v5 prerelease: scan → vex → vendor workflow, hosted by default - #277
Conversation
Mikola Lysenko (mikolalysenko)
left a comment
There was a problem hiding this comment.
Release review at 8ae7dc37: hold the release until the integrated hosted lifecycle is working and green. The direction is right, but the stack currently removes some visible CLI surface while adding new restoration/state machinery behind it.
I reviewed all seven open PRs and left specific feedback:
| PR | Assessment |
|---|---|
| #279 | Keep setup/hook removal. Finish consistent empty-list status, command grouping and one result schema. |
| #280 | Fix offline HTTP, fresh-checkout eject and dropped wiring diagnostics. Share restore grammar; delete the checked-in .orig. |
| #281 | Good registry/model direction; complete shared grammar instead of retaining parallel readers/writers. Reproduced inherited Gem checksum duplication. |
| #282 | Good core/Node boundary. Remove repeated ledger sorting and finish one project snapshot plus ledger-free disk/memory integration. |
| #283 | Good backend consolidation, but two reproduced repair regressions: lost offline source bytes and silently changed lock integrity. |
| #270 | Useful Composer correctness foundation; no new blocker confirmed. Reuse its identity/installer rules in the v5 models and restore path. |
The simplification I would ship:
- One normal workflow:
scanselects and applies hosted patches;scan --vex <file>optionally emits the report in the same run;vendorchanges the same selected patch set to committed artifacts. Keep standalonevex/listfor inspection. Make targetedgeta thin selector over that same execution path, and route undo/remove through the same transition planner. Preserve the planned agent-mode escape hatch without duplicating its orchestration. - One data path: project snapshot → parsed format models → patch selection → typed change plan → verified artifacts → commit → human/JSON rendering. Share inventory/wiring views, keep VEX eligibility separate, and reload/invalidate after writes. Hiding flags is not a substitute for deleting parallel execution branches.
- One acquisition path with explicit policy: reuse service artifacts where available; isolate the local-build fallback. Repair can reuse acquisition but must preserve the original artifact identity and lock wiring. Hosted→vendor should not pass through a committed unpatched state when conversion fails.
- Delete obsolete hosted write/replay machinery after checking consumers. Keep a small legacy reader. Prefer removing duplicate parsers and event-to-JSON-to-event conversions over cutting supported ecosystems or package-manager versions.
- Measure the intended savings: crawl/parse counts, API requests, no-op re-run work and end-to-end latency.
Ledgers::owned()currently adds a repeated full sort/scan;ProjectContextstill caches two separate parses. These are more useful optimization targets than moving functions between files.
Release gates:
- All ten pairs of the five sibling cleanup heads produced merge conflicts in
git merge-tree, including edits to files another PR deletes. Stack/rebase in a declared order and test the actual combined tree; per-branch results do not validate the release. - Run a lifecycle matrix: fresh lock-only checkout → hosted scan → native install → VEX/list → vendor → offline install → repair → rollback. Cover human/JSON/dry-run parity, zero HTTP offline, and failure injection that preserves existing protection.
- Migrate the remaining tests that assume agent defaults or a hosted ledger. I checked the base Cargo CI failures and a #280 Go job; those include obsolete ledger assumptions, not evidence that every red job is a new product defect. They still need to be green under the new contract before release.
- Finish the v5 version bump and docs against that integrated behavior. Workspace version is still
4.0.0in this draft.
The inline comments cover a reproduced multi-project VEX overwrite and a patch-selection invariant that deserves an explicit decision before unattended mutation becomes the default.
Validation: source/diff and CI-log review across all seven PRs; isolated CLI builds/reproductions; 36 upstream restoration goldens passed; repair behavior compared before/after. No full cross-platform matrix or conflict-resolved integration build was run. Cloud delegation was attempted but rejected with 403: GitHub connector is disabled or unavailable, so this review ran locally in isolated worktrees.
|
[agent] Detailed v5 implementation handoff, incorporating Mikola's latest direction from the review discussion. Target: make depscan the owner of package construction and remove CLI repacking where the hosted artifact contract supports it. Lockfile changes are part of the intended workflow and should remain supported. Mikola is comfortable keeping the entire repacking engine in depscan and prefers deleting the CLI copy if feasible. Avoid breaking or rewriting depscan's working builder merely to achieve code sharing. This supersedes my earlier suggestion to expose the Rust repacker to both callers. Prefer the smaller migration: preserve depscan's existing implementation, turn the CLI into an artifact consumer, and delete redundant client construction paths. What is actually shared today In the inspected depscan checkout ( There is real duplication. Depscan's Berry writer explicitly identifies itself as a port of the CLI implementation. The npm paths also differ: depscan preserves upstream tar entry order and uses epoch timestamps; the CLI sorts paths and uses npm's fixed 1985 timestamp. Equal patched members therefore do not imply equal archive digests. Preserve already-published bytes and identities during this migration. Suggested implementation sequence
Other deletions that complement this boundary
Coordination and validation The current sibling PRs are active and overlap heavily. Inspect their latest heads and existing reviews first. In particular, #283 advanced to Use the existing release review and linked per-PR reviews as additional context. Revalidate findings against the integrated tree. Preserve all currently supported package-manager versions and the planned agent-mode escape hatch; update Acceptance checks should cover:
Please push a focused draft PR targeting Cloud delegation from this session is unavailable: task creation returned |
|
Landing: #283 (WS5 VendoredBackend) landed on release/v5-prerelease as 06437d2; next up #281 (needs re-merge of the base). #288 fast lane still draft. Generated by Claude Code |
|
Coordinator: #281 (WS3 lock models) landed on release/v5-prerelease as 73c0c4f; next in order is #279, which needs a re-merge of the base. Generated by Claude Code |
|
Coordinator: #279 landed as f6bdad5 (CI reds all base-inherited: yarn-classic Generated by Claude Code |
|
Coordinator: #291 (v5 CI: build e2e binaries once and tier the PM matrix) landed on release/v5-prerelease as f9cb7e1, ahead of #287. Its only red checks (4 vlt install-proof cells, yarn-classic 1.0.2/1.6.0/1.7.0/1.9.4) fail the same way on the base. #287 is still blocked: it is a draft and nobody has pushed the docs-only reduction. Next up: #292. Generated by Claude Code |
|
Coordinator: #296 (remove dead code and v3 shims) landed on release/v5-prerelease as 1e3ace6. Its only red checks were base-inherited: yarn-classic ×4 Generated by Claude Code |
|
Coordinator: #297 (one suite per command, retire #257 oracles) landed on release/v5-prerelease as b97a1c2. Its only red checks were base-inherited: yarn-classic ×4 and vlt install-proof 0.0.0-1/0.0.0-11 ×4. Next up: #293, then #294, each after it merges the new base. #287 is still skipped (draft, not yet reduced to docs-only). Generated by Claude Code |
|
Coordinator: #294 (cap new patches per scan) landed on release/v5-prerelease as 180f10f. Still open: #287 (draft, waiting on its Generated by Claude Code |
|
Claude (@claude) review |
|
BugBot review |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
Bugbot Autofix prepared a fix for the issue found in the latest run.
- ✅ Fixed: Multi-project VEX overwrites one file
- Added a guard to reject --vex with multiple directories, preventing file overwrites by ensuring each scan uses a distinct output path.
Or push these changes by commenting:
@cursor push 18234dbdbd
Preview (18234dbdbd)
diff --git a/crates/socket-patch-cli/src/commands/scan/mod.rs b/crates/socket-patch-cli/src/commands/scan/mod.rs
--- a/crates/socket-patch-cli/src/commands/scan/mod.rs
+++ b/crates/socket-patch-cli/src/commands/scan/mod.rs
@@ -1385,6 +1385,13 @@
);
return 2;
}
+ if args.vex.vex.is_some() && dirs.len() > 1 {
+ eprintln!(
+ "Error: --vex takes one project directory ({} given); run one scan per directory",
+ dirs.len()
+ );
+ return 2;
+ }
// One budget per invocation (§5.2): the directories spend it in sorted
// order, and a package admitted in one is admitted free in the next.
let configured = match args.rollout.resolve_from_env(invocation.policy.max_new_patches()) {You can send follow-ups to the cloud agent here.
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 180f10f. Configure here.
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
bd40e28 to
909c08c
Compare
|
[agent] CI and review summary for this routine run (head Root causes of the red CI and the fixes
Review threads
Still open
Final state on
|
|
[agent] Status on head #300 regressions fixed since
|
Resolve conflicts with #277: keep Poetry-aware venv probe order in find_local_venv_site_packages and add the Poetry entry to the consolidated changelog. Assisted-by: Claude Code:claude-opus-5-5
Brings in the v5 consolidation (#277). Keeps main's rewritten CHANGELOG and re-adds this branch's Fixed entry, and points the virtualStoreDir reader at strip_bom's new home in utils::serde. Assisted-by: Claude Code:claude-opus-5-5


This PR integrates the v5 prerelease workflow:
scanapplies hosted patch references, the package manager installs them, andvexemits OpenVEX evidence.vendormaterializes the selected patched packages for committed/offline use;listinspects the live state.scanandget. Hosted state is read from dependency files, with no new hosted ledger.rollbackandremoveresolve upstream references, and unsupported/offline restoration fails explicitly.socket.yml, package/severity filters, directory targeting, and--max-new-patchescontrol rollout. Automatic selection prefers the highest severity, then the most distinct advisories fixed, then publication date. Selection and upgrade detection use the same order; tier/UUID ties alone do not trigger replacement. Multi-directory scans reject a single--vexdestination before making changes.setup, obsolete hooks/flags, and PyPI/RubyGems CLI distributions. Standalone binaries, Cargo, and npm distributions remain; Python/Ruby project support remains available. See the migration guide.Validation for the ranking change: 39 core ranking tests and 891 CLI/unit/integration tests passed locally, including the repository-policy, in-memory rollout, in-process scan, and disk rollout suites. Workspace Clippy passed with all features and warnings denied. The PR is squashed into one signed commit directly on
main; GitHub CI and CodeQL are running on that commit.CodeQL findings were reviewed against the source, and 61 false positives were dismissed with explanations: public patch identifiers/test diagnostics, a fixture-case count, and the intentional local developer regex option. Scanning remains enabled.
The packaging version is still
4.0.0; the documented release process performs the v5 version bump and publication in a separate release PR/workflow. This integration PR does not publish a release.