Issue & discussion janitor log #576
Mikola Lysenko (mikolalysenko)
started this conversation in
General
Replies: 1 comment
|
[agent] Janitor: bridge test. The janitor/ledger workflow posted this comment on the routine's behalf. Hourly runs log here from now on. Generated by Claude Code |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Janitor: the hourly issue and discussion janitor rewrites this log each run. It shows the last run, the actions it took with a reason for each, a rolling list of recent actions, deferred candidates, and anything that needs a human. The routine writes it to the
janitor/ledgerbranch, and a workflow on that branch applies it here.Last run
2026-10-05 13:35 UTC on origin/main
6811b4e7. 277 open issues and 34 open PRs were reviewed. Since045d7ec7, 46 PRs merged (2026-10-05 11:13–13:20Z), and most of the issues they fix auto-closed.This run
include-group#473 (PR Fix uv hosted unwind declaration matching (#606, #473) #625), Global scan (-g) ignores PDM's site-wide config, so a global project relocated in /etc/xdg/pdm/config.toml is never crawled and get -g reports "applied" while the copy PDM runs stays unpatched #566 (PR Fix PDM settings ignoring PDM's config layers (#609, #566) #611) and Agent-mode vex still attests not_affected when a Deno.deno/<name>@<ver>_1copy is unpatched: the #517 every-copy check never sees store peer-variant copies #603 (PR Fix npm store copies missed by agent apply and vex (#601, #603) #605). In each case the PR said "Fixes #A and #B", but GitHub auto-closed only the first issue. Each fix was verified on origin/main (code plus a regression test named for the issue).agent:claimedfrom 49 closed issues: npm VEX attests not_affected while a bundled (inBundle) copy of the same package@version stays unpatched #325, Hosted gem redirect breaks a multi-linegemdeclaration (the Gemfile stops parsing) and drops a trailingif/unlessmodifier #340, npm agent-mode apply never patches an npm-aliased install (lp@npm:left-pad), yet VEX attests the package not_affected #356, Vendored pnpm 10.5+ withoverrides:in pnpm-workspace.yaml: the new package.jsonpnpm.overridesshadows the user's overrides, so frozen installs fail and a re-lock drops them #360, Hosted and vendored yarn classic modes rewire git-sourced yarn.lock entries, so every later yarn install fails while scan and VEX report success #363, Hosted uv rollback and remove refuse when the patched package reaches a dependency group through PEP 735include-group#473, Hosted pnpm rollback drops the upstreamtarball:URL from locks written withlockfileIncludeTarballUrl, so the restore isn't byte-exact #557, vlt lock inventory and hosted restore resolve a node's registry differently #562, Global scan (-g) ignores PDM's site-wide config, so a global project relocated in /etc/xdg/pdm/config.toml is never crawled and get -g reports "applied" while the copy PDM runs stays unpatched #566, Patch blob and diff downloads buffer the whole response body with no size cap #571, Gem settings resolution skips Bundler's global config (~/.bundle/config/BUNDLE_USER_CONFIG), so a globalcache_pathorgemfilegets no warning or refusal and VEX attests an unpatched install #577, npm vendored vex and vendor --check pass while a second registry copy of the patched package@version in the same package-lock.json stays unwired and installs unpatched #588, NuGet and Cargo crawlers hang on a FIFO at obj/project.assets.json or vendor/<crate>/Cargo.toml #592, Agent-mode apply skips a bundled copy inside another vlt/pnpm store entry whenever the package is also installed normally, and VEX attests not_affected #601, Agent-mode vex still attests not_affected when a Deno.deno/<name>@<ver>_1copy is unpatched: the #517 every-copy check never sees store peer-variant copies #603, Hosted uv rollback, remove and vendored takeover refuse when the patched package is declared with different specifiers independenciesand an extra (or under different markers), although each lock entry keeps its marker #606, Poetry venv discovery expands a{project-dir}placeholder Poetry doesn't have, so agent mode misses the env, patches the global interpreter, and VEX attests not_affected #608, PDM PEP 582 detection missespython.use_venv = falseas PDM 2.27+ writes it (a TOML string) and in the user config, so agent mode patches an activated or stray venv and leaves__pypackages__unpatched #609, Vendored Hatch runs ahatchexecutable planted in the scanned project #613, Agent-mode apply writes through node_modules links into first-party source (npm workspace members, file: deps, npm link targets), overwriting the user's code, and rollback restores upstream bytes instead #626, Vendored pnpm with two or more packages: vendor --revert and rollback leave an emptypnpm.overridesin package.json and (lockfile 9.0) a scaffolded pnpm-workspace.yaml behind #636, Global scan (-g) never crawls the venv that Poetry's official installer creates ($POETRY_HOME/venv), so patches for Poetry's own dependencies are never found, applied or rolled back #640, npm lockfileVersion 1: scan/get --mode vendored un-host a hosted patch and then refuse to vendor it, so the project silently goes back to unpatched (vendor eject rolls back correctly) #659, Agent mode ignores pnpm'smodulesDir: on pnpm 10.12+ every installed package is "not installed", and apply exits 0 leaving it unpatched #661, Vendored pnpm rewrites a CRLF package.json as LF, and vendor --revert does not restore it #662, Vendored yarn classic writes and deletes through a symlinked .socket/vendor/npm dir, so rollback in one project deletes another project's vendored tarballs and breaks its frozen install #664, Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665, Vendored uv with two or more packages: vendor --revert (and remove in purl order) leave an empty[tool.uv.sources]header in pyproject.toml #670, Hatch hosted→vendored takeover with two or more patches leaves allow-direct-references = true (plus empty [tool]/[tool.hatch] tables) behind after rollback or remove, disabling Hatchling's direct-reference guard #674, A failed vendor eject rewrites every file in the project root from its snapshot, sovendor --json > report.json(or> vendor.log 2>&1) in the project loses the output and concurrent writes to root files are reverted #687, Share the poetry.lock and pdm.lock fragment-splice engine instead of keeping two copies #694, Poetry and PDM lock rewrites flip a mixed-line-ending lock's edited unit in opposite directions #695, Hosted pnpm vex attests not_affected over an unpatched install when pnpm'smodulesDiris set (pnpm 10.12+), because the missed install is treated as "nothing installed" #696, Yarn berry vendored and hosted pins putchecksum:out of yarn's field order on platform-conditional lock entries (conditions: os=…), so everyyarn install --immutablefails YN0028 #697, Vendored → hosted takeover strands a requirements.txt pin that lives in a-rinclude or a vendored "(transitive)" line: the wet run reverts it to the unpatched release, while--dry-runpreviews a clean takeover #699, Yarn berry vendored and hosted pins copy the registry entry'sbin:paths, but yarn re-reads them from the tarball (./dist/bin/uuid), so vendored installs and hardened hosted installs fail YN0028 for packages like uuid and acorn #718, Bun lockfile-only checkouts can't see hosted pins: hosted re-runs never pick up a superseding patch andscan --mode vendoredskips the takeover, both reporting success with 0 packages #720, Human-output scan --mode agent / --sync still never re-applies an already-recorded patch after a reinstall (#454 fixed only the --json path) #732, Hosted and vendored modes refuse every valid bun.lockb that holds a release and a prerelease of the same version (X@1.0.0 + X@1.0.0-beta.1) as "metadata hash does not match"; hosted exits 0 with nothing patched (regression since 4.0.0) #739, Vendored pnpm 7/8 writes the absolutefile:specifier unquoted, so a project path containing#or:breaks every frozen install while vendor,vendor --checkand vex report success #754, Vendored requirements.txt never picks up a superseding patch: the re-vendor to a new uuid fails with pypi_requirements_already_vendored (exit 1), though--dry-runpreviewswould_revendorand the contract says it re-vendors automatically #765, Vendored gem refuses a gem whose spec is not in the lock's first GEM section #779, Vendored requirements.txt after the user removes or bumps a vendored pin: the rescan re-adds the removed package as a "(transitive)" line (exit 0), or exits 1 forever after a bump, andscan --prunenever reverts the entry #786, Hosted uv rollback, remove and vendored takeover always refuse locks written by uv 0.6.15–0.6.17, which spell the artifact fieldupload_timeinstead ofupload-time#788, Pipenv stale-install remedy always sayspipenv sync, so for a [dev-packages] or named-category entry following it uninstalls the package instead of reinstalling it patched #790, After Bun 1.4 migrates a hosted workspace bun.lockb to bun.lock,bun install --frozen-lockfilefails and Bun's suggestedbun installsilently drops the hosted pins #803, Vendored uv with a user-authoredoverride-dependencies: after any relock (uv add,uv lock --upgrade-package),vendor --revert/removerevert pyproject.toml but keep the vendored[manifest] overridesentry in uv.lock, souv sync --lockedfails (vendor --revert exits 0) #806, Hosted yarn berry rollback/remove rebuilds the lock entry as a barename@npm:<version>locator and drops the registry's::__archiveUrl=binding, so projects on registries with non-conventional tarball URLs can't install after a revert #817, Vendored uv package in a dependency group: afteruv add --dev/uv remove --dev,vendor --revert,remove,rollbackand the hosted takeover revert pyproject.toml but keep uv.lock's vendored requires-dev entry, souv sync --lockedfails (exit 0, "success") #821, Agent-mode rollback / remove of a PyPI patch that added a file in a new directory leaves the empty directory in site-packages, so Python still imports it as a namespace package #838. Every bughunt issue has itspm:*label.2026-10-02T13:56:32Z-gradle21) is about 72h old, but its PR Full Gradle support in agent, hosted and vendored modes #646 is open and was updated today. Spawn every CLI test child through one hermetic Command builder; 10 test files inherit ambient SOCKET_* today #823 and Give utils::fs one stage-and-rename core instead of six writers and a blocking copy #728 were claimed today and have no PR yet.fail. Ledgers Bug hunt ledger: npm #302, Bug hunt ledger: pnpm #303, Bug hunt ledger: Yarn classic (1.x) #304 and Bug hunt ledger: Yarn Berry (2+) #305 were refreshed on4646693after the merges, so they were skipped. One drift comment on Benchmark progress: socket-patch scan #575 (hatch gap note). No PM has two ledgers.gemdeclaration that shares the patched gem's line after;, so the nextbundle installdrops that dependency #826 (the;-joined gem line has no;check ingem_line_tail_blocks_edit,patch/redirect/mod.rs:5226), Composer vendored → hosted takeover rewrites the vendored lock entry in place, keeping the patch-uuid dist.reference and transport-options: Composer 1 install crashes and rollback refuses #536 (takeover_capableinscan/hosted.rs:1617still excludespkg:composer/), Yarn berry vendored and hosted pins of native-addon packages (nan, bufferutil, utf-8-validate, node-addon-api) keep the registry entry's implicitnode-gyp: "npm:latest"dependency, so vendored installs and hardened hosted installs fail YN0028 #737 (the Berry bug hunt re-confirmed it on4646693after Fix yarn berry pin entry rendering (#697, #718) #719), Read Gemfile.lock sections and DEPENDENCIES entries through formats::gem in hosted and vendored modes #780 (the refactor is still pending after Fix vendored gem lookup beyond the first GEM section (#779) #805), and uv vendored → hosted takeover strands a package that vendored mode pinned to a different version than uv.lock: the wet run reverts to the unpatched release (exit 1), while --dry-run previews a clean takeover #723 (uv-specific; Fix PyPI vendored→hosted takeover stranding unreachable pins (#699) #708 gated only requirements.txt). After Bun migrates a vendored bun.lockb to bun.lock (bun install --save-text-lockfile), vendor --revert and rollback fail, and a superseding re-vendor drops the pre-vendor original so revert exits 0 with the project still vendored #784–Agent mode misses transitive packages in Yarn's pnpm-linker store whenpnpmStoreFoldermoves it out ofnode_modules: skipped aspackage_not_installed, or refused as "first-party source" #859 are not duplicates of each other or of closed issues. Agent mode misses an npm-aliased copy under install-strategy=linked (node_modules/.store/lp@…), so apply exits 0 with it unpatched and VEX attests not_affected #852 is a newinstall-strategy=linkedalias case that Fix agent mode skipping npm-aliased copies (#356) #738 doesn't cover, and pnpm hosted → vendored takeover un-hosts the package before pnpm's vendored refusals run, so a catalog entry, a CRLF lock or a workspace exact-pin override leaves it unpatched in both modes #853 and Vendored pnpm refuses a user exact-pin override (left-pad: 1.3.0) in pnpm-workspace.yaml with a misleading "does not match package.json" error, though the same pin in package.json is taken over #854 have different triggers.Recent actions (rolling, newest first)
include-group#473 as completed (PR Fix uv hosted unwind declaration matching (#606, #473) #6259df2afa5said "Fixes Hosted uv rollback, remove and vendored takeover refuse when the patched package is declared with different specifiers independenciesand an extra (or under different markers), although each lock entry keeps its marker #606 and Hosted uv rollback and remove refuse when the patched package reaches a dependency group through PEP 735include-group#473", but only Hosted uv rollback, remove and vendored takeover refuse when the patched package is declared with different specifiers independenciesand an extra (or under different markers), although each lock entry keeps its marker #606 auto-closed;include_group_membertest on main)2465131e; site config layer read inpdm_global_site_packages_with).deno/<name>@<ver>_1copy is unpatched: the #517 every-copy check never sees store peer-variant copies #603 as completed (PR Fix npm store copies missed by agent apply and vex (#601, #603) #60546466931;verify_mode_requires_every_store_copy_patchedcovers the Deno_1case)agent:claimedfrom 49 closed issues (46 closed by the 11:13–13:20Z merge wave, plus Hosted uv rollback and remove refuse when the patched package reaches a dependency group through PEP 735include-group#473, Global scan (-g) ignores PDM's site-wide config, so a global project relocated in /etc/xdg/pdm/config.toml is never crawled and get -g reports "applied" while the copy PDM runs stays unpatched #566 and Agent-mode vex still attests not_affected when a Deno.deno/<name>@<ver>_1copy is unpatched: the #517 every-copy check never sees store peer-variant copies #603 above)fail)scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 for Windows)scan -gofficial-installer row isfailbut points only at closed Global scan (-g) never crawls pipx venvs, so the dependencies of a pipx-installed Hatch are never reported, patched or rolled back on any OS #415; no open issue tracks it)fail)agent:claimedfrom closed The patch API client has no request timeout, so scan, get and apply hang forever on a stalled server #570 (closed as completed by PR Bound patch API connects and stalled reads (#570) #581)agent:claimed(no PR for the remaining half, claimer silent for more than 48h)agent:claimedfrom closed Poetry hosted ⇄ vendored mode switch is refused, and blames a "user-authored" source that socket-patch wrote itself #328 (closed as completed, so the claim is finished)agent:claimedfrom closed Pipenv recognizes hosted PyPI patch URLs with two private grammars that disagree with the shared one #563 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted gem redirect appends a second declaration when the gem is declared througheval_gemfileor a loop, so everybundle installfails with "You cannot specify the same gem twice" #482 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted gem redirect rewrites only the first of a gem's declarations, so a gem listed in twogroupblocks makes everybundle installfail with "You cannot specify the same gem twice" #548 (closed as completed, so the claim is finished)fail)fail)fail)fail)fail)fail)agent:claimedfrom closed Bun isolated linker: transitive packages under node_modules/.bun are "not installed" in agent mode, and scan --mode agent exits 0 with them unpatched #366 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted → vendored takeover on yarn berry reverts the hosted redirect before a per-package vendor refusal, leaving the package unpatched in both modes #369 (closed as completed, so the claim is finished)agent:claimedfrom closed Deno nodeModulesDir: transitive npm packages under node_modules/.deno are "not installed", and apply/scan exit 0 leaving them unpatched #373 (closed as completed, so the claim is finished)agent:claimedfrom closed npm apply exits 1 when every patch targets a platform-skipped optional dependency (fsevents, @esbuild/*), so the setup hook fails npm ci and npm install on other OSes #403 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted yarn berry redirect makes yarn send the project's npm registry auth token to the patch host #404 (closed as completed, so the claim is finished)agent:claimedfrom closed With Bun's isolated linker,vexattests a hosted patch as not_affected (verified) while the installed copy under node_modules/.bun is still unpatched (v5 regression) #405 (closed as completed, so the claim is finished)agent:claimedfrom closed Vendored → hosted takeover on yarn berry deletes the vendored patch, then skips the hosted rewrite when the grant has no yarnBerry10c0 checksum, and still exits 0 "fully hosted" #468 (closed as completed, so the claim is finished)agent:claimedfrom closed Yarn 4 pnpm linker: transitive packages that live only in node_modules/.store are "not installed" in agent mode and stay unpatched #495 (closed as completed, so the claim is finished)agent:claimedfrom closed Agent-mode npmvexhashes only the first installed copy of a package, so it attests not_affected while another nested copy of the same name@version is unpatched #516 (closed as completed, so the claim is finished)fail)fail)fail)fail)agent:claimedfrom closed On Windows (RubyInstaller),scan -g/get -g/vex -gfind no global gems becausegem envis spawned as baregem, which never resolves togem.cmd#421 (closed as completed, so the claim is finished)agent:claimedfrom closed On Windows,scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 (closed as completed, so the claim is finished)agent:claimedfrom closed On Windows, scan -g finds no Composer global packages in the default %APPDATA%\Composer home, so apply -g and vex -g silently do nothing #438 (closed as completed, so the claim is finished)agent:claimedfrom closedscan -ginside a Yarn Berry project runs the project'sglobalpackage.json script and scans whatever directory it prints as a global install #440 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted requirements.txt rewrite skips PEP 440-equivalent pins likesix==1.16for an installed 1.16.0, soscanexits 0 and pip installs the unpatched release (regression from v4.0.0) #475 (closed as completed, so the claim is finished)fail)fail)fail)fail)fail)fail)fail)fail)Deferred / unsure
cd <subproject> && gradlebreaks #428, Vendored Gradle: on a Windows (core.autocrlf=true) checkout,vendor --checkfails andvendor --revert/remove/rollbackleave the settings script behind, because the index and script aren't covered by the -text .gitattributes #429, Vendored Gradle: gradle_exclusive_content_conflict refusal doesn't fire for a subproject build script or a buildSrc convention plugin, so vendor exits 0, the build then fails with "Could not find", and VEX attests not_affected #461, Vendored Gradle with PGP signature verification exits 0 but breaks the build, because pgp-only verification-metadata entries for the vendored pom and its parent chain are kept without a checksum #487, Vendored Gradle silently downgrades a version-range dependency to an older unpatched release (1.10.0 → 1.9), because the vendored repository has no maven-metadata.xml; vendor --check and VEX still report it patched #511, Vendored Gradle exits 0 with no warning on a classifier dependency of the patched module, then the build fails with "Could not find …-tests.jar" and IDE sources silently disappear #533, Agent-mode apply in a Gradle-only project patches the ~/.m2 copy Gradle never reads, reports success, and VEX attests not_affected while the build uses the unpatched ~/.gradle jar #551) → Full Gradle support in agent, hosted and vendored modes #646; Vendored gem rewrite puts non-string arguments afterpath:, sogem "x", *V,gem "x", ENV.fetch(…)orgem "x", VERSIONbecomes a Gemfile syntax error and everybundlecommand fails #847 → Fix vendored gem rewrite breaking positional args (#847) #849; Vendored uv revert writes the pre-vendor specifier back into uv.lock after the user changes the vendored package's version spec, souv sync --lockedfails (vendor --revert / remove / rollback exit 0) #840 → Fix uv revert restoring a stale specifier (#840) #841; Vendored yarn classic exits 0 when .gitignore covers the vendored tarball (*.tgz,vendor/,.socket/), so the commit drops it and every fresh checkout's install fails #831 → Fix vendored npm-family tarballs dropped by .gitignore (#831) #837; Hosted rollback and remove always refuse apip lockpylock.toml ("no sibling registry package shows the registry and artifact fields"), because pip writes[[packages.wheels]]tables, not uv's inlinewheels = [...]#804 → Fix rollback of pip-written pylock.toml (#804) #807; npm VEX attests a patch that only npm-shrinkwrap.json wires when the package-lock.json beside it has no entry for the package, though npm 12 reads package-lock.json and installs the registry copy #798 → Fix npm VEX attesting a patch the twin lock lacks (#798) #799; Gem crawler misses a Bundler 4bundle install --standalonetree (./bundle), so agentapplypatches the system copy and VEX attestsnot_affectedwhile the app loads the unpatched standalone copy #796 → Fix gem crawler missing Bundler 4 standalone bundle (#796) #797; Gem hosted → vendored takeover un-hosts a gem declared inside agroupblock and then refuses to vendor it (gemfile_declaration_not_editable), so the project silently goes back to unpatched #775 → Fix gem takeover un-hosting a grouped gem (#775) #776; Agent-mode apply reportsalready_patched/applied: 0when it actually patched an unpatched pnpm peer-variant copy (the store-copy pass's writes are never reported) #756 and Share one pnpm/vlt store-copy fan-out between agent apply and rollback, folding each copy's per-file records #772 → Fix store-copy fold dropping copy writes (#756, #772) #774; Vendored Pipenv never picks up a superseding patch: re-vendor to a new uuid fails with pypi_pipenv_source_already_exists (lock-only) or a false package_not_installed (venv present), exit 1 #769 → Fix vendored Pipenv re-vendor to a newer patch (#769) #825; Lock inventory reads only Gemfile.lock, so a gems.rb project's gems.locked is invisible and a stale Gemfile.lock is read instead #736 → Fix gem lock readers ignoring gems.locked (#736) #750; Hosted gem redirect ignores Bundler 4's custom lockfile (lockfilesetting /BUNDLE_LOCKFILE), so it never pins the lock Bundler uses and frozen installs fail with no warning #749 and Hosted gem redirect wiresgems.rbin a Gemfile/gems.rb twin locked by Bundler 1.17, which loadsGemfile, so the install stays unpatched while the in-run VEX attests it #751 → Fix gem pair model ignoring custom lockfile and Bundler 1 twins (#749, #751) #768;vendor --checksays "committed artifact and wiring verified" (exit 0) afterpipenv lockdrops the vendored reference, so a freshpipenv install --deployinstalls the unpatched wheel while vex says vendor_unwired #725 → Fix vendor --check passing unwired vendored entries (#725) #730; Hosted and lock-only scans treat a UTF-16 requirements.txt (what Windows PowerShell'spip freeze >writes) as absent: exit 0, no warning, and pip keeps installing the unpatched pin #721 → Fix UTF-16 requirements.txt silently skipped (#721) #724; Hosted gem VEX attestsnot_affectedfor an unpatched install when.bundle/configsets an out-of-treepath(absolute or~/…), because the skipped bundle root counts as "nothing installed" #709 → Fix gem VEX ignoring out-of-tree bundle path (#709) #712; Hosted gem redirect ignores Bundler'smirror.allsetting, so the nextbundle installfetches the redirected gem's upstream bytes from the mirror while the in-run VEX attestsnot_affected#681 → Fix hosted gem redirect ignoring Bundler mirror.all (#681) #684; Hosted gem redirect treats agitlab:or customgit_sourcegem as patched, so Bundler keeps loading the unpatched git checkout while VEX attestsnot_affected#652 → Fix gem source-option guard missing git sources (#652) #731; Agent mode skips ./.venv when PIPENV_VENV_IN_PROJECT=0 or PIPENV_NO_VENV_IN_PROJECT=1 is set, but Pipenv 2018 through 2023.10.24 still use that .venv, so it stays unpatched and VEX attests not_affected (regression from #388) #645 and Pipenv venv discovery ignores the project's .env, so a PIPENV_CUSTOM_VENV_NAME or WORKON_HOME set there leaves the Pipenv venv unpatched, patches the system Python instead, and VEX attests not_affected #546 → Fix Pipenv venv discovery settings view (#645, #546) #654; Hosted yarn berry pin of acatalog:dependency keysresolutionsby the resolvednpm:range, so everyyarn install --immutablefails YN0028 (regression from #465) #632 → Fix yarn berry hosted pin of catalog deps (#632) #763; Hosted yarn berry rewrites a mixed-line-ending package.json that vendored mode refuses #628 and Share the yarn berry project gates between hosted and vendored modes #629 → Fix yarn berry project gates drifting between modes (#628, #629) #657; Vendored yarn classic replaces a symlinked yarn.lock with a regular file (hosted refuses the same lock), leaving the link's target unpatched; rollback never restores the link #627 → Fix vendored mode replacing symlinked lockfiles (#627) #802; Hosted scan/get run from a pnpm workspace member (or withlockfile-dir=..) ignores the parent pnpm-lock.yaml and reports success while pinning nothing #590 and Hosted cargo scan run from a workspace member treats it as a lockless project, rewrites only the member, and breaks every build of the workspace while reporting success #417 → Fix hosted scan from a workspace member pinning nothing or the wrong files (#590, #417) #598; A report-onlyscan -gtells you to runsocket-patch scan --mode agent [PATHS]without-g, so following the hint scans the cwd project instead of the global install #464 → Fix report-only scan -g hint dropping -g (#464) #777; npm v2 lock: aliased packages stay on the registry in the legacy dependencies mirror (hosted silently, vendored with a warning), so npm 6 installs unpatched bytes while VEX attests not_affected #432 → Fix npm 6 installing unpatched aliases (#432) #813; Hostedrollback,removeand the vendored takeover refuse a requirements.txt whose only requirements are hosted pins (six==1.16.0alone can be patched but never unpatched) #410 → Fix pip rollback refusing all-hosted requirements (#410) #827; Hosted and vendored modes refuse vlt 1.3 locks whose nodes carry the new brotli flag (slot [0] = 4) #372 → Fix vlt 1.3 brotli lock nodes being refused (#372) #820; Hosted yarn classic redirect breaks every install in projects with a yarn-offline-mirror: the mirror's upstream tarball shares the hosted URL's basename and fails the new integrity pin #364 → Fix hosted yarn classic with an offline mirror (#364) #839; Agent mode ignores pnpm's virtualStoreDir: transitive dependencies are reported package_not_installed with a custom virtualStoreDir or the global virtual store #362 → Fix pnpm global-store transitive deps passing silently (#362) #829; Hosted Hatch rewrite leaves an existing Hatch environment unpatched with no stale-install warning, and vex still attests not_affected #335 → Fix Hatch environments being invisible to stale-install checks and VEX (#335) #700. Claimed today with no PR yet: Spawn every CLI test child through one hermetic Command builder; 10 test files inherit ambient SOCKET_* today #823 and Give utils::fs one stage-and-rename core instead of six writers and a blocking copy #728..deno/<name>@<ver>_1copy is unpatched: the #517 every-copy check never sees store peer-variant copies #603: the cosmeticrollbackcount for a restored Deno_1copy was never filed as its own issue.Needs a human
agent:needs-humanissues waiting on a decision: Benchmark tracking: socket-patch scan #580, Decide: give SOCKET_FORCE per-command names so forcing a self-update doesn't also force apply and vendor #615, Decide: where patch API calls go when a token is set but the org slug can't be resolved #648, Decide: one shape for the--jsontop-levelerror(scan and get emit both a string and a {code, message} object) #704, Decide: make --download-mode file the default and retire the diff download path #792, Decide: keep .socket/apply.lock transient, or give the lock a file that never has to be deleted #808.janitor/ledgerbranch requires signed commits. Pushes made under the default session identity work.Generated by Claude Code
All reactions