Skip to content

v5 prerelease: scan → vex → vendor workflow, hosted by default - #277

Merged
Mikola Lysenko (mikolalysenko) merged 1 commit into
mainfrom
release/v5-prerelease
Oct 1, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 1 commit into
mainfrom
release/v5-prerelease

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

This PR integrates the v5 prerelease workflow: scan applies hosted patch references, the package manager installs them, and vex emits OpenVEX evidence. vendor materializes the selected patched packages for committed/offline use; list inspects the live state.

  • Hosted mode is the default for scan and get. Hosted state is read from dependency files, with no new hosted ledger. rollback and remove resolve upstream references, and unsupported/offline restoration fails explicitly.
  • Vendoring uses verified service artifacts and a shared backend for vendor, repair, rollback, and remove. Fresh lock-only checkouts, release variants, artifact identity, re-vendoring, and service-outage reuse are covered by the integrated fixes and regression tests.
  • socket.yml, package/severity filters, directory targeting, and --max-new-patches control rollout. Automatic selection prefers the highest severity, then the most distinct advisories fixed, then publication date. Selection and upgrade detection use the same order; tier/UUID ties alone do not trigger replacement. Multi-directory scans reject a single --vex destination before making changes.
  • Shared project snapshots and format models support the CLI and in-memory hosted engine. The integrated changes expand package-manager compatibility, lockfile discovery, VEX, and JVM vendoring.
  • The v5 migration removes setup, obsolete hooks/flags, and PyPI/RubyGems CLI distributions. Standalone binaries, Cargo, and npm distributions remain; Python/Ruby project support remains available. See the migration guide.
  • CI reuses compiled E2E binaries and runs the full release-branch compatibility tier. Usage, configuration, CLI contracts, migration instructions, and the changelog describe the integrated behavior.

Validation for the ranking change: 39 core ranking tests and 891 CLI/unit/integration tests passed locally, including the repository-policy, in-memory rollout, in-process scan, and disk rollout suites. Workspace Clippy passed with all features and warnings denied. The PR is squashed into one signed commit directly on main; GitHub CI and CodeQL are running on that commit.

CodeQL findings were reviewed against the source, and 61 false positives were dismissed with explanations: public patch identifiers/test diagnostics, a fixture-case count, and the intentional local developer regex option. Scanning remains enabled.

The packaging version is still 4.0.0; the documented release process performs the v5 version bump and publication in a separate release PR/workflow. This integration PR does not publish a release.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Release review at 8ae7dc37: hold the release until the integrated hosted lifecycle is working and green. The direction is right, but the stack currently removes some visible CLI surface while adding new restoration/state machinery behind it.

I reviewed all seven open PRs and left specific feedback:

PR Assessment
#279 Keep setup/hook removal. Finish consistent empty-list status, command grouping and one result schema.
#280 Fix offline HTTP, fresh-checkout eject and dropped wiring diagnostics. Share restore grammar; delete the checked-in .orig.
#281 Good registry/model direction; complete shared grammar instead of retaining parallel readers/writers. Reproduced inherited Gem checksum duplication.
#282 Good core/Node boundary. Remove repeated ledger sorting and finish one project snapshot plus ledger-free disk/memory integration.
#283 Good backend consolidation, but two reproduced repair regressions: lost offline source bytes and silently changed lock integrity.
#270 Useful Composer correctness foundation; no new blocker confirmed. Reuse its identity/installer rules in the v5 models and restore path.

The simplification I would ship:

  1. One normal workflow: scan selects and applies hosted patches; scan --vex <file> optionally emits the report in the same run; vendor changes the same selected patch set to committed artifacts. Keep standalone vex/list for inspection. Make targeted get a thin selector over that same execution path, and route undo/remove through the same transition planner. Preserve the planned agent-mode escape hatch without duplicating its orchestration.
  2. One data path: project snapshot → parsed format models → patch selection → typed change plan → verified artifacts → commit → human/JSON rendering. Share inventory/wiring views, keep VEX eligibility separate, and reload/invalidate after writes. Hiding flags is not a substitute for deleting parallel execution branches.
  3. One acquisition path with explicit policy: reuse service artifacts where available; isolate the local-build fallback. Repair can reuse acquisition but must preserve the original artifact identity and lock wiring. Hosted→vendor should not pass through a committed unpatched state when conversion fails.
  4. Delete obsolete hosted write/replay machinery after checking consumers. Keep a small legacy reader. Prefer removing duplicate parsers and event-to-JSON-to-event conversions over cutting supported ecosystems or package-manager versions.
  5. Measure the intended savings: crawl/parse counts, API requests, no-op re-run work and end-to-end latency. Ledgers::owned() currently adds a repeated full sort/scan; ProjectContext still caches two separate parses. These are more useful optimization targets than moving functions between files.

Release gates:

  • All ten pairs of the five sibling cleanup heads produced merge conflicts in git merge-tree, including edits to files another PR deletes. Stack/rebase in a declared order and test the actual combined tree; per-branch results do not validate the release.
  • Run a lifecycle matrix: fresh lock-only checkout → hosted scan → native install → VEX/list → vendor → offline install → repair → rollback. Cover human/JSON/dry-run parity, zero HTTP offline, and failure injection that preserves existing protection.
  • Migrate the remaining tests that assume agent defaults or a hosted ledger. I checked the base Cargo CI failures and a #280 Go job; those include obsolete ledger assumptions, not evidence that every red job is a new product defect. They still need to be green under the new contract before release.
  • Finish the v5 version bump and docs against that integrated behavior. Workspace version is still 4.0.0 in this draft.

The inline comments cover a reproduced multi-project VEX overwrite and a patch-selection invariant that deserves an explicit decision before unattended mutation becomes the default.

Validation: source/diff and CI-log review across all seven PRs; isolated CLI builds/reproductions; 36 upstream restoration goldens passed; repair behavior compared before/after. No full cross-platform matrix or conflict-resolved integration build was run. Cloud delegation was attempted but rejected with 403: GitHub connector is disabled or unavailable, so this review ran locally in isolated worktrees.

Comment thread crates/socket-patch-cli/src/commands/scan/mod.rs
Comment thread crates/socket-patch-core/src/api/ranking.rs Outdated
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] Detailed v5 implementation handoff, incorporating Mikola's latest direction from the review discussion.

Target: make depscan the owner of package construction and remove CLI repacking where the hosted artifact contract supports it. Lockfile changes are part of the intended workflow and should remain supported. Mikola is comfortable keeping the entire repacking engine in depscan and prefers deleting the CLI copy if feasible. Avoid breaking or rewriting depscan's working builder merely to achieve code sharing.

This supersedes my earlier suggestion to expose the Rust repacker to both callers. Prefer the smaller migration: preserve depscan's existing implementation, turn the CLI into an artifact consumer, and delete redundant client construction paths.

What is actually shared today

In the inspected depscan checkout (c70d82a4097b61842c8834f8f490c1b5c93c9e80), production goes through buildAndStorePatchPackage → convertPatchToPackage → TypeScript ecosystem repackers and @socketsecurity/patches-shared/archive/repack-utils. Its own repack-* commands reuse those modules. This path does not call socket-patch's Rust repackers.

There is real duplication. Depscan's Berry writer explicitly identifies itself as a port of the CLI implementation. The npm paths also differ: depscan preserves upstream tar entry order and uses epoch timestamps; the CLI sorts paths and uses npm's fixed 1985 timestamp. Equal patched members therefore do not imply equal archive digests. Preserve already-published bytes and identities during this migration.

Suggested implementation sequence

  1. Establish the artifact coverage boundary before deleting code. Inventory each CLI vendor backend's required archive, extracted layout, auxiliary files and native checksums. Match these against the existing service response and serving routes. An ecosystem appearing in depscan's repacker registry is not proof that every variant is downloadable. Its current servable-variant guard rejects Maven classifiers/non-JAR variants and platform-specific gems. Berry sidecars are optional. Check wheel tags, Berry cache versions, Go module flavors, Cargo metadata, gem stub gemspecs, Maven POMs and NuGet metadata against actual supported CLI paths. Report which gaps affect existing supported behavior; do not assume they all do.

  2. Introduce one artifact acquisition path using the existing service contract. Carry immutable artifact identity, variant and expected digest through selection, acquisition, validation and installation. Prefer an already verified committed/cached artifact; otherwise download the exact service artifact when online. Return typed per-package results. Fresh lock-only checkouts must not require an installed pristine dependency tree just to vendor a service artifact. Keep safe extraction, integrity verification and package-manager wiring in the client. Audit callers before deleting shared hashing/extraction helpers merely because they live beside packers.

  3. Make vendor and repair consumers of that path with explicit operation semantics. Vendor may deliberately select a new artifact and edit the lockfile. Repair restores the pinned identity. Acquire into staging, validate against the original expected identity, then replace the artifact; failure must preserve the current project state. Repair must not validate against a fingerprint that the same operation just rewrote. For a historical locally built archive whose digest differs from the service archive, return a precise recovery instruction or require an explicit re-vendor; do not silently substitute different bytes. An intact historical artifact should remain usable.

  4. Remove CLI construction and fallback paths once coverage is demonstrated. Candidates include archive packing, wheel rebuilding, Berry archive generation, pristine-source acquisition used only for building, patch-content staging used only for building, and VendorSource::Auto/Build branches. This is a call-graph audit, not a blanket directory deletion: agent-mode application, rollback/upstream resolution and integrity verification may still consume nearby helpers. Remove dead dependencies and tests specific to the deleted responsibility. Make the v5 change to --vendor-source build explicit in CLI behavior and migration docs; no hidden fallback to local rebuilding after a service error.

  5. Define offline behavior without promising offline reconstruction. Existing committed artifacts and verified cache hits remain usable without HTTP. Missing bytes with no local verified source produce a clear refusal before mutation. A service-only design cannot reconstruct missing historical bytes offline, so document that intentional change. Preserve vendored/offline installation. Test offline behavior at the network boundary, including dry runs, rather than relying on flags propagated through several layers.

  6. Keep depscan stable. Aim for a CLI-only PR against release/v5-prerelease. Do not replace the TypeScript repackers, change existing artifact URLs/digests, regenerate published packages or alter storage/publication behavior to make the CLI refactor easier. If an actual capability gap blocks removal, use a narrowly scoped additive depscan change in a separate dependent PR; preserve existing outputs and consumers. Avoid adding a second server implementation of the Rust engine. Where coverage is incomplete, state the remaining build path explicitly and defer its deletion rather than silently dropping package-manager support.

Other deletions that complement this boundary

  • scan and targeted get should select inputs for the same execution path. vendor should acquire/materialize the chosen artifacts and plan their local references. Hosted→vendor should acquire successfully before committing any removal of hosted protection.
  • Return typed backend outcomes and render human/JSON output afterward. The reviewed WS5: one VendoredBackend for vendored apply/revert/repair; cut repair's ledger rebuild #283 repair adapter creates a scratch Envelope and interprets event codes in EngineOutcome::of; this is an internal dependency on the output protocol. Delete that round trip.
  • Share each format's parsed representation among inventory, wiring, edits, repair and VEX. Keep raw wiring inventory separate from attestation eligibility so an invalid or conflicting reference cannot disappear from management commands.
  • Finish deletion of obsolete hosted ledger writers/replay after auditing library consumers. Keep only the legacy reading/migration behavior still needed. Do not recreate three competing authoritative stores behind a new context type.
  • Keep the shared disk/memory hosted engine from v5 WS4/WS6: one hosted engine for disk + memory; unified Ledgers view #282. Moving package construction to depscan does not imply moving the CLI's project/lockfile engine there.

Coordination and validation

The current sibling PRs are active and overlap heavily. Inspect their latest heads and existing reviews first. In particular, #283 advanced to 6b04d2f with fixes and regression tests for the two repair problems I reproduced at e3717a0; I have not rerun the new tests. Do not duplicate those fixes or treat the older findings as proof that the latest head still fails. The longer-term simplification is to avoid general apply/rewire during repair in the first place.

Use the existing release review and linked per-PR reviews as additional context. Revalidate findings against the integrated tree. Preserve all currently supported package-manager versions and the planned agent-mode escape hatch; update docs/design/v5-plan.md where the newly authorized removal of client building changes the previous contract.

Acceptance checks should cover:

  • Fresh lock-only checkout → hosted selection → native install → vendor → native offline install.
  • Missing/corrupt artifact repair with an exact cache/service match; digest mismatch, pending/unavailable artifact, interrupted acquisition and failure before commit.
  • A historical locally built artifact with a different digest: usable when intact, explicit refusal/migration when unavailable, no silent re-pin.
  • Zero HTTP offline; equivalent operation semantics for human/JSON and dry runs.
  • Required sidecars/variants and native installer compatibility for every backend touched.
  • No-op reruns avoid rebuilding, unnecessary downloads and repeated parsing.
  • Relevant existing tests on the combined branch; report actual results and any matrix not run.

Please push a focused draft PR targeting release/v5-prerelease, describe any dependency on the sibling PRs, list concrete removed paths/dependencies and retained compatibility gaps, and do not merge automatically. The desired result is less client code and fewer execution paths with depscan's existing package builder preserved.

Cloud delegation from this session is unavailable: task creation returned 403: GitHub connector is disabled or unavailable, and no cloud task was created. This comment is the implementation handoff for the agent already working on the release.

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Landing: #283 (WS5 VendoredBackend) landed on release/v5-prerelease as 06437d2; next up #281 (needs re-merge of the base). #288 fast lane still draft.


Generated by Claude Code

Comment thread crates/socket-patch-cli/src/commands/vendored_backend/repair.rs Dismissed
Comment thread crates/socket-patch-cli/src/commands/vendored_backend/repair.rs Dismissed
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Coordinator: #281 (WS3 lock models) landed on release/v5-prerelease as 73c0c4f; next in order is #279, which needs a re-merge of the base.


Generated by Claude Code

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Coordinator: #279 landed as f6bdad5 (CI reds all base-inherited: yarn-classic mode_migration_npm, vlt install-proof 0.0.0-*). Next: #282, which needs to merge the base again.


Generated by Claude Code

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Coordinator: #282 (one hosted engine) landed on release/v5-prerelease as 14a9cb0 — core four (#283, #281, #279, #282) are all in; next up #287, #291, #292, #293, #294 once re-merged and ready.


Generated by Claude Code

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Coordinator: #291 (v5 CI: build e2e binaries once and tier the PM matrix) landed on release/v5-prerelease as f9cb7e1, ahead of #287. Its only red checks (4 vlt install-proof cells, yarn-classic 1.0.2/1.6.0/1.7.0/1.9.4) fail the same way on the base. #287 is still blocked: it is a draft and nobody has pushed the docs-only reduction. Next up: #292.


Generated by Claude Code

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Coordinator: #292 landed on release/v5-prerelease as a7b0d00. Next up: #296, then #297, #293 and #294, each after it merges the new base and is ready. #287 is still skipped (draft, not yet reduced to docs-only).


Generated by Claude Code

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Coordinator: #296 (remove dead code and v3 shims) landed on release/v5-prerelease as 1e3ace6. Its only red checks were base-inherited: yarn-classic ×4 mode_migration_npm and vlt install-proof 0.0.0-1/0.0.0-11 ×4. Next up: #297, then #293 and #294, each after it merges the new base. #287 is still skipped (draft, not yet reduced to docs-only).


Generated by Claude Code

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Coordinator: #297 (one suite per command, retire #257 oracles) landed on release/v5-prerelease as b97a1c2. Its only red checks were base-inherited: yarn-classic ×4 and vlt install-proof 0.0.0-1/0.0.0-11 ×4. Next up: #293, then #294, each after it merges the new base. #287 is still skipped (draft, not yet reduced to docs-only).


Generated by Claude Code

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Coordinator: #293 (socket.yml patch rollout config and filtering) landed on release/v5-prerelease as b9e106d. Next: #294 (needs a re-merge of the base); #287 is still a draft; #295 is queued at the end.


Generated by Claude Code

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Coordinator: #294 (cap new patches per scan) landed on release/v5-prerelease as 180f10f. Still open: #287 (draft, waiting on its [agent] ready to land) and #295 (no ready comment yet).


Generated by Claude Code

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Claude (@claude) review

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: Multi-project VEX overwrites one file
    • Added a guard to reject --vex with multiple directories, preventing file overwrites by ensuring each scan uses a distinct output path.

Create PR

Or push these changes by commenting:

@cursor push 18234dbdbd
Preview (18234dbdbd)
diff --git a/crates/socket-patch-cli/src/commands/scan/mod.rs b/crates/socket-patch-cli/src/commands/scan/mod.rs
--- a/crates/socket-patch-cli/src/commands/scan/mod.rs
+++ b/crates/socket-patch-cli/src/commands/scan/mod.rs
@@ -1385,6 +1385,13 @@
         );
         return 2;
     }
+    if args.vex.vex.is_some() && dirs.len() > 1 {
+        eprintln!(
+            "Error: --vex takes one project directory ({} given); run one scan per directory",
+            dirs.len()
+        );
+        return 2;
+    }
     // One budget per invocation (§5.2): the directories spend it in sorted
     // order, and a package admitted in one is admitted free in the next.
     let configured = match args.rollout.resolve_from_env(invocation.policy.max_new_patches()) {

You can send follow-ups to the cloud agent here.

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 180f10f. Configure here.

Comment thread crates/socket-patch-cli/src/commands/scan/mod.rs
@socket-security

socket-security Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedcargo/​ignore@​0.4.339810093100100
Addedcargo/​serde-saphyr@​1.3.09610093100100

View full report

@socket-security-staging

socket-security-staging Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedcargo/​ignore@​0.4.339810093100100
Addedcargo/​serde-saphyr@​1.3.09610093100100

View full report

Comment thread scripts/pin-socket-hosts.py Fixed
Comment thread crates/socket-patch-core/src/patch/redirect/upstream/client.rs Dismissed
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] CI and review summary for this routine run (head df9fe07). Another Claude session pushed to this branch at the same time; its commits are credited below.

Root causes of the red CI and the fixes

  • Compile error that broke every Rust job (build, clippy, test, coverage, docker, e2e, node-addon and every ecosystem matrix). The Require server artifacts and exact redownload for vendoring #300 squash kept both Composer file-inventory fixes, so composer_lock.rs rebound a moved file_inventory (E0382, plus an unused variable under -D warnings). e47663c keeps the pre-lock-rewrite inventory (the marker lives in the uuid dir, outside the inventoried copy). fb47c56 (other session) also removes the extracted copy when that inventory fails.
  • lint-ecosystems (test_perf_harness): scripts/perf/replay.py recorded by_kind/by_status/inflight only after writing the response, so a client could read stats that didn't include its own request. a350536 accounts for each request before replying.
  • Audit GitHub Actions (zizmor, 25 cache-poisoning findings): caused by the push: release/v5-prerelease trigger. 83b958e (other session) drops that trigger and runs the full tier when head_ref == release/v5-prerelease, so coverage is kept. The audit is green now.
  • yarn-classic 1.0.2/1.6.0 legs: fixed in df9fe07 (other session).

Review threads

  • Multi-directory scan --vex overwrites one file (Mikola Lysenko (@mikolalysenko) and Cursor Bugbot): fixed in bd5caf5. --vex with more than one project directory is now a usage error (exit 2) before anything is touched, like --json. A regression test is in scan_paths_e2e and CLI_CONTRACT.md is updated. Both threads are resolved.
  • Merged-patch selection policy (ranking.rs): left open. The code matches the PR spec; moving to a server-recommended cumulative/supersession contract is an author decision.
  • CodeQL "use of insecure SSL/TLS" in pin-socket-hosts.py: fixed in 086fd31 (other session).
  • CodeQL "cleartext transmission" in patch/redirect/upstream/client.rs:187: I believe it's a false positive (a public patch UUID in a public-registry GET). Left open for a maintainer to dismiss. It is what keeps the CodeQL check red.

Still open

  • PDM compat, hosted cells only (rescanIdempotent/rescanAfterRelockApplies). It fails different cells on different PDM versions each run: 0.12.3 space-unicode on fb47c56; 2.10.4 transitive and pep582 on df9fe07. It passed on bd5caf5, which has the same PDM-relevant code, and the failing cells ran about twice as long, which fits the harness retrying against the live patch API. I couldn't confirm locally: the harness needs the live API, which my sandbox can't reach, and the run artifacts were blocked by the proxy. A re-run of the failed job was refused (403 This workflow run cannot be retried), so please re-run it from the UI. If it fails again, it needs a real look at hosted-rescan determinism.
  • coverage-docker (npm) on the superseded head a350536 failed on a corepack prepare crash inside Node's HTTP client (undici assert(!this.paused)) during the image build. It didn't recur on later heads.
  • 12 permission-based tests failed only in my root sandbox (chmod has no effect as root); they pass in CI.
  • cargo clippy --all-targets (not what CI runs) still flags a few test-only lints; left alone as out of scope.

Final state on df9fe07

  • Main CI: 181 of 182 jobs green, with test (windows-latest) still running when I checked.
  • All compat workflows except PDM, and Audit GHA, pin-check, Socket Security and CodeQL analyze: green.
  • Red: CodeQL (the gate on the open alert above) and PDM (the flake above).

Generated by Claude Code

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] Status on head f3127645. Every Actions workflow is green: CI (182 jobs), all ecosystem compat matrices (Bun, vlt, PDM, Poetry, pnpm, Composer, npm, Go, Pipenv), Pin check and Audit GHA. The only red check is CodeQL, and a code push can't clear it (details below).

#300 regressions fixed since df9fe07

After #300 compiled again, a multi-agent review of its production code found six issues. An independent verifier confirmed each one against the code. Each fix has a regression test:

  • pypi sdists (bec319b, 6618bc9): a committed server sdist was treated as platform-locked, so a failed re-wire swept the artifact the ledger still named. leaf_to_purl didn't recognise .tar.gz/.tgz/.zip sdists, so VEX and lock inventory dropped vendored sdists. uv's wired_pin also ignored the sdist = { hash } pin.
  • Inventory cap (1c044c5, efbbe31): composer, cargo and Go refused any package over 10,000 files. They now record no inventory and warn, the same as gem. A dry run also refuses a non-crates.io Cargo source, like the real run does.
  • Re-vendor of pre-v5 dir entries (b389a0f, fbb1cd2): a dir copy with no inventory could never be restored, and the suggested re-vendor failed the same way. vendor now rebuilds it from a fresh verified download, and the refusal messages name the remedy that works. Related: 924951a (vlt dirs ending in .zip) and 8eb0406 (Bun workspace mirrors are rewritten locally, offline too).
  • Release variants (e9f6154): on a fresh clone, vendor failed vendor_variant_ambiguous even when the ledger had already picked the variant.
  • Yarn Berry (c44db2b, 20c48ad): an in-sync re-run failed when a reused ledger entry had no yarnBerry10c0. The checksum now comes from the service first, and from our own lock entry only as an offline fallback that is never persisted.

CodeQL (55 high): needs dismissal in the code-scanning UI

I ran CodeQL 2.27.1 locally on this branch and on main, and diffed the results. The Python TLS alert (086fd31), the four uuid-printing test assertions (2eb7d9d) and four critical hard-coded-cryptographic-value hits on a test parameter named salt (f312764) are fixed. Everything left is a name heuristic, not a data flow:

  • rust/cleartext-logging / rust/cleartext-transmission: CodeQL treats any uuid as sensitive. These are public patch UUIDs that the CLI prints and requests by design (get, remove, repair, VEX discovery, and upstream/client.rs:187). Only about 8 of them are new relative to main. GitHub counts the rest as new because the diff is too large for it to match moved code.
  • js/regex-injection in scripts/study-crates.ts: the --filter <regex> flag of a local dev script. It is already on main; this PR only edits a doc comment in that file.

Suggested dismissal reason: "false positive" for the uuid alerts and "used in tests / won't fix" for the dev script. Changing product output to hide patch UUIDs would change the CLI contract, so I haven't done that.

Still open for the author

  • The ranking.rs merged-patch policy thread: a design decision; no code change here.
  • The PR description's "Known red: e2e_redirect_cargo_build" is stale. That suite passes now.

Generated by Claude Code

Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 1, 2026
Resolve conflicts with #277: keep Poetry-aware venv probe order in
find_local_venv_site_packages and add the Poetry entry to the
consolidated changelog.

Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 1, 2026
Brings in the v5 consolidation (#277). Keeps main's rewritten
CHANGELOG and re-adds this branch's Fixed entry, and points the
virtualStoreDir reader at strip_bom's new home in utils::serde.

Assisted-by: Claude Code:claude-opus-5-5
This was referenced Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants