 marker split) leaves it unpatched in both modes, while --dry-run previews would_vendor #944 scan/get preview), and Hosted scan/get run from a vlt workspace member reports success while pinning nothing: the #598 / #901 member refusal has no vlt.json case #942 is the vlt case Fix hosted runs from npm/yarn/bun workspace members pinning nothing (#884) #901 deliberately left out (checked in1c6c509b).Claim-ID: 2026-10-05T11:56:39Z-93d7a1). Slice 1 merged as Spawn CLI test children through one hermetic Command builder (#823) #850, no follow-up PR, and the claimer has been silent for more than 48h. The issue stays open.agent:claimedfrom 33 closed issues: Hosted yarn classic redirect breaks every install in projects with a yarn-offline-mirror: the mirror's upstream tarball shares the hosted URL's basename and fails the new integrity pin #364, Hosted and vendored Bun rewiring silently discards the project's ownbun patch(patchedDependencies): fresh frozen installs drop the user's patch with exit 0 #367, Hostedrollback,removeand the vendored takeover refuse a requirements.txt whose only requirements are hosted pins (six==1.16.0alone can be patched but never unpatched) #410, scan/get --json drop the agent-mode apply failure: exit 1 with failed: 0, the patch shown as "added", and no error anywhere (e.g. a read-only global ~/.m2) #424, A report-onlyscan -gtells you to runsocket-patch scan --mode agent [PATHS]without-g, so following the hint scans the cwd project instead of the global install #464, Agent-mode scan in a Pipenv project without a Pipenv venv patches the system Python's site-packages in place instead of the project's venv/ (regression from #388) #504, vlt hosted rollback and remove rewrite slot [3] to a synthesized/<name>/-/<leaf>-<ver>.tgzURL instead of the registry's dist.tarball, so the next coldvlt ci404s #521, Hosted gem redirect ignores Bundler'smirror.allsetting, so the nextbundle installfetches the redirected gem's upstream bytes from the mirror while the in-run VEX attestsnot_affected#681, Hosted uv scan silently wires a platform-specific patched wheel (cp311 manylinux) into a universal uv.lock, souv sync --lockedfails on every other Python version, macOS and Windows, and rollback then refuses #701, Slow scan: poetry hosted 4.5x median ms/pkg (per-patch poetry.lock re-parse) #760, Slow scan: pdm hosted 3.6x median ms/pkg (per-patch pdm.lock re-parse) #762, Vendored Pipenv never picks up a superseding patch: re-vendor to a new uuid fails with pypi_pipenv_source_already_exists (lock-only) or a false package_not_installed (venv present), exit 1 #769, Gem hosted and vendored rewrites delete a secondgemdeclaration that shares the patched gem's line after;, so the nextbundle installdrops that dependency #826, Vendored yarn classic exits 0 when .gitignore covers the vendored tarball (*.tgz,vendor/,.socket/), so the commit drops it and every fresh checkout's install fails #831, Crawler probes spawn gem, python and npm with no timeout, so a hung shim hangs scan forever #845, Agent mode misses an npm-aliased copy under install-strategy=linked (node_modules/.store/lp@…), so apply exits 0 with it unpatched and VEX attests not_affected #852, Vendored yarn classic drops the git-skip warning when the git block is the only copy, and refuses with vendor_lock_entry_not_found telling the user to runyarn install#857, Hosted scan from a pnpm 11/12 workspace member with its own lock writes trustLockfile into a nested member pnpm-workspace.yaml that pnpm ignores, so the root install fails with ERR_PNPM_TARBALL_URL_MISMATCH #880, Vendored scan from a pnpm 11/12 workspace member with its own lock writes the override into a nested member pnpm-workspace.yaml that pnpm ignores, so the root frozen install fails and a plainpnpm installsilently reinstalls the unpatched package #881, Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884, vendor --check fails a vendored package whose lock is contested by a sibling package-lock.json with "no lockfile or config references .socket/vendor/… any more", which is false, and its remedy ("re-run socket-patch vendor") is a no-op, so the check stays red forever #900, Hosted yarn berry rollback/remove still drops a custom registry's::__archiveUrl=binding (#817 fix incomplete): the restore looks updist.tarballon npmjs, not the project'snpmRegistryServer, so cold installs 404 #908, socket.ymlignorePackages/packagesandscan --packagedon't PEP 503-normalise PyPI names, soignorePackages: ["typing_extensions"]is silently ignored and the package is patched anyway #910, Gem crawler ignores Bundler'spath.system: truewhen a leftovervendor/bundleexists, so agentapplypatches the unused copy andvexattestsnot_affectedwhile Bundler loads the unpatched system gem #915, Yarn classic VEX attests not_affected while afile:directory copy of the patched package@version installs unpatched, and hosted scan gives no warning for that copy #921,get <name>doesn't PEP 503-normalise PyPI names, soget typing_extensionsorget ruamel.yamlreports "No packages matching" (exit 0) for an installed, patchable package #926, Vendored requirements.txt fromuv pip compile --universalrefuses a marker-split package (six==1.16.0 ; python < 3.12+six==1.17.0 ; python >= 3.12) as "not pinned to ==1.16.0", while --dry-run previews would_vendor and hosted / vendored pylock handle the same split #928, Hosted Pipenv scan silently rewrites a Pipfile.lock entry to a single platform-specific patched wheel (cp311 manylinux), sopipenv syncfails on every other Python version, macOS and Windows #932, Vendored scan of a fresh Pipenv checkout (no venv yet) fails with exit 1 on packages that exist only in the system Python, because the crawler falls back to the global site-packages #947, Vendored pnpm 7/8 (lock 5.4 / 6.0) writes an unquotedname: @scope/pkgfor a scoped package, so every frozen install fails with ERR_PNPM_BROKEN_LOCKFILE after a successful scan #956, Vendored pnpm 9+ misses the aliased-importer refusal for a scoped npm alias (sl: npm:@scope/pkg@x), so it leaves a dangling quoted importer reference: scan says success, frozen installs fail, and VEX attests not_affected #957, On Alpine/musl,@socketsecurity/socket-patchinstalled with yarn classic exits 1 with no output: yarn 1 ignoreslibc, installs both -gnu and -musl binaries, and the wrapper runs the glibc one #974 and Lock-only requirements.txt discovery skips-rincludes that are quoted, backslash-escaped or use${VAR}(-r "dev reqs.txt",--requirement="dev.txt",-r ${DIR}/dev.txt), so the scan exits 0 with "No patches" while pip installs the include's unpatched pins #994. Every bughunt issue has itspm:*label.fail. Bug hunt ledger: Yarn classic (1.x) #304 already notes its closures and was skipped, and so was Bug hunt ledger: pnpm #303's Vendored pnpm 7/8 (lock 5.4 / 6.0) writes an unquotedname: @scope/pkgfor a scoped package, so every frozen install fails with ERR_PNPM_BROKEN_LOCKFILE after a successful scan #956. One drift comment went to Benchmark progress: socket-patch scan #575 (Slow scan: poetry hosted 4.5x median ms/pkg (per-patch poetry.lock re-parse) #760 and Slow scan: pdm hosted 3.6x median ms/pkg (per-patch pdm.lock re-parse) #762 are closed by Fix per-patch Poetry/PDM lock re-parse (#760, #762) #877, but the body still lists them as slow with a draft fix).Recent actions (rolling, newest first)
2026-10-05T11:56:39Z-93d7a1on Spawn every CLI test child through one hermetic Command builder; 10 test files inherit ambient SOCKET_* today #823 (Spawn CLI test children through one hermetic Command builder (#823) #850 merged slice 1 only, no follow-up PR, claimer silent for more than 48h)agent:claimedfrom 33 closed issues (closed by the 2026-10-07 11:48–12:40Z merge wave, plus Hosted yarn classic redirect breaks every install in projects with a yarn-offline-mirror: the mirror's upstream tarball shares the hosted URL's basename and fails the new integrity pin #364, Hosted and vendored Bun rewiring silently discards the project's ownbun patch(patchedDependencies): fresh frozen installs drop the user's patch with exit 0 #367, Hostedrollback,removeand the vendored takeover refuse a requirements.txt whose only requirements are hosted pins (six==1.16.0alone can be patched but never unpatched) #410, scan/get --json drop the agent-mode apply failure: exit 1 with failed: 0, the patch shown as "added", and no error anywhere (e.g. a read-only global ~/.m2) #424, A report-onlyscan -gtells you to runsocket-patch scan --mode agent [PATHS]without-g, so following the hint scans the cwd project instead of the global install #464, Agent-mode scan in a Pipenv project without a Pipenv venv patches the system Python's site-packages in place instead of the project's venv/ (regression from #388) #504 and vlt hosted rollback and remove rewrite slot [3] to a synthesized/<name>/-/<leaf>-<ver>.tgzURL instead of the registry's dist.tarball, so the next coldvlt ci404s #521, which were closed earlier)fail)abb5787asaid "Fixes Hosted scan/get run from a pnpm workspace member (or withlockfile-dir=..) ignores the parent pnpm-lock.yaml and reports success while pinning nothing #590 and Hosted cargo scan run from a workspace member treats it as a lockless project, rewrites only the member, and breaks every build of the workspace while reporting success #417", but only Hosted scan/get run from a pnpm workspace member (or withlockfile-dir=..) ignores the parent pnpm-lock.yaml and reports success while pinning nothing #590 auto-closed;cargo_hosted_scan_from_workspace_member_refuseson main)0c1e07b8said "Fixes Hosted NuGet mapping reads commented-out package sources #561 and Hosted NuGet splices the Socket source (and mapping) into a commented-out <packageSources> / <packageSourceMapping> block, so every restore fails NU1100 while scan reports success and its in-run VEX attests not_affected #585", but only Hosted NuGet mapping reads commented-out package sources #561 auto-closed; hosted NuGet anchors come fromformats::nuget::parse_config)applycan't apply Maven patch records keyed by jar member paths, althoughvendoraccepts the same record #264 as completed (PR Full Gradle support in agent, hosted and vendored modes #6460685ba8caddedpatch/jvm_jar.rs, a member-keyed Maven record jar swap inapply_maven_base; tests ingradle_agent_cli.rs)2026-10-04T03:20:54Z-020a8fon uv projects never pick up a superseding patch: hosted re-scan lists the upgrade in updates[] but refuses its own earlier [tool.uv.sources] pin (exit 0, still on the old uuid), and vendored re-scan fails pypi_uv_source_already_exists #742 and Hatch never picks up a superseding patch: re-scan refuses its own earlier wiring ("existing direct source must be reverted"), so hosted exits 0 still pinned to the old patch uuid #650 (only the hosted slice merged in Fix uv/Hatch hosted re-pin to a newer patch (#742, #650) #743, no vendored PR, claimer silent for more than 48h)agent:claimedfrom 34 closed issues (Hosted cargo scan run from a workspace member treats it as a lockless project, rewrites only the member, and breaks every build of the workspace while reporting success #417, plus 33 closed by the 2026-10-05 13:39–18:16Z merge wave)fail), Bug hunt ledger: vlt #307 (Hosted and vendored modes refuse vlt 1.3 locks whose nodes carry the new brotli flag (slot [0] = 4) #372), Bug hunt ledger: Bundler (RubyGems) #316 (Hosted gem VEX attestsnot_affectedfor an unpatched install when.bundle/configsets an out-of-treepath(absolute or~/…), because the skipped bundle root counts as "nothing installed" #709), Bug hunt ledger: NuGet / dotnet #320 (Vendored yarn classic replaces a symlinked yarn.lock with a regular file (hosted refuses the same lock), leaving the link's target unpatched; rollback never restores the link #627) and Bug hunt ledger: npm #302 (npm v2 lock: aliased packages stay on the registry in the legacy dependencies mirror (hosted silently, vendored with a warning), so npm 6 installs unpatched bytes while VEX attests not_affected #432)include-group#473 as completed (PR Fix uv hosted unwind declaration matching (#606, #473) #6259df2afa5said "Fixes Hosted uv rollback, remove and vendored takeover refuse when the patched package is declared with different specifiers independenciesand an extra (or under different markers), although each lock entry keeps its marker #606 and Hosted uv rollback and remove refuse when the patched package reaches a dependency group through PEP 735include-group#473", but only Hosted uv rollback, remove and vendored takeover refuse when the patched package is declared with different specifiers independenciesand an extra (or under different markers), although each lock entry keeps its marker #606 auto-closed;include_group_membertest on main)2465131e; site config layer read inpdm_global_site_packages_with).deno/<name>@<ver>_1copy is unpatched: the #517 every-copy check never sees store peer-variant copies #603 as completed (PR Fix npm store copies missed by agent apply and vex (#601, #603) #60546466931;verify_mode_requires_every_store_copy_patchedcovers the Deno_1case)agent:claimedfrom 49 closed issues (46 closed by the 11:13–13:20Z merge wave, plus Hosted uv rollback and remove refuse when the patched package reaches a dependency group through PEP 735include-group#473, Global scan (-g) ignores PDM's site-wide config, so a global project relocated in /etc/xdg/pdm/config.toml is never crawled and get -g reports "applied" while the copy PDM runs stays unpatched #566 and Agent-mode vex still attests not_affected when a Deno.deno/<name>@<ver>_1copy is unpatched: the #517 every-copy check never sees store peer-variant copies #603 above)fail)scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 for Windows)scan -gofficial-installer row isfailbut points only at closed Global scan (-g) never crawls pipx venvs, so the dependencies of a pipx-installed Hatch are never reported, patched or rolled back on any OS #415; no open issue tracks it)fail)agent:claimedfrom closed The patch API client has no request timeout, so scan, get and apply hang forever on a stalled server #570 (closed as completed by PR Bound patch API connects and stalled reads (#570) #581)agent:claimed(no PR for the remaining half, claimer silent for more than 48h)agent:claimedfrom closed Poetry hosted ⇄ vendored mode switch is refused, and blames a "user-authored" source that socket-patch wrote itself #328 (closed as completed, so the claim is finished)agent:claimedfrom closed Pipenv recognizes hosted PyPI patch URLs with two private grammars that disagree with the shared one #563 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted gem redirect appends a second declaration when the gem is declared througheval_gemfileor a loop, so everybundle installfails with "You cannot specify the same gem twice" #482 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted gem redirect rewrites only the first of a gem's declarations, so a gem listed in twogroupblocks makes everybundle installfail with "You cannot specify the same gem twice" #548 (closed as completed, so the claim is finished)fail)fail)fail)fail)fail)fail)agent:claimedfrom closed Bun isolated linker: transitive packages under node_modules/.bun are "not installed" in agent mode, and scan --mode agent exits 0 with them unpatched #366 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted → vendored takeover on yarn berry reverts the hosted redirect before a per-package vendor refusal, leaving the package unpatched in both modes #369 (closed as completed, so the claim is finished)agent:claimedfrom closed Deno nodeModulesDir: transitive npm packages under node_modules/.deno are "not installed", and apply/scan exit 0 leaving them unpatched #373 (closed as completed, so the claim is finished)agent:claimedfrom closed npm apply exits 1 when every patch targets a platform-skipped optional dependency (fsevents, @esbuild/*), so the setup hook fails npm ci and npm install on other OSes #403 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted yarn berry redirect makes yarn send the project's npm registry auth token to the patch host #404 (closed as completed, so the claim is finished)agent:claimedfrom closed With Bun's isolated linker,vexattests a hosted patch as not_affected (verified) while the installed copy under node_modules/.bun is still unpatched (v5 regression) #405 (closed as completed, so the claim is finished)agent:claimedfrom closed Vendored → hosted takeover on yarn berry deletes the vendored patch, then skips the hosted rewrite when the grant has no yarnBerry10c0 checksum, and still exits 0 "fully hosted" #468 (closed as completed, so the claim is finished)agent:claimedfrom closed Yarn 4 pnpm linker: transitive packages that live only in node_modules/.store are "not installed" in agent mode and stay unpatched #495 (closed as completed, so the claim is finished)agent:claimedfrom closed Agent-mode npmvexhashes only the first installed copy of a package, so it attests not_affected while another nested copy of the same name@version is unpatched #516 (closed as completed, so the claim is finished)fail)Deferred / unsure
Claim-ID: 2026-10-05T13:56:13Z-6cfcbb, slice 1 merged as Compute sha256, sha1 and SRI digests through utils::digest (#706) #865) reaches 48h at 2026-10-07 13:59Z, just after this run. Release it next run if no follow-up PR appears.trustLockfile: trueauto-config when pnpm-lock.yaml starts with a UTF-8 BOM, so pnpm 11/12 frozen installs fail with ERR_PNPM_TARBALL_URL_MISMATCH after a successful scan #903, pnpm-workspace.yaml with a UTF-8 BOM: hosted and vendored miss the first top-level key and append a duplicatetrustLockfile/overrides, so every pnpm install fails with "duplicate mapping key" after a successful scan #904 and pnpm lock and workspace readers don't skip a leading BOM, because BOM handling has no shared helper (4 named copies, ~50 inline strips) #905 (batch3fcf3e, claimed 2026-10-06 01:24Z, no PR). Release them after 2026-10-08 01:25Z if there's still no PR.scan/get --mode vendored) restores the package to PyPI before the uv vendored refusals run, so an inline[tool.uv] sources = {…}table (or a #928 marker split) leaves it unpatched in both modes, while --dry-run previews would_vendor #944 have a new claim (2026-10-07T12:44:29Z-pnpm07, PR Fix open pnpm issues (#1006, #919, #902, #854, #853, #830, #778, #734, #714, #713, #633, #556, #492, #466, #435) #1007) for the dry-run preview slice. Hatch never picks up a superseding patch: re-scan refuses its own earlier wiring ("existing direct source must be reverted"), so hosted exits 0 still pinned to the old patch uuid #650 and uv projects never pick up a superseding patch: hosted re-scan lists the upgrade in updates[] but refuses its own earlier [tool.uv.sources] pin (exit 0, still on the old uuid), and vendored re-scan fails pypi_uv_source_already_exists #742 were re-claimed for the vendored half (PR Fix vendored uv/Hatch re-vendor to a newer patch (#742, #650) #943).paththat isn't installed yet, soscan --mode hosted --vexfails withno_applicable_patcheson fresh checkouts #1001 and Hosted gem stale-install warning calls the project's ownvendor/bundlea "shared gem home" when--cwdis left at its default (or relative), so it gives the wrong remedy and drops the committed cache archive from the delete list #729 → Fix gem stale-install guard home selection (#1001, #729) #1002; Hosted and vendored pnpm 11/12 refuse a standalone project nested under an unrelated pnpm-workspace.yaml (not in itspackages:globs) as a "workspace member", and the suggested fix doesn't work (regression from #888) #1006, Global agent mode on pnpm 12 (and 11 without the global virtual store) patches only one of the per-install copies of a package, reports success, and VEX attests not_affected #435, Vendored pnpm 12 withpackageManagerset: the two-document pnpm-lock.yaml makes vendor refuse, andvendor --revert, rollback and the hosted takeover half-revert the project and break frozen installs #466, Hosted scan on a pnpm workspace withsharedWorkspaceLockfile: falseignores the per-package pnpm-lock.yaml files and reports success while redirecting nothing #492, Hosted scan with pnpmgitBranchLockfilepins the stale pnpm-lock.yaml and reports success, while pnpm installs unpatched bytes from pnpm-lock.<branch>.yaml #556, Agent-mode apply in a pnpm workspace reports each member-linked package twice, inflating the --json skipped count with duplicate already_patched events #633, Hosted scan on a Rush repo with pnpm 11/12 reports success, butrush installthen fails with ERR_PNPM_TARBALL_URL_MISMATCH, or (pnpm 11.0.0) silently installs the upstream package #713, Hosted scan on a Rush repo with subspaces never emitsredirect_rush_repo_state_stale, sorush installfails on the shrinkwrap hash check with no warning #714, Hosted and vendored modes create apackages: ['.']pnpm-workspace.yaml that turns a single-package project into a workspace, sopnpm add <pkg>fails with ERR_PNPM_ADDING_TO_ROOT on pnpm 9.0–10.4 #734, Agent-modescan packages/<member>finds nothing in a pnpm workspace (exit 0), whilerollback packages/<member>selects the same packages #778, Vendored pnpm: unwinding a vendored package whose dependency is also vendored clobbers the child's lock wiring —remove <parent>breaks frozen installs, the hosted takeover silently unpatches the child, and rollback fails forever #830, pnpm hosted → vendored takeover un-hosts the package before pnpm's vendored refusals run, so a catalog entry, a CRLF lock or a workspace exact-pin override leaves it unpatched in both modes #853, Vendored pnpm refuses a user exact-pin override (left-pad: 1.3.0) in pnpm-workspace.yaml with a misleading "does not match package.json" error, though the same pin in package.json is taken over #854, Hosted pnpm rollback/remove adds registrytarball:URLs the lock never had whenlockfileIncludeTarballUrlsits in a settings file the installed pnpm ignores (workspace file on pnpm 9,.npmrcon pnpm 11/12) #902 and Hosted pnpm rollback/remove restorespnpm-lock.yamlfrom npmjs's version document instead of the project's.npmrcregistry, so a mirror project loses itstarball:URL (cold frozen install 404s) or is moved to npmjs #919 → Fix open pnpm issues (#1006, #919, #902, #854, #853, #830, #778, #734, #714, #713, #633, #556, #492, #466, #435) #1007; scan --mode agent --json and get --json overwrite a locally modified npm file without the documented content_mismatch_overwritten warning (not in the JSON, not on stderr) #1004, A rolled-back vendor eject prints "Vendored 1 package" and "Commit .socket/vendor/" with no eject_rolled_back warning, and --json still reports the rolled-back package as applied #1005, remove --preserve-state on a manifest-less hosted npm project silently restores the pin without the documented hosted_state_not_preservable note #433, Agent-mode scan ignores socket.yml includePaths / ignorePaths (and the built-in tests/ default) for nested npm projects, patching every nested project's node_modules #554, Walk package-lock entries once for inventory, vendored, hosted and restore #663, npm vendored refuses a registry package with vendor_workspace_member whenever a local file: directory (or workspace member) has the same name@version, and the hosted→vendored takeover then un-hosts it, leaving it unpatched #688, Hosted npm scan pins a package that npm 12's nativepatchedDependenciesalso patches, so every laternpm ci/npm installfails EPATCHFAILED (and vendored refuses the lockfileVersion 4 lock with wrong advice) #711, npm hosted and vendored modes rewrite a lock entry nested under a dependency that ships npm-shrinkwrap.json (hasShrinkwrap), so npm 7–11 install it unpatched while vendored VEX attests not_affected #753, Hosted npm scan pins a hosted tarball URL that npm rewrites to the registry under replace-registry-host=always, so every npm ci / npm install then fails E404 while the scan reports success #812, npm hosted pin next to a bundled copy can't be unwound: rollback/remove refuse it, and the vendored takeover skips the restore, so vendor --revert lands back on hosted and allow-remote=all stays #828, Resolve VEX npm alias copies through the core resolver and delete vex_consumed's second alias walk #856, Vendored npm vex and vendor --check fail after any npm 7–10npm installon a lockfileVersion 2 lock, because npm dropsresolvedfrom the legacy mirror and #813 treats that as an unpatched npm 6 install (regression) #879, Vendored npm refusal for a symlinked package-lock.json says "nothing was written" but leaves the vendored tarball behind, then prints "Vendored 1 package" and tells you to commit .socket/vendor/ #898, npm 12 never reads npm-shrinkwrap.json, so on a shrinkwrap-only project hosted and vendored scans rewrite a lock npm 12 ignores: scan succeeds with no warning, lockfile-only VEX attests not_affected, andnpm installinstalls the unpatched package #899, Tracking: drive the seven npm-family vendor backends through one generic driver #920, Build npm-family vendor ledger entries through one constructor instead of seven literal VendorEntry blocks #922, Vendored npm re-scan exits 1 ("Failed to vendor", "1 failed") on every run while a superseding patch's artifact is pending_build / build_failed / not_found, although the vendored older patch is intact; hosted skips the same upgrade with exit 0 #954, Vendored npm scan wires file: tarballs that npm ≥ 11.14 refuses under allow-file=root (transitive deps) or allow-file=none, so every npm ci fails EALLOWFILE while scan, vendor --check and vex report success with no warning #969 and Perf regression: npm/hosted wall +15% (2463257a..9c43dfc9) #993 → Fix open npm issues #1008; Global mode misses every Bun global package when BUN_INSTALL_BIN or BUN_INSTALL_GLOBAL_DIR is set: scan -g reports success with nothing found, get -g / vex -g patch and attest nothing #443, Bun hosted and vendored modes skip a URL orfile:tarball copy of the patched package without warning, and vendoredvexattests not_affected (the #326 fix covers npm locks only) #497, Perf regression: bun/hosted wall +110% (1169ae68, #472) #578, With Bun's isolated linker,vexrefuses every hosted patch as not_applied after the usual in-placebun install, because it checks orphanednode_modules/.bunregistry entries that Bun never removes (regression from #496) #599, With Bun's globalStore (Bun ≥ 1.3.14), agent mode patches and rolls back every other project sharing the store, and vex attests unpatched transitive copies as not_affected #635, Lock inventory ignores a bun.lockb that Bun installs from when bun.lock is a dangling symlink #735, After a Bun rollback orvendor --revert, the advisedbun installkeeps the patched bytes installed on the hoisted linker (Bun reports "no changes") #764, After Bun migrates a vendored bun.lockb to bun.lock (bun install --save-text-lockfile), vendor --revert and rollback fail, and a superseding re-vendor drops the pre-vendor original so revert exits 0 with the project still vendored #784, Vendored re-run on an isolated-linker bun.lockb writes two package records with the same local tarball, so frozen installs on Bun 1.3.9/1.4.2 fail intermittently with EEXIST #861 and Hosted Bun rollback/remove writes an empty registry slot that Bun < 1.3.7 resolves against npmjs, so custom-registry projects can't frozen-install after a revert #992 → Fix open bun issues (#992, #861, #784, #764, #735, #635, #599, #578, #497, #443, #371) #1009; Vendored yarn berry PnP refusal keys only on .pnp.cjs: a lock-only PnP checkout vendors successfully, then every re-run in an installed checkout fails exit 1 with vendor_yarn_berry_unsupported #539 and Yarn 4 node-modules / pnpm-linker projects migrated from Yarn 2 PnP keep a stale.pnp.js, and socket-patch refuses them as Plug'n'Play: agent and vendored exit 1, hosted warns "npm dependencies were NOT scanned" (regression since 3.3.0) #975 → Fix yarn PnP detection ignoring nodeLinker (#975, #539) #978; Hosted yarn berry rewrites a mixed-line-ending package.json that vendored mode refuses #628 and Share the yarn berry project gates between hosted and vendored modes #629 → Fix yarn berry project gates drifting between modes (#628, #629) #657; Vendor-service retries ignore an HTTP-date Retry-After: fold the vendor Retry-After parser and jitter onto api::retry #677 → Honor HTTP-date Retry-After on vendor-service retries through api::retry (#677) #889; Hosted and lock-only scans treat a UTF-16 requirements.txt (what Windows PowerShell'spip freeze >writes) as absent: exit 0, no warning, and pip keeps installing the unpatched pin #721 → Fix UTF-16 requirements.txt silently skipped (#721) #724; uv vendored → hosted takeover strands a package that vendored mode pinned to a different version than uv.lock: the wet run reverts to the unpatched release (exit 1), while --dry-run previews a clean takeover #723 and Poetry 0.x vendored → hosted takeover un-vendors the package before hosted mode refuses the lock, while --dry-run previews a clean takeover (redirected: 1, exit 0) #945 → Fix PyPI hosted takeover un-vendoring before refusal (#723, #945) #946; Hosted gem redirect ignores Bundler 4's custom lockfile (lockfilesetting /BUNDLE_LOCKFILE), so it never pins the lock Bundler uses and frozen installs fail with no warning #749 and Hosted gem redirect wiresgems.rbin a Gemfile/gems.rb twin locked by Bundler 1.17, which loadsGemfile, so the install stays unpatched while the in-run VEX attests it #751 → Fix gem pair model ignoring custom lockfile and Bundler 1 twins (#749, #751) #768; Gem hosted → vendored takeover un-hosts a gem declared inside agroupblock and then refuses to vendor it (gemfile_declaration_not_editable), so the project silently goes back to unpatched #775 → Fix gem takeover un-hosting a grouped gem (#775) #776; Vendored requirements.txt:vendor --revert/removedelete the vendored wheel while a-rinclude still points at it (exit 0), so every laterpip install -r requirements.txtfails #867 and Vendored uv:vendor --revert/remove/rollbackdelete the vendored wheel while auv export-ed requirements.txt or pylock.toml still points at it (exit 0), so installs from the exported file fail #996 → Fix PyPI revert deleting still-referenced wheel (#996, #867) #997; Registry downloads give up after 60 s even while the body is still arriving #872 → Bound registry downloads by ApiTimeouts instead of a 60 s total deadline (#872) #876; Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap) #907 → Fix hosted yarn classic pins missing berry warning (#907) #917; After an agent→hosted migration, a superseding patch leaves the stale agent manifest record, so npm rollback exits 1 ("modified after patching") and remove refuses to un-host #933 → Fix rollback/remove of an agent record superseded by a hosted pin (#933) #934; pnpm VEX attests not_affected while afile:directory orfile:tarball copy of the patched package@version in the same pnpm-lock.yaml installs unpatched, and hosted/vendored scans give no warning for that copy #935, Yarn classic VEX attests not_affected when yarn.lock also has a registry block for the patched name@version (e.g. afteryarn add -W <pkg> --exact), though yarn installs only the unpatched registry copy #938 and Yarn berry hosted and vendored scans miss afile:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939 → Fix VEX attesting beside an unpatched same-lock copy (#935, #938, #939) #940; Gem.bundle/configreader keeps a trailing# commentin the value, so a commentedBUNDLE_PATHis missed, agentapplypatches the system copy andvexattestsnot_affectedwhile Bundler loads the unpatched project copy #951 → Fix .bundle/config values keeping a trailing # comment (#951) #953; Vendored scan of a fresh uv checkout (uv.lock, no .venv yet) exits 1 on packages that exist only in the system Python, because the crawler falls back to the global site-packages (the uv side of #947) #964 → Fix uv project with no env falling back to system Python (#964) #965; Gem crawler ignores Bundler's.bundledefault install path (default_install_uses_pathon 2.x,simulate_version 5on 4.x), so agentapplypatches the system copy andvexattestsnot_affectedwhile Bundler loads the unpatched.bundle/ruby/<abi>copy #967 → Fix gem crawler missing Bundler .bundle root (#967) #968; Vendoredvendor --dry-runpreviews success on a uv project with an inline[tool.uv]/sourcestable, but the real run refusespypi_uv_lock_parse_failed(exit 1) #979 → Fix uv dry run missing inline [tool.uv] refusal (#979) #980.Claim-ID: 2026-10-07T12:56:20Z-90d5b6) are claimed with no PR yet. They're fresh.--jsontop-levelerror(scan and get emit both a string and a {code, message} object) #704, Decide: make --download-mode file the default and retire the diff download path #792, Decide: keep .socket/apply.lock transient, or give the lock a file that never has to be deleted #808, Decide: warn on and then remove scan --apply/--vendor, and whether --vex stays embedded #966 and Decide: vendor single-module Maven poms through the suffixed-version jvm planner and retire the same-GAV <repository> wiring #973 had maintainer comments in the last 72h and recorded decisions. Hands off.Needs a human
agent:needs-humanany more. The former set (Decide: keep .socket/apply.lock transient, or give the lock a file that never has to be deleted #808, Decide: make --download-mode file the default and retire the diff download path #792, Decide: one shape for the--jsontop-levelerror(scan and get emit both a string and a {code, message} object) #704, Decide: where patch API calls go when a token is set but the org slug can't be resolved #648, Decide: give SOCKET_FORCE per-command names so forcing a self-update doesn't also force apply and vendor #615, Benchmark tracking: socket-patch scan #580) has maintainer decisions and is now claimed.Generated by Claude Code
All reactions