Skip to content

Commit 18234db

Browse files
committed
Fix multi-project VEX file overwrite bug
Prevent multiple project directories from overwriting the same VEX output file by adding a guard that rejects --vex with multiple directories, similar to the existing --json guard. This prevents data loss when later projects overwrite earlier VEX documents or when a failed generation removes a shared file.
1 parent 180f10f commit 18234db

1 file changed

Lines changed: 7 additions & 0 deletions

File tree

  • crates/socket-patch-cli/src/commands/scan

‎crates/socket-patch-cli/src/commands/scan/mod.rs‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1385,6 +1385,13 @@ async fn run_project_dirs(
13851385
);
13861386
return 2;
13871387
}
1388+
if args.vex.vex.is_some() && dirs.len() > 1 {
1389+
eprintln!(
1390+
"Error: --vex takes one project directory ({} given); run one scan per directory",
1391+
dirs.len()
1392+
);
1393+
return 2;
1394+
}
13881395
// One budget per invocation (§5.2): the directories spend it in sorted
13891396
// order, and a package admitted in one is admitted free in the next.
13901397
let configured = match args.rollout.resolve_from_env(invocation.policy.max_new_patches()) {

0 commit comments

Comments
 (0)