Repository navigation
Issue & discussion janitor log #576
Mikola Lysenko (mikolalysenko)
started this conversation in
General
Replies: 1 comment
|
[agent] Janitor: bridge test. The janitor/ledger workflow posted this comment on the routine's behalf. Hourly runs log here from now on. Generated by Claude Code |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Janitor: the hourly issue and discussion janitor rewrites this log each run. It shows the last run, the actions it took with a reason for each, a rolling list of recent actions, deferred candidates, and anything that needs a human. The routine writes it to the
janitor/ledgerbranch, and a workflow on that branch applies it here.Last run
2026-10-06 13:26Z on origin/main
9c43dfc9. 292 open issues and the PRs merged since the last run were reviewed. Since6811b4e7, 24 PRs merged (2026-10-05 13:39–18:18Z), and most of the issues they fix auto-closed. No PRs merged on 2026-10-06.This run
applycan't apply Maven patch records keyed by jar member paths, althoughvendoraccepts the same record #264 (PR Full Gradle support in agent, hosted and vendored modes #646). The first two were "Fixes #A and #B" cases where only #A auto-closed. Agent-modeapplycan't apply Maven patch records keyed by jar member paths, althoughvendoraccepts the same record #264 was fixed by the Gradle PR's agent-mode jar swap, which covers everypkg:mavenrecord. Each was verified on origin/main (code plus a regression test).Claim-ID: 2026-10-04T03:20:54Z-020a8f). Fix uv/Hatch hosted re-pin to a newer patch (#742, #650) #743 merged with only the hosted slice and Fix vendored requirements.txt re-vendor to a superseding patch (#765) #766 with only the requirements.txt slice. There is no PR for the vendored half and no claimer activity for more than 48h. Both issues stay open.agent:claimedfrom Hosted cargo scan run from a workspace member treats it as a lockless project, rewrites only the member, and breaks every build of the workspace while reporting success #417 and from 33 closed issues: Hosted Gradle exclusiveContent snippet is not fail-closed: a transitive request for the base version wins conflict resolution and the unpatched jar is used #347, Hosted Gradle snippet is always Groovy DSL, so pasting it into a build.gradle.kts fails to compile #348, scan reports success with 0 packages on a resolved Gradle project because the Gradle cache (~/.gradle/caches/modules-2) is never crawled #349, Agent mode ignores pnpm's virtualStoreDir: transitive dependencies are reported package_not_installed with a custom virtualStoreDir or the global virtual store #362, Hosted and vendored modes refuse vlt 1.3 locks whose nodes carry the new brotli flag (slot [0] = 4) #372, Vendored Maven on a project with both pom.xml and build.gradle reports success with no Gradle warning, the Gradle build keeps the unpatched jar, and VEX attests not_affected #395, Hosted Gradle snippet silently builds the unpatched jar in any project using dependency locking (gradle.lockfile), on every Gradle major and OS #396, Vendored Gradle: running vendor from a subproject of a multi-project build exits 0 but wires a nested settings.gradle, so the real build stays unpatched andcd <subproject> && gradlebreaks #428, Vendored Gradle: on a Windows (core.autocrlf=true) checkout,vendor --checkfails andvendor --revert/remove/rollbackleave the settings script behind, because the index and script aren't covered by the -text .gitattributes #429, npm v2 lock: aliased packages stay on the registry in the legacy dependencies mirror (hosted silently, vendored with a warning), so npm 6 installs unpatched bytes while VEX attests not_affected #432, Vendored Gradle: gradle_exclusive_content_conflict refusal doesn't fire for a subproject build script or a buildSrc convention plugin, so vendor exits 0, the build then fails with "Could not find", and VEX attests not_affected #461, Vendored Gradle with PGP signature verification exits 0 but breaks the build, because pgp-only verification-metadata entries for the vendored pom and its parent chain are kept without a checksum #487, Vendored Gradle silently downgrades a version-range dependency to an older unpatched release (1.10.0 → 1.9), because the vendored repository has no maven-metadata.xml; vendor --check and VEX still report it patched #511, Vendored Gradle exits 0 with no warning on a classifier dependency of the patched module, then the build fails with "Could not find …-tests.jar" and IDE sources silently disappear #533, Pipenv venv discovery ignores the project's .env, so a PIPENV_CUSTOM_VENV_NAME or WORKON_HOME set there leaves the Pipenv venv unpatched, patches the system Python instead, and VEX attests not_affected #546, Agent-mode apply in a Gradle-only project patches the ~/.m2 copy Gradle never reads, reports success, and VEX attests not_affected while the build uses the unpatched ~/.gradle jar #551, Hosted scan/get run from a pnpm workspace member (or withlockfile-dir=..) ignores the parent pnpm-lock.yaml and reports success while pinning nothing #590, Vendored yarn classic replaces a symlinked yarn.lock with a regular file (hosted refuses the same lock), leaving the link's target unpatched; rollback never restores the link #627, Hosted yarn berry pin of acatalog:dependency keysresolutionsby the resolvednpm:range, so everyyarn install --immutablefails YN0028 (regression from #465) #632, Agent mode skips ./.venv when PIPENV_VENV_IN_PROJECT=0 or PIPENV_NO_VENV_IN_PROJECT=1 is set, but Pipenv 2018 through 2023.10.24 still use that .venv, so it stays unpatched and VEX attests not_affected (regression from #388) #645, Hosted gem redirect treats agitlab:or customgit_sourcegem as patched, so Bundler keeps loading the unpatched git checkout while VEX attestsnot_affected#652, Hosted gem VEX attestsnot_affectedfor an unpatched install when.bundle/configsets an out-of-treepath(absolute or~/…), because the skipped bundle root counts as "nothing installed" #709,vendor --checksays "committed artifact and wiring verified" (exit 0) afterpipenv lockdrops the vendored reference, so a freshpipenv install --deployinstalls the unpatched wheel while vex says vendor_unwired #725, Give utils::fs one stage-and-rename core instead of six writers and a blocking copy #728, Lock inventory reads only Gemfile.lock, so a gems.rb project's gems.locked is invisible and a stale Gemfile.lock is read instead #736, Agent-mode apply reportsalready_patched/applied: 0when it actually patched an unpatched pnpm peer-variant copy (the store-copy pass's writes are never reported) #756, Share one pnpm/vlt store-copy fan-out between agent apply and rollback, folding each copy's per-file records #772, Read the go.mod module directive through go_mod_edit and delete the crawler's unused parse_go_mod_module #781, Gem crawler misses a Bundler 4bundle install --standalonetree (./bundle), so agentapplypatches the system copy and VEX attestsnot_affectedwhile the app loads the unpatched standalone copy #796, npm VEX attests a patch that only npm-shrinkwrap.json wires when the package-lock.json beside it has no entry for the package, though npm 12 reads package-lock.json and installs the registry copy #798, Hosted rollback and remove always refuse apip lockpylock.toml ("no sibling registry package shows the registry and artifact fields"), because pip writes[[packages.wheels]]tables, not uv's inlinewheels = [...]#804, Vendored uv revert writes the pre-vendor specifier back into uv.lock after the user changes the vendored package's version spec, souv sync --lockedfails (vendor --revert / remove / rollback exit 0) #840 and Vendored gem rewrite puts non-string arguments afterpath:, sogem "x", *V,gem "x", ENV.fetch(…)orgem "x", VERSIONbecomes a Gemfile syntax error and everybundlecommand fails #847. Every bughunt issue has itspm:*label.cd <subproject> && gradlebreaks #428, Vendored Gradle: on a Windows (core.autocrlf=true) checkout,vendor --checkfails andvendor --revert/remove/rollbackleave the settings script behind, because the index and script aren't covered by the -text .gitattributes #429, Vendored Gradle: gradle_exclusive_content_conflict refusal doesn't fire for a subproject build script or a buildSrc convention plugin, so vendor exits 0, the build then fails with "Could not find", and VEX attests not_affected #461, Vendored Gradle with PGP signature verification exits 0 but breaks the build, because pgp-only verification-metadata entries for the vendored pom and its parent chain are kept without a checksum #487, Vendored Gradle silently downgrades a version-range dependency to an older unpatched release (1.10.0 → 1.9), because the vendored repository has no maven-metadata.xml; vendor --check and VEX still report it patched #511, Vendored Gradle exits 0 with no warning on a classifier dependency of the patched module, then the build fails with "Could not find …-tests.jar" and IDE sources silently disappear #533 and Agent-mode apply in a Gradle-only project patches the ~/.m2 copy Gradle never reads, reports success, and VEX attests not_affected while the build uses the unpatched ~/.gradle jar #551 asfail, and all of them were closed by Full Gradle support in agent, hosted and vendored modes #646. Single-issue drift comments went to Bug hunt ledger: vlt #307 (Hosted and vendored modes refuse vlt 1.3 locks whose nodes carry the new brotli flag (slot [0] = 4) #372, fixed by Fix vlt 1.3 brotli lock nodes being refused (#372) #820), Bug hunt ledger: Bundler (RubyGems) #316 (Hosted gem VEX attestsnot_affectedfor an unpatched install when.bundle/configsets an out-of-treepath(absolute or~/…), because the skipped bundle root counts as "nothing installed" #709, fixed by Fix gem VEX ignoring out-of-tree bundle path (#709) #712), Bug hunt ledger: NuGet / dotnet #320 (Vendored yarn classic replaces a symlinked yarn.lock with a regular file (hosted refuses the same lock), leaving the link's target unpatched; rollback never restores the link #627, fixed by Fix vendored mode replacing symlinked lockfiles (#627) #802) and Bug hunt ledger: npm #302 (npm v2 lock: aliased packages stay on the registry in the legacy dependencies mirror (hosted silently, vendored with a warning), so npm 6 installs unpatched bytes while VEX attests not_affected #432, fixed by Fix npm 6 installing unpatched aliases (#432) #813). Bug hunt ledger: pnpm #303, Bug hunt ledger: Yarn classic (1.x) #304, Bug hunt ledger: Yarn Berry (2+) #305, Bug hunt ledger: uv #310 and Bug hunt ledger: Pipenv #313 already note their fixes in the prose, so they were skipped. Benchmark progress: socket-patch scan #575 has no drift.file:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939 aren't exact duplicates. The BOM cluster Hosted pnpm scan skips thetrustLockfile: trueauto-config when pnpm-lock.yaml starts with a UTF-8 BOM, so pnpm 11/12 frozen installs fail with ERR_PNPM_TARBALL_URL_MISMATCH after a successful scan #903, pnpm-workspace.yaml with a UTF-8 BOM: hosted and vendored miss the first top-level key and append a duplicatetrustLockfile/overrides, so every pnpm install fails with "duplicate mapping key" after a successful scan #904 and pnpm lock and workspace readers don't skip a leading BOM, because BOM handling has no shared helper (4 named copies, ~50 inline strips) #905 is deliberately grouped (one symptom per lane plus the arch-audit root). Yarn classic VEX attests not_affected while afile:directory copy of the patched package@version installs unpatched, and hosted scan gives no warning for that copy #921, pnpm VEX attests not_affected while afile:directory orfile:tarball copy of the patched package@version in the same pnpm-lock.yaml installs unpatched, and hosted/vendored scans give no warning for that copy #935, Yarn classic VEX attests not_affected when yarn.lock also has a registry block for the patched name@version (e.g. afteryarn add -W <pkg> --exact), though yarn installs only the unpatched registry copy #938 and Yarn berry hosted and vendored scans miss afile:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939 arefile:/registry copies in different PMs or with different triggers. Hosted scan from a pnpm 11/12 workspace member with its own lock writes trustLockfile into a nested member pnpm-workspace.yaml that pnpm ignores, so the root install fails with ERR_PNPM_TARBALL_URL_MISMATCH #880 and Vendored scan from a pnpm 11/12 workspace member with its own lock writes the override into a nested member pnpm-workspace.yaml that pnpm ignores, so the root frozen install fails and a plainpnpm installsilently reinstalls the unpatched package #881 are hosted vs vendored. socket.ymlignorePackages/packagesandscan --packagedon't PEP 503-normalise PyPI names, soignorePackages: ["typing_extensions"]is silently ignored and the package is patched anyway #910 andget <name>doesn't PEP 503-normalise PyPI names, soget typing_extensionsorget ruamel.yamlreports "No packages matching" (exit 0) for an installed, patchable package #926 are different commands.Recent actions (rolling, newest first)
abb5787asaid "Fixes Hosted scan/get run from a pnpm workspace member (or withlockfile-dir=..) ignores the parent pnpm-lock.yaml and reports success while pinning nothing #590 and Hosted cargo scan run from a workspace member treats it as a lockless project, rewrites only the member, and breaks every build of the workspace while reporting success #417", but only Hosted scan/get run from a pnpm workspace member (or withlockfile-dir=..) ignores the parent pnpm-lock.yaml and reports success while pinning nothing #590 auto-closed;cargo_hosted_scan_from_workspace_member_refuseson main)0c1e07b8said "Fixes Hosted NuGet mapping reads commented-out package sources #561 and Hosted NuGet splices the Socket source (and mapping) into a commented-out <packageSources> / <packageSourceMapping> block, so every restore fails NU1100 while scan reports success and its in-run VEX attests not_affected #585", but only Hosted NuGet mapping reads commented-out package sources #561 auto-closed; hosted NuGet anchors come fromformats::nuget::parse_config)applycan't apply Maven patch records keyed by jar member paths, althoughvendoraccepts the same record #264 as completed (PR Full Gradle support in agent, hosted and vendored modes #6460685ba8caddedpatch/jvm_jar.rs, a member-keyed Maven record jar swap inapply_maven_base; tests ingradle_agent_cli.rs)2026-10-04T03:20:54Z-020a8fon uv projects never pick up a superseding patch: hosted re-scan lists the upgrade in updates[] but refuses its own earlier [tool.uv.sources] pin (exit 0, still on the old uuid), and vendored re-scan fails pypi_uv_source_already_exists #742 and Hatch never picks up a superseding patch: re-scan refuses its own earlier wiring ("existing direct source must be reverted"), so hosted exits 0 still pinned to the old patch uuid #650 (only the hosted slice merged in Fix uv/Hatch hosted re-pin to a newer patch (#742, #650) #743, no vendored PR, claimer silent for more than 48h)agent:claimedfrom 34 closed issues (Hosted cargo scan run from a workspace member treats it as a lockless project, rewrites only the member, and breaks every build of the workspace while reporting success #417, plus 33 closed by the 2026-10-05 13:39–18:16Z merge wave)fail), Bug hunt ledger: vlt #307 (Hosted and vendored modes refuse vlt 1.3 locks whose nodes carry the new brotli flag (slot [0] = 4) #372), Bug hunt ledger: Bundler (RubyGems) #316 (Hosted gem VEX attestsnot_affectedfor an unpatched install when.bundle/configsets an out-of-treepath(absolute or~/…), because the skipped bundle root counts as "nothing installed" #709), Bug hunt ledger: NuGet / dotnet #320 (Vendored yarn classic replaces a symlinked yarn.lock with a regular file (hosted refuses the same lock), leaving the link's target unpatched; rollback never restores the link #627) and Bug hunt ledger: npm #302 (npm v2 lock: aliased packages stay on the registry in the legacy dependencies mirror (hosted silently, vendored with a warning), so npm 6 installs unpatched bytes while VEX attests not_affected #432)include-group#473 as completed (PR Fix uv hosted unwind declaration matching (#606, #473) #6259df2afa5said "Fixes Hosted uv rollback, remove and vendored takeover refuse when the patched package is declared with different specifiers independenciesand an extra (or under different markers), although each lock entry keeps its marker #606 and Hosted uv rollback and remove refuse when the patched package reaches a dependency group through PEP 735include-group#473", but only Hosted uv rollback, remove and vendored takeover refuse when the patched package is declared with different specifiers independenciesand an extra (or under different markers), although each lock entry keeps its marker #606 auto-closed;include_group_membertest on main)2465131e; site config layer read inpdm_global_site_packages_with).deno/<name>@<ver>_1copy is unpatched: the #517 every-copy check never sees store peer-variant copies #603 as completed (PR Fix npm store copies missed by agent apply and vex (#601, #603) #60546466931;verify_mode_requires_every_store_copy_patchedcovers the Deno_1case)agent:claimedfrom 49 closed issues (46 closed by the 11:13–13:20Z merge wave, plus Hosted uv rollback and remove refuse when the patched package reaches a dependency group through PEP 735include-group#473, Global scan (-g) ignores PDM's site-wide config, so a global project relocated in /etc/xdg/pdm/config.toml is never crawled and get -g reports "applied" while the copy PDM runs stays unpatched #566 and Agent-mode vex still attests not_affected when a Deno.deno/<name>@<ver>_1copy is unpatched: the #517 every-copy check never sees store peer-variant copies #603 above)fail)scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 for Windows)scan -gofficial-installer row isfailbut points only at closed Global scan (-g) never crawls pipx venvs, so the dependencies of a pipx-installed Hatch are never reported, patched or rolled back on any OS #415; no open issue tracks it)fail)agent:claimedfrom closed The patch API client has no request timeout, so scan, get and apply hang forever on a stalled server #570 (closed as completed by PR Bound patch API connects and stalled reads (#570) #581)agent:claimed(no PR for the remaining half, claimer silent for more than 48h)agent:claimedfrom closed Poetry hosted ⇄ vendored mode switch is refused, and blames a "user-authored" source that socket-patch wrote itself #328 (closed as completed, so the claim is finished)agent:claimedfrom closed Pipenv recognizes hosted PyPI patch URLs with two private grammars that disagree with the shared one #563 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted gem redirect appends a second declaration when the gem is declared througheval_gemfileor a loop, so everybundle installfails with "You cannot specify the same gem twice" #482 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted gem redirect rewrites only the first of a gem's declarations, so a gem listed in twogroupblocks makes everybundle installfail with "You cannot specify the same gem twice" #548 (closed as completed, so the claim is finished)fail)fail)fail)fail)fail)fail)agent:claimedfrom closed Bun isolated linker: transitive packages under node_modules/.bun are "not installed" in agent mode, and scan --mode agent exits 0 with them unpatched #366 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted → vendored takeover on yarn berry reverts the hosted redirect before a per-package vendor refusal, leaving the package unpatched in both modes #369 (closed as completed, so the claim is finished)agent:claimedfrom closed Deno nodeModulesDir: transitive npm packages under node_modules/.deno are "not installed", and apply/scan exit 0 leaving them unpatched #373 (closed as completed, so the claim is finished)agent:claimedfrom closed npm apply exits 1 when every patch targets a platform-skipped optional dependency (fsevents, @esbuild/*), so the setup hook fails npm ci and npm install on other OSes #403 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted yarn berry redirect makes yarn send the project's npm registry auth token to the patch host #404 (closed as completed, so the claim is finished)agent:claimedfrom closed With Bun's isolated linker,vexattests a hosted patch as not_affected (verified) while the installed copy under node_modules/.bun is still unpatched (v5 regression) #405 (closed as completed, so the claim is finished)agent:claimedfrom closed Vendored → hosted takeover on yarn berry deletes the vendored patch, then skips the hosted rewrite when the grant has no yarnBerry10c0 checksum, and still exits 0 "fully hosted" #468 (closed as completed, so the claim is finished)agent:claimedfrom closed Yarn 4 pnpm linker: transitive packages that live only in node_modules/.store are "not installed" in agent mode and stay unpatched #495 (closed as completed, so the claim is finished)agent:claimedfrom closed Agent-mode npmvexhashes only the first installed copy of a package, so it attests not_affected while another nested copy of the same name@version is unpatched #516 (closed as completed, so the claim is finished)fail)fail)fail)fail)agent:claimedfrom closed On Windows (RubyInstaller),scan -g/get -g/vex -gfind no global gems becausegem envis spawned as baregem, which never resolves togem.cmd#421 (closed as completed, so the claim is finished)Deferred / unsure
uv pip compile --universalrefuses a marker-split package (six==1.16.0 ; python < 3.12+six==1.17.0 ; python >= 3.12) as "not pinned to ==1.16.0", while --dry-run previews would_vendor and hosted / vendored pylock handle the same split #928 → Fix vendored requirements refusing marker-split pins (#928) #929;get <name>doesn't PEP 503-normalise PyPI names, soget typing_extensionsorget ruamel.yamlreports "No packages matching" (exit 0) for an installed, patchable package #926 → Fixget <name>missing PyPI names spelled with_or.(#926) #927; Yarn classic VEX attests not_affected while afile:directory copy of the patched package@version installs unpatched, and hosted scan gives no warning for that copy #921 and Vendored yarn classic drops the git-skip warning when the git block is the only copy, and refuses with vendor_lock_entry_not_found telling the user to runyarn install#857 → Fix yarn classic unrewritable copies going unreported (#921, #857) #924; Gem crawler ignores Bundler'spath.system: truewhen a leftovervendor/bundleexists, so agentapplypatches the unused copy andvexattestsnot_affectedwhile Bundler loads the unpatched system gem #915 → Fix gem crawl ignoring Bundler path.system (#915) #916; socket.ymlignorePackages/packagesandscan --packagedon't PEP 503-normalise PyPI names, soignorePackages: ["typing_extensions"]is silently ignored and the package is patched anyway #910 → Fix PyPI package specs ignoring PEP 503 spellings (#910) #911; Hosted yarn berry rollback/remove still drops a custom registry's::__archiveUrl=binding (#817 fix incomplete): the restore looks updist.tarballon npmjs, not the project'snpmRegistryServer, so cold installs 404 #908 and vlt hosted rollback and remove rewrite slot [3] to a synthesized/<name>/-/<leaf>-<ver>.tgzURL instead of the registry's dist.tarball, so the next coldvlt ci404s #521 → Fix npm-family restore ignoring project registry (#908, #521) #918; Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap) #907 → Fix hosted yarn classic pins missing berry warning (#907) #917; Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884 → Fix hosted runs from npm/yarn/bun workspace members pinning nothing (#884) #901; Hosted scan from a pnpm 11/12 workspace member with its own lock writes trustLockfile into a nested member pnpm-workspace.yaml that pnpm ignores, so the root install fails with ERR_PNPM_TARBALL_URL_MISMATCH #880 and Vendored scan from a pnpm 11/12 workspace member with its own lock writes the override into a nested member pnpm-workspace.yaml that pnpm ignores, so the root frozen install fails and a plainpnpm installsilently reinstalls the unpatched package #881 → Fix pnpm member settings written to an ignored nested pnpm-workspace.yaml (#880, #881) #888; Registry downloads give up after 60 s even while the body is still arriving #872 → Bound registry downloads by ApiTimeouts instead of a 60 s total deadline (#872) #876; Crawler probes spawn gem, python and npm with no timeout, so a hung shim hangs scan forever #845 → Bound crawler and tool probes through one spawn deadline (#845) #886; Vendored yarn classic exits 0 when .gitignore covers the vendored tarball (*.tgz,vendor/,.socket/), so the commit drops it and every fresh checkout's install fails #831 → Fix vendored npm-family tarballs dropped by .gitignore (#831) #837; Gem hosted and vendored rewrites delete a secondgemdeclaration that shares the patched gem's line after;, so the nextbundle installdrops that dependency #826 → Fix gem rewrite deleting a;-joined declaration (#826) #875; Gem hosted → vendored takeover un-hosts a gem declared inside agroupblock and then refuses to vendor it (gemfile_declaration_not_editable), so the project silently goes back to unpatched #775 → Fix gem takeover un-hosting a grouped gem (#775) #776; Vendored Pipenv never picks up a superseding patch: re-vendor to a new uuid fails with pypi_pipenv_source_already_exists (lock-only) or a false package_not_installed (venv present), exit 1 #769 → Fix vendored Pipenv re-vendor to a newer patch (#769) #825; Slow scan: poetry hosted 4.5x median ms/pkg (per-patch poetry.lock re-parse) #760 and Slow scan: pdm hosted 3.6x median ms/pkg (per-patch pdm.lock re-parse) #762 → Fix per-patch Poetry/PDM lock re-parse (#760, #762) #877; Hosted gem redirect ignores Bundler 4's custom lockfile (lockfilesetting /BUNDLE_LOCKFILE), so it never pins the lock Bundler uses and frozen installs fail with no warning #749 and Hosted gem redirect wiresgems.rbin a Gemfile/gems.rb twin locked by Bundler 1.17, which loadsGemfile, so the install stays unpatched while the in-run VEX attests it #751 → Fix gem pair model ignoring custom lockfile and Bundler 1 twins (#749, #751) #768; Hosted and lock-only scans treat a UTF-16 requirements.txt (what Windows PowerShell'spip freeze >writes) as absent: exit 0, no warning, and pip keeps installing the unpatched pin #721 → Fix UTF-16 requirements.txt silently skipped (#721) #724; Hosted gem redirect ignores Bundler'smirror.allsetting, so the nextbundle installfetches the redirected gem's upstream bytes from the mirror while the in-run VEX attestsnot_affected#681 → Fix hosted gem redirect ignoring Bundler mirror.all (#681) #684; Vendor-service retries ignore an HTTP-date Retry-After: fold the vendor Retry-After parser and jitter onto api::retry #677 → Honor HTTP-date Retry-After on vendor-service retries through api::retry (#677) #889; Hosted yarn berry rewrites a mixed-line-ending package.json that vendored mode refuses #628 and Share the yarn berry project gates between hosted and vendored modes #629 → Fix yarn berry project gates drifting between modes (#628, #629) #657; A report-onlyscan -gtells you to runsocket-patch scan --mode agent [PATHS]without-g, so following the hint scans the cwd project instead of the global install #464 → Fix report-only scan -g hint dropping -g (#464) #777; Hostedrollback,removeand the vendored takeover refuse a requirements.txt whose only requirements are hosted pins (six==1.16.0alone can be patched but never unpatched) #410 → Fix pip rollback refusing all-hosted requirements (#410) #827; Hosted and vendored Bun rewiring silently discards the project's ownbun patch(patchedDependencies): fresh frozen installs drop the user's patch with exit 0 #367 → Fix Bun rewiring dropping the project's bun patch (#367) #873; Hosted yarn classic redirect breaks every install in projects with a yarn-offline-mirror: the mirror's upstream tarball shares the hosted URL's basename and fails the new integrity pin #364 → Fix hosted yarn classic with an offline mirror (#364) #839; Hosted Hatch rewrite leaves an existing Hatch environment unpatched with no stale-install warning, and vex still attests not_affected #335 → Fix Hatch environments being invisible to stale-install checks and VEX (#335) #700.trustLockfile: trueauto-config when pnpm-lock.yaml starts with a UTF-8 BOM, so pnpm 11/12 frozen installs fail with ERR_PNPM_TARBALL_URL_MISMATCH after a successful scan #903, pnpm-workspace.yaml with a UTF-8 BOM: hosted and vendored miss the first top-level key and append a duplicatetrustLockfile/overrides, so every pnpm install fails with "duplicate mapping key" after a successful scan #904 and pnpm lock and workspace readers don't skip a leading BOM, because BOM handling has no shared helper (4 named copies, ~50 inline strips) #905 (2026-10-06 01:20Z batch3fcf3e). Release them if there's still no PR after 2026-10-08 01:25Z.Needs a human
agent:needs-humanissues waiting on a decision: Decide: keep .socket/apply.lock transient, or give the lock a file that never has to be deleted #808, Decide: make --download-mode file the default and retire the diff download path #792, Decide: one shape for the--jsontop-levelerror(scan and get emit both a string and a {code, message} object) #704, Decide: where patch API calls go when a token is set but the org slug can't be resolved #648, Decide: give SOCKET_FORCE per-command names so forcing a self-update doesn't also force apply and vendor #615, Benchmark tracking: socket-patch scan #580.Generated by Claude Code
All reactions