Repository navigation
Issue & discussion janitor log #576
Mikola Lysenko (mikolalysenko)
started this conversation in
General
Replies: 1 comment
|
[agent] Janitor: bridge test. The janitor/ledger workflow posted this comment on the routine's behalf. Hourly runs log here from now on. Generated by Claude Code |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Janitor: the hourly issue and discussion janitor rewrites this log each run. It shows the last run, the actions it took with a reason for each, a rolling list of recent actions, deferred candidates, and anything that needs a human. The routine writes it to the
janitor/ledgerbranch, and a workflow on that branch applies it here.Last run
2026-10-11 13:26Z on origin/main
578b63e4. Reviewed 174 open issues, 279 issues closed or updated since 2026-10-04, and the 121 PRs merged since 2026-10-09 13:00Z (6 PRs are open). The previous run was 2026-10-09 13:35Z; no run is logged for 2026-10-10.This run
Refs/ a slice and says what remains: Yarn classic hosted and vendored scans miss afile:directory copy of the patched package declared under another dependency name, soscan --vexand lock-onlyvexattest not_affected while that copy installs unpatched #1236 (Fix yarn classic copies locked under another name (#1236) #1242 fixes thefile:/ URL shapes, not the git variant), Hosted gem stale-install guard still flags an unused system gem-home copy under Bundlerdeploymentor the.bundledefault path, soscan --mode hosted --vexfails withno_applicable_patcheson fresh checkouts #1109 (Fix gem checks judging unused system gem homes (#1098, #1109) #1290 fixesdeployment, not the.bundleflags; alsoagent:needs-human), Vendored mode leaves a Pipenv-written pylock.toml or a uv-export requirements.txt unpatched beside the wired lock #1368 (split out of Vendored mode in a Pipenv project wires only Pipfile.lock and silently leaves a sibling requirements.txt unpatched, and the hosted → vendored takeover reverts that file's hosted pin to plain PyPI #612 by Fix vendored Pipenv sibling requirements.txt (#612) #1309), Vendored yarn classic wiring breaks every install run from a workspace member directory: yarn resolves thefile:./.socket/vendor/…tarball against the member dir #691 (Warn on yarn classic member-dir vendored installs (#691) #1324 is an interim warning;agent:needs-human), Read and splice nuget.config through formats::nuget in hosted, vendored and restore #594, Delete the vendored and hosted-vlt helpers left without a production caller by the v5 consolidation #782, Pick the line terminator for spliced lines through one line_endings::terminator #815, Tracking: share CLI test helpers through one test-support module instead of 100+ per-file copies #824, Consolidate remaining BOM stripping after the pnpm reader failures were fixed #905, Hash agent-mode jar members through the shared streaming zip comparator instead of buffering each member #914, Tracking: revert every vendored backend through one record-revert engine instead of nine hand-written mechanisms #989, Tracking: assert stable codes instead of human sentences in CLI tests, and fold the covgap suites #1089, CI performance dashboard #1182, NuGet version identity is normalized by vendor but not by PurlKey, so a freshly vendored 4-part version is judged unused and pruned #1202 (slices). Re-checked: Maven CI matrix has no Windows leg, a stale 4.0 RC, and no legs at the resolver boundaries #267 (ci.ymlstill pins Maven4.0.0-rc-6and has no Windows Maven leg), Warn during pnpm scans when non-registry copies cannot be patched #935 (scan-side warning still open per pnpm ledger run 30). No exact duplicates: the uv script-lock family (Vendored uv script lock: after the user changes the vendored package's specifier in the PEP 723 block,vendor --revert/remove/rollbackwrite the stale==1.16.0back into<script>.py.lock, souv run --lockedfails (exit 0) #869, Vendored uv script locks: once the user deletes one wired script (or its .py.lock),vendor --revert,remove,rollbackand the hosted takeover can never unwind the other scripts, and the takeover's suggested fix is the command that fails #890, Vendored uv script locks: afteruv remove --scriptdrops the package from one of two vendored scripts, every unwind keeps the other script wired (revert exits 0, remove/rollback exit 1, hosted takeover refuses) #1285, Vendored uv transitive package later added as a direct dependency (uv add six==1.16.0):vendor --revert/remove/rollbackhalf-revert the pair, souv sync --lockedfails andvendor --checkclaims nothing references the wheel #1374) and the Maven.mvn/maven.configpair (Vendored Maven reactor ignores user properties set in .mvn/maven.config as --define=k=v or -D k=v, so a 1.11.0 build is silently downgraded to 1.10.0-socket.* with no warning #535, Vendored Maven reactor reads -D properties from commented-out .mvn/maven.config lines, so a 1.11.0 build is silently downgraded to 1.10.0-socket.* (or a valid patch is refused) #550) each have a different trigger. No empty, spam or test issues; every open issue comes from the maintainer account's agents.uv add six==1.16.0):vendor --revert/remove/rollbackhalf-revert the pair, souv sync --lockedfails andvendor --checkclaims nothing references the wheel #1374, CI perf: PR CI — 23% of full PR runs re-test unchanged diffs after a merge-main push (~20–30k Linux job-min/day, feeds the ubuntu-latest backlog) #1373, Vendored requirements.txt refuses asix (==1.16.0)pin that the inventory and hosted mode accept, because exact pins are read by three grammars #1365 (open PRs CI: type-check Windows in the queue, in parallel (#1385) #1386, Fix uv revert after a vendored dep goes direct (#1374) #1384, CI: skip PR re-test after a clean main merge (#1373) #1383, Fix requirements.txt pin grammar split (#1365) #1381), Yarn classic hosted and vendored scans miss afile:directory copy of the patched package declared under another dependency name, soscan --vexand lock-onlyvexattest not_affected while that copy installs unpatched #1236, Hosted gem stale-install guard still flags an unused system gem-home copy under Bundlerdeploymentor the.bundledefault path, soscan --mode hosted --vexfails withno_applicable_patcheson fresh checkouts #1109, Vendored yarn classic wiring breaks every install run from a workspace member directory: yarn resolves thefile:./.socket/vendor/…tarball against the member dir #691, Tracking: share CLI test helpers through one test-support module instead of 100+ per-file copies #824, Delete the vendored and hosted-vlt helpers left without a production caller by the v5 consolidation #782, Read and splice nuget.config through formats::nuget in hosted, vendored and restore #594, Consolidate remaining BOM stripping after the pnpm reader failures were fixed #905 (claimer active within 48h), and NuGet version identity is normalized by vendor but not by PurlKey, so a freshly vendored 4-part version is judged unused and pruned #1202, Tracking: assert stable codes instead of human sentences in CLI tests, and fold the covgap suites #1089, Tracking: revert every vendored backend through one record-revert engine instead of nine hand-written mechanisms #989, Pick the line terminator for spliced lines through one line_endings::terminator #815, Tracking: build and classify purls through one validated utils::purl API #748, Route purl ecosystem checks through Ecosystem::from_purl instead of 24 inline starts_with("pkg:<type>/") tests #747 (a claimed PR merged within 48h).agent:claimedfrom 134 closed issues. No bughunt issue is missing apm:*label.Recent actions (rolling, newest first)
2026-10-08T02:56:01Z-9ee976on Route the remaining hand-rolled child-process deadlines through utils::process #1067 (Bound the PDM site probe through utils::process (#1067) #1106 merged thepdm_siteslice only, claimer silent since 2026-10-08 03:01Z)2026-10-08T15:55:44Z-d66405on Tracking: read and edit pom.xml through one element scanner in formats::maven #715 (Read Gradle verification metadata through one shared XML scanner (#715) #1145 merged item 6 only, claimer silent since 2026-10-08 16:02Z)agent:claimedfrom 134 closed issues (Hosted NuGet remove / rollback / takeover restore packages.lock.json to the nuget.org catalog packageHash, which isn't NuGet's contentHash for signed packages, so every later dotnet restore fails NU1403 #624, Decide: warn on and then remove scan --apply/--vendor, and whether --vex stays embedded #966, Yarn classic: a patch that adds a dependency to the package's own package.json leaves vendored yarn.lock with a dangling dependency (offline frozen install fails, lock churns), and hosted silently installs without it #591, Maven pom rewrites add a second <repositories> or <dependencyManagement> section when the existing one is self-closed or has a comment before <dependencies>, so Maven refuses the pom #342, Vendored and hosted NuGet patches are shadowed by a warm global packages folder: silently unpatched without a lock, NU1403 with one #352, Hosted Maven rewriter ignores<classifier>and suffixes sources/tests/native classifier dependencies, which breaks the build #262, Hosted Maven rewriter edits commented-out, plugin and profile markup, so builds either stay unpatched or break #259, Hosted/vendored NuGet mapping isn't exclusive when nuget.config already maps the exact package id to another source, so restore races the Socket feed against nuget.org (NU1403 with a lock, silently unpatched without one) #462, NuGet nuget.config authored by vendored/hosted mode maps '*' only to nuget.org, cutting off sources inherited from parent or user-level configs (NU1101) #354, With --manifest-path into another project, rollback, remove, repair, vex, scan and get read the vendored ledger from --cwd #745, Vendored mode in a Pipenv project wires only Pipfile.lock and silently leaves a sibling requirements.txt unpatched, and the hosted → vendored takeover reverts that file's hosted pin to plain PyPI #612, Go apply and vendor wire in a patched module whose go.mod raises or adds a requirement without syncing the consumer go.mod/go.sum, so every defaultgo buildfails while apply, --check and VEX report success #618, Go apply and vendor break every build in projects with a committed vendor/ directory (modules.txt not synced), while apply --check and VEX report success #343, Maven hosted scan pins, and VEX attests, artifacts the project doesn't depend on (the crawler lists all of~/.m2) #265, Vendored NuGet on a core.autocrlf checkout: vendor --revert / remove / rollback revert packages.lock.json but leave nuget.config wired, so every restore fails NU1403 (vendor --revert exits 0) #537, Vendored Maven, Gradle and NuGet artifacts can be git-ignored silently, because only npm checks .gitignore #1061, Hosted PDM rollback and remove replace a private index's static_urls with files.pythonhosted.org, so PDM bypasses the mirror (or fails on 2.12 behind a firewall) #413, Agent-mode cargoscan --sync/--prunedrops the manifest entry of a crate the lock no longer resolves but leaves its shared registry-cache copy patched, sorollbackcan't restore it (regression from #1205) #1278, Cargo rollback after an agent→vendored takeover leaves the shared registry cache patched, reports success, and deletes the revert blobs #336, Hosted gemrollback/removestrips theDEPENDENCIES!of a gem the user declared inside asource "https://rubygems.org" doblock, so every frozen install fails after the unwind #1056, Vendored and hosted NuGet ignore a per-project packages.<project>.lock.json, so the lock is never re-pinned and every later restore fails NU1403 while VEX attests the patch #514, Agent-mode cargo apply/rollback has no effect on an already-built project: cargo reuses the cached rlib from target/, while apply reports success and VEX attests not_affected #387, Vendored and hosted NuGet leave member-project packages.lock.json unpinned in a solution layout, so every fresh restore fails NU1403 #353,removeandrollbackcall a vendored PyPI residual-reference keep "lockfile wiring drifted", and their "re-runscan --mode vendoredto normalize, then remove" remedy loops (Pipenvpipenv requirementsexport) #1184, After a hosted or vendored PDM rollback, pdm sync / pdm install keep the patched build installed, though rollback says the next install restores it #477, Hosted cargo scan redirects a crate the user overrides with[patch.crates-io], silently dropping the override and breaking--locked#480, Vendored pnpm 7–11 scan exits 1 afterpnpm remove(or an upgrade) because it tries to vendor the orphanednode_modules/.pnpm/<name>@<ver>that pnpm keeps for 7 days, and the suggestedpnpm installdoesn't clear it #1197, Hosted and vendored pnpm scans add keys to an empty or comment-only pnpm-workspace.yaml withoutpackages:, so every pnpm 8.x–10.4 command then fails with "packages field missing or empty" #1096, Afteryarn removeof a hosted-pinned yarn berry package, its leftoverresolutionspin makes rollback, remove and list fail forever with hosted_wiring_contested, and the remedy they print (re-run the hosted scan) changes nothing #1203, Hosted yarn berry rollback/remove still drops a mirror's::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017, Hatch 1.17+ projects with a hatch-generated pylock.toml get only the lock rewritten, and Hatch regenerates it from pyproject, so hosted and vendored patches are silently dropped #479, uv projects that declare the patched package as a PEP 508 direct URL (six @ https://…/git+…): vendored writes a lockuv sync --lockedrejects while vex attests, and hosted overrides the user's URL then refuses to roll it back #767, Lock-only requirements.txt discovery sends PEP 440-equivalent pins verbatim (six==1.16→pkg:pypi/six@1.16), so a fresh checkout reports "No patches available" while the same file with a venv is patched #604, Hosted yarn classic rewrite drops the#sha1fragment when the grant has no sha1, so yarn's cache serves stale bytes: yarn ≤1.17 silently installs the unpatched package, and yarn ≥1.19 fails every warm-cache install #558, On Windows, Go apply and vendor always fail with "Access is denied. (os error 5)" because the copied module-cache files keep their read-only attribute #346, Hosted yarn berry rollback/remove keep the pin's tarball-formbin:paths (./dist/bin/uuid) on the restorednpm:entry, so hardenedyarn install --immutablefails YN0028 for packages like uuid and prettier #1131, Scan from a hatchling member of a uv workspace rewrites the member's pyproject.toml as a lockless Hatch project, so the root uv.lock goes stale,uv sync --frozeninstalls the unpatched release and vendoredvexattests not_affected #1138, Vendored Maven reactor pins over an imported BOM or external parent, so a build that uses 1.11.0 is silently downgraded to 1.10.0-socket.* and a later BOM bump never takes effect #488, Vendored uv transitive package: afteruv removeof its parent,scan --prune,vendor --revert,removeandrollbackdrift-keep it, sovendor --checkstays red and its prune remedy loops (project and script lanes) #1287, v5 Bundler plugin cleanup leaves.bundle/pluginregistered in every other checkout, sobundle installcrashes with LoadError on Bundler 2.3–2.5 #1295, vendor --force documents a missing-file tolerance and a mismatch warning that no vendored backend implements #923, repair and scan --prune delete the beforeHash blobs of active patches, so a later offline rollback fails and tells the user to run repair #893, Composer reinstall hints always name vendor/<vendor>/<name>, so with a custom config.vendor-dir following them leaves the installed package unpatched #658, Hosted and vendored NuGet reject a packages.lock.json with a UTF-8 BOM that dotnet restores fine: hosted skips the redirect and exits 0 success, vendored fails apply_failed #623, Hosted NuGet rewrites packages.lock.json entries at other versions of the patched id #593, Go settings written withgo env -ware ignored: GOPRIVATE modules are requested from proxy.golang.org, a GOPROXY mirror is bypassed, and a GOMODCACHE cache is not found #344,apply --checkdrift report tells you to runsocket-patch applywithout the-g/--global-prefix/--cwdit was given, so following it patches nothing and exits 0 #1219,socket-patch --updateon a pnpm-installed copy says "managed by npm" and gives an npm command:npm update -gleaves a pnpm global install stale, andnpm install …@latestin a pnpm project breaks the nextpnpm install --frozen-lockfile#1111, Hosted cargo remove writes a duplicate cfg-if block into Cargo.lock when crates.io also locks the same crate@version, so cargo can no longer parse the lock while remove reports success #863, Hosted cargo vex attests not_affected while Cargo.lock also builds an unpatched crates.io copy of the same crate@version #679, Yarn berry vendored and hosted pins of native-addon packages (nan, bufferutil, utf-8-validate, node-addon-api) keep the registry entry's implicitnode-gyp: "npm:latest"dependency, so vendored installs and hardened hosted installs fail YN0028 #737, Vendored scala-cli gate passes a version conflict when a Bloop project file is truncated or oversized #1270, Hosted gem scan of a Gemfile with no lock still pins shared-gem-home versions:gem "x", "~> 2.0"becomes the older patched"1.0.0", and a gem the project never declared is appended as a new dependency #1125, Decide: make the command model read-only scan plus fix/undo/sync, with mode taken from project state, and make "nothing to undo" exit 0 #1088, Hosted Maven mode edits only the root pom of a multi-module build, leaves child literals unpatched, and still attests VEX #261, pnpm node-linker=pnp with a modulesDir is refused as yarn Plug'n'Play, because the layout detector ignores the modulesDir the crawler honors #1129, Humanscan --mode vendored --prunesilently skips the vendored GC when no remaining package has a patch, so annpm uninstalled vendored entry is never reverted (exit 0), while--jsonreverts it andvendor --checkkeeps pointing at that same command #1127, Hosted uv rollback and remove delete a user-authoredoverride-dependencies = ["<pkg>==<ver>"]pin that hosted mode never added #411, Decide: support tiers for bun.lockb writes, vendored pnpm 7/8 locks, vlt pre-1.0 locks and hosted Maven/Gradle #1156, Every HTTPS call fails behind a TLS-inspecting proxy because the clients trust only bundled webpki roots #1107, Cargo apply on a cold or pruned registry cache now exits 0 as "lockfile-only", then the next cargo build downloads and compiles the unpatched crate (regression from #555) #616, CLI_CONTRACT.md documents status paidRequired for get and scan, but get emits "paid_required" and scan never reports it #982, remove, rollback and get treat case-distinct packages as one:remove pkg:npm/jsonstreamalso removes JSONStream's patch #1292, Hosted Bun rollback/remove ignores a private scope set in ~/.npmrc or ~/.bunfig.toml: it looks the package up on the public registry, then fails or writes a "" slot with the public package's integrity (#992 fix reads only the project's files) #1276, Afternpm install <pkg>@<other version>moves a vendored npm package off its patched version,scan --prune,vendor --revert,removeandrollbackall drift-keep it, sovendor --checkstays red and every remedy it names loops #1155, Vendored Pipenv re-serializes the whole Pipfile.lock, so a non-ASCII lock is rewritten throughout and its revert is not byte-identical #1128, Decide: make --download-mode file the default and retire the diff download path #792, scan exits 1 in human output but 0 with --json when every patch query returns nothing #1062, Hosted requirements.txt rewrite replaces a user's own direct reference (six @ https://mirror/…/six-1.16.0-….whl,file://fork) with the Socket PyPI build, and rollback then restoressix==1.16.0from PyPI, losing the original source #542, Yarn classic hosted and vendored modes can't see or patch a yarn.lock block whose key has an empty range (left-pad@:from"left-pad": ""), so a lock-only scan reports no vulnerable package and an installed scan leaves it unpatched #1271, Gem VEX judges an unused system gem-home copy when the project sets a Bundler path, so standalone vex never attests #1098, Hosted pin on a bun.lockb record that Bun shares with a bundled copy can't be unwound: list errors, and the vendored takeover fails (#1008's #828 fix covers the text bun.lock only) #1243, Vendored NuGet doesn't recognise a close tag with whitespace (</packageSources >,</packageSourceMapping >), so it appends a second section that NuGet ignores and every restore fails NU1100 / NU1403 while scan reports success and VEX attests #685, Vendored→hosted takeover on yarn classic un-patches a vendorednpm:alias copy when a direct copy is pinned, instead of retracting the takeover #1158, Hosted yarn classicscan --vexattests not_affected when annpm:alias copy of the patched package was skipped, while standalonevexrefuses the same lock #1081, A failed VEX write leaves a truncated OpenVEX document at the output path #1144, Hosted gemrollback/removeleave the patched.gemin the project's committedvendor/cache, so every laterbundle installfails with mismatched checksums (exit 37) while the unwind reports success #1260, Vendored PyPI revert, remove, rollback and the hosted takeover delete the vendored wheel while a rootuv export -o requirements.lock(Rye-style name) still installs from it (exit 0) #1252, Afteruv remove --scriptdrops a vendored package from a PEP 723 script lock,scan --prune,vendor --revert,remove,rollbackand the hosted takeover still drift-keep it, sovendor --checkstays red and its prune remedy loops #1214, Scan of a fresh Poetry checkout (no Poetry env yet, default virtualenvs.create) crawls the system Python: vendored exits 1 on system-only packages and agent mode patches dpkg-owned files (the Poetry side of #947 / #964) #1023, With{data-dir}in Poetry's virtualenvs.path, agent mode also patches an unrelated activated VIRTUAL_ENV / conda env, even thoughpoetry env usepins the project's env, and hosted VEX then refuses a correctly installed patch #866, With Poetry virtualenvs.create = false, agent mode patches a stray ./venv (or ./.venv under in-project = false) instead of the system env Poetry installed into, and VEX attests not_affected #671, Lock-only requirements.txt discovery drops a pin whose last line ends in a dangling\continuation (six==1.16.0 \at EOF): scan exits 0 with "No patches", but pip installs it #1249, Hosted and vendored scans from a vlt workspace member with a stray vlt-lock.json write to that lock, which vlt ignores, and exit 0 (vendored VEX then attests not_affected whilevlt cifails) #1134, Capped hosted scan (--max-new-patches 0) defers an already-pinned npm patch as NEW when a second lock entry of the same version is unpinned, so the vex remedy loops and that copy stays unpatched (regression from #1058) #1195, Hosted and vendored scans from a Bun workspace member with a stray bun.lock / bun.lockb pin that ignored lock, exit 0, and lock-only VEX attests not_affected while Bun installs the unpatched package #1101, On Bun ≥ 1.3.5, hosted and vendored rewiring drops Bun's default trust, so install scripts of patched packages (better-sqlite3, esbuild, sharp…) are silently blocked #371, Bun hosted and vendored modes skip a URL orfile:tarball copy of the patched package without warning, and vendoredvexattests not_affected (the #326 fix covers npm locks only) #497, Global mode misses every Bun global package when BUN_INSTALL_BIN or BUN_INSTALL_GLOBAL_DIR is set: scan -g reports success with nothing found, get -g / vex -g patch and attest nothing #443, Perf regression: bun/hosted wall +110% (1169ae68, #472) #578, With Bun's globalStore (Bun ≥ 1.3.14), agent mode patches and rolls back every other project sharing the store, and vex attests unpatched transitive copies as not_affected #635, With Bun's isolated linker,vexrefuses every hosted patch as not_applied after the usual in-placebun install, because it checks orphanednode_modules/.bunregistry entries that Bun never removes (regression from #496) #599, After a Bun rollback orvendor --revert, the advisedbun installkeeps the patched bytes installed on the hoisted linker (Bun reports "no changes") #764, Lock inventory ignores a bun.lockb that Bun installs from when bun.lock is a dangling symlink #735, Vendored re-run on an isolated-linker bun.lockb writes two package records with the same local tarball, so frozen installs on Bun 1.3.9/1.4.2 fail intermittently with EEXIST #861, After Bun migrates a vendored bun.lockb to bun.lock (bun install --save-text-lockfile), vendor --revert and rollback fail, and a superseding re-vendor drops the pre-vendor original so revert exits 0 with the project still vendored #784, Hosted Bun rollback/remove writes an empty registry slot that Bun < 1.3.7 resolves against npmjs, so custom-registry projects can't frozen-install after a revert #992, Hosted pnpm rollback/remove restorespnpm-lock.yamlfrom npmjs's version document instead of the project's.npmrcregistry, so a mirror project loses itstarball:URL (cold frozen install 404s) or is moved to npmjs #919, Decide: where patch API calls go when a token is set but the org slug can't be resolved #648, Global agent mode on pnpm 12 (and 11 without the global virtual store) patches only one of the per-install copies of a package, reports success, and VEX attests not_affected #435, Vendored pnpm 12 withpackageManagerset: the two-document pnpm-lock.yaml makes vendor refuse, andvendor --revert, rollback and the hosted takeover half-revert the project and break frozen installs #466, Hosted scan with pnpmgitBranchLockfilepins the stale pnpm-lock.yaml and reports success, while pnpm installs unpatched bytes from pnpm-lock.<branch>.yaml #556, Hosted scan on a pnpm workspace withsharedWorkspaceLockfile: falseignores the per-package pnpm-lock.yaml files and reports success while redirecting nothing #492, Hosted scan on a Rush repo with pnpm 11/12 reports success, butrush installthen fails with ERR_PNPM_TARBALL_URL_MISMATCH, or (pnpm 11.0.0) silently installs the upstream package #713, Agent-mode apply in a pnpm workspace reports each member-linked package twice, inflating the --json skipped count with duplicate already_patched events #633, Hosted scan on a Rush repo with subspaces never emitsredirect_rush_repo_state_stale, sorush installfails on the shrinkwrap hash check with no warning #714, Agent-modescan packages/<member>finds nothing in a pnpm workspace (exit 0), whilerollback packages/<member>selects the same packages #778, Hosted and vendored modes create apackages: ['.']pnpm-workspace.yaml that turns a single-package project into a workspace, sopnpm add <pkg>fails with ERR_PNPM_ADDING_TO_ROOT on pnpm 9.0–10.4 #734, Vendored pnpm: unwinding a vendored package whose dependency is also vendored clobbers the child's lock wiring —remove <parent>breaks frozen installs, the hosted takeover silently unpatches the child, and rollback fails forever #830, Vendored pnpm refuses a user exact-pin override (left-pad: 1.3.0) in pnpm-workspace.yaml with a misleading "does not match package.json" error, though the same pin in package.json is taken over #854, pnpm hosted-to-vendored scan/get dry-run previews success for a refused takeover #853, Hosted pnpm rollback/remove adds registrytarball:URLs the lock never had whenlockfileIncludeTarballUrlsits in a settings file the installed pnpm ignores (workspace file on pnpm 9,.npmrcon pnpm 11/12) #902, Hosted and vendored scans rewrite a Pipenv project's pylock.toml to anarchiveentry that Pipenv 2026.4+ ignores, sopipenv syncsilently installs the unpatched release from PyPI #912, Build npm-family vendor ledger entries through one constructor instead of seven literal VendorEntry blocks #922, Resolve VEX npm alias copies through the core resolver and delete vex_consumed's second alias walk #856, Walk package-lock entries once for inventory, vendored, hosted and restore #663, remove --preserve-state on a manifest-less hosted npm project silently restores the pin without the documented hosted_state_not_preservable note #433, Agent-mode scan ignores socket.yml includePaths / ignorePaths (and the built-in tests/ default) for nested npm projects, patching every nested project's node_modules #554, npm vendored refuses a registry package with vendor_workspace_member whenever a local file: directory (or workspace member) has the same name@version, and the hosted→vendored takeover then un-hosts it, leaving it unpatched #688, npm hosted and vendored modes rewrite a lock entry nested under a dependency that ships npm-shrinkwrap.json (hasShrinkwrap), so npm 7–11 install it unpatched while vendored VEX attests not_affected #753, Hosted npm scan pins a package that npm 12's nativepatchedDependenciesalso patches, so every laternpm ci/npm installfails EPATCHFAILED (and vendored refuses the lockfileVersion 4 lock with wrong advice) #711, npm hosted pin next to a bundled copy can't be unwound: rollback/remove refuse it, and the vendored takeover skips the restore, so vendor --revert lands back on hosted and allow-remote=all stays #828, Hosted npm scan pins a hosted tarball URL that npm rewrites to the registry under replace-registry-host=always, so every npm ci / npm install then fails E404 while the scan reports success #812, Vendored npm vex and vendor --check fail after any npm 7–10npm installon a lockfileVersion 2 lock, because npm dropsresolvedfrom the legacy mirror and #813 treats that as an unpatched npm 6 install (regression) #879, npm 12 never reads npm-shrinkwrap.json, so on a shrinkwrap-only project hosted and vendored scans rewrite a lock npm 12 ignores: scan succeeds with no warning, lockfile-only VEX attests not_affected, andnpm installinstalls the unpatched package #899, Vendored npm refusal for a symlinked package-lock.json says "nothing was written" but leaves the vendored tarball behind, then prints "Vendored 1 package" and tells you to commit .socket/vendor/ #898, Project-mode NuGet agent scan patches, and VEX attests, packages the project doesn't depend on (the crawler lists the whole ~/.nuget/packages) #427, Delete go_sum_edit's oracle-only free functions and move the go.sum codec to formats #631, Agent-mode apply and rollback reject a manifest hash in uppercase hex that blob download accepts as valid #707, Decide: one shape for the--jsontop-levelerror(scan and get emit both a string and a {code, message} object) #704, Decide: keep .socket/apply.lock transient, or give the lock a file that never has to be deleted #808, Vendored requirements.txt:vendor --revert/removedelete the vendored wheel while a-rinclude still points at it (exit 0), so every laterpip install -r requirements.txtfails #867, Read Cargo.toml package name and version through one shared toml_edit reader #693, Decide: give SOCKET_FORCE per-command names so forcing a self-update doesn't also force apply and vendor #615)fail)agent:claimedfrom 29 closed issues (Vendored Poetry wires a 2.x lock through two different splicers depending on its line endings #936, Vendored npm re-scan exits 1 ("Failed to vendor", "1 failed") on every run while a superseding patch's artifact is pending_build / build_failed / not_found, although the vendored older patch is intact; hosted skips the same upgrade with exit 0 #954, Vendored npm scan wires file: tarballs that npm ≥ 11.14 refuses under allow-file=root (transitive deps) or allow-file=none, so every npm ci fails EALLOWFILE while scan, vendor --check and vex report success with no warning #969, Decide: vendor single-module Maven poms through the suffixed-version jvm planner and retire the same-GAV <repository> wiring #973, Perf regression: npm/hosted wall +15% (2463257a..9c43dfc9) #993, Vendored uv:vendor --revert/remove/rollbackdelete the vendored wheel while auv export-ed requirements.txt or pylock.toml still points at it (exit 0), so installs from the exported file fail #996, scan --mode agent --json and get --json overwrite a locally modified npm file without the documented content_mismatch_overwritten warning (not in the JSON, not on stderr) #1004, A rolled-back vendor eject prints "Vendored 1 package" and "Commit .socket/vendor/" with no eject_rolled_back warning, and --json still reports the rolled-back package as applied #1005, Hosted and vendored pnpm 11/12 refuse a standalone project nested under an unrelated pnpm-workspace.yaml (not in itspackages:globs) as a "workspace member", and the suggested fix doesn't work (regression from #888) #1006, Vendored uv repair pairs a hashless pure wheel with another wheel's hash, because ledger recovery re-parses uv.lock with its own scanner #1079, On Bun's isolated linker, rollback/remove of a superseded agent record (#934) drops the record and its blobs while the orphanednode_modules/.bun/<pkg>@<ver>copy still holds the agent patch, and the advisedbun installrelinks it #1084, Lockfile discovery treats a requirements.txt-rinclude as a competing lock, so after a hosted rewritevexattests nothing (exit 2) androllbackrefuses (exit 1), althoughpip install -r requirements.txtinstalls the patched wheel #1086, Hosted and vendored scans run from an npm workspace member that has a stray package-lock.json of its own rewrite that lock, which npm ignores, and report success while npm installs the unpatched package and VEX attests not_affected #1094, Lock-only scans still drop a requirements.txt pip decodes through a PEP 263 coding line (latin-1): "No pypi packages found", exit 0, while the same project with a venv refusescandidate_file_unreadable#1119, Vendored uv: a UTF-16 requirements.txt beside uv.lock is read as absent, sovexattests not_affected andvendor --checkpasses whileuv pip install -r requirements.txtinstalls the unpatched release #1120, Vendored scan of a Pipenvuse_pylock = trueproject wires only pylock.toml, but Pipenv installs from Pipfile.lock, sopipenv sync/install --deployinstall the unpatched release after a "success" run #1122, Afterbun removeof a vendored package in a bun.lockb project,scan --prune,vendor --revertandremovekeep it as "drifted", sovendor --checkstays red and its remedy loops #1132, Vendored Poetry never re-vendors to a superseding patch: re-scan exits 1 with pypi_poetry_source_already_exists, while --dry-run previews would_revendor, and the project keeps installing the old patch #1136, Afteruv removeof a vendored package,scan --prune,vendor --revert,removeandrollbackall keep it as "drifted", sovendor --checkstays red and its suggestedscan --prunefix loops #1140, Afterpipenv uninstallof a vendored package from a named category on Pipenv 2022/2023,scan --prune,vendor --revert,removeandrollbackkeep it as "drifted", sovendor --checkstays red and itsscan --pruneremedy loops #1142, Lock inventory pins cp311/pp310/py2 "-none-any" wheels as pure, while vendored, hosted and recovery refuse them #1150, Vendored PyPI revert,removeand the hosted takeover still delete the vendored wheel while a requirements file in a subdirectory (requirements/dev.txt,pip freeze > requirements/lock.txt) installs from it (exit 0), so that install then fails #1167, Hosted gem re-scan refreshes a patch-registry GEM remote in place without re-sorting the lock's GEM sections, so after a superseding patch on a two-gem project every Bundler 4.0.19+ frozen install fails #1186, Scope the project-mode cargo crawl to the registry crates Cargo.lock resolves #1204, Scope the project-mode Go crawl to the modules go.sum records #1207, Since #1152, a plain-ASCII requirements.txt whose coding line names an unmodelled codec (iso-8859-15, cp1250, gbk…) is read as absent: scan finds nothing (exit 0), and vex / rollback can't see an existing hosted pin #1212, Vendored PyPI revert, remove, rollback and the hosted takeover still delete the vendored wheel while auv export --format pylock.tomlin a subdirectory installs from it (exit 0) #1213, Scope the project-mode Deno crawl to the JSR packages deno.lock records #1216, Capped hosted gem re-scan counts a Gemfile-only (no-CHECKSUMS) pin as NEW, so--max-new-patches Nspends its budget on gems it already wired and starves the next one forever (regression from #1058) #1224)fail)agent:claimedfrom 37 closed issues (Hosted Hatch rewrite leaves an existing Hatch environment unpatched with no stale-install warning, and vex still attests not_affected #335, Vendored yarn berry PnP refusal keys only on .pnp.cjs: a lock-only PnP checkout vendors successfully, then every re-run in an installed checkout fails exit 1 with vendor_yarn_berry_unsupported #539, Hosted yarn berry rewrites a mixed-line-ending package.json that vendored mode refuses #628, Share the yarn berry project gates between hosted and vendored modes #629, Hatch never picks up a superseding patch: re-scan refuses its own earlier wiring ("existing direct source must be reverted"), so hosted exits 0 still pinned to the old patch uuid #650, Vendor-service retries ignore an HTTP-date Retry-After: fold the vendor Retry-After parser and jitter onto api::retry #677, Compute sha256, sha1 and sha512-SRI digests through utils::digest instead of inline copies #706, Hosted and lock-only scans treat a UTF-16 requirements.txt (what Windows PowerShell'spip freeze >writes) as absent: exit 0, no warning, and pip keeps installing the unpatched pin #721, uv vendored → hosted takeover strands a package that vendored mode pinned to a different version than uv.lock: the wet run reverts to the unpatched release (exit 1), while --dry-run previews a clean takeover #723, Hosted gem stale-install warning calls the project's ownvendor/bundlea "shared gem home" when--cwdis left at its default (or relative), so it gives the wrong remedy and drops the committed cache archive from the delete list #729, uv projects never pick up a superseding patch: hosted re-scan lists the upgrade in updates[] but refuses its own earlier [tool.uv.sources] pin (exit 0, still on the old uuid), and vendored re-scan fails pypi_uv_source_already_exists #742, Hosted gem redirect ignores Bundler 4's custom lockfile (lockfilesetting /BUNDLE_LOCKFILE), so it never pins the lock Bundler uses and frozen installs fail with no warning #749, Hosted gem redirect wiresgems.rbin a Gemfile/gems.rb twin locked by Bundler 1.17, which loadsGemfile, so the install stays unpatched while the in-run VEX attests it #751, Gem hosted → vendored takeover un-hosts a gem declared inside agroupblock and then refuses to vendor it (gemfile_declaration_not_editable), so the project silently goes back to unpatched #775, Vendored-reference scan never sees NuGet or Maven wiring, so the orphan sweep deletes a still-wired unit #832, Registry downloads give up after 60 s even while the body is still arriving #872, Hosted pnpm scan skips thetrustLockfile: trueauto-config when pnpm-lock.yaml starts with a UTF-8 BOM, so pnpm 11/12 frozen installs fail with ERR_PNPM_TARBALL_URL_MISMATCH after a successful scan #903, pnpm-workspace.yaml with a UTF-8 BOM: hosted and vendored miss the first top-level key and append a duplicatetrustLockfile/overrides, so every pnpm install fails with "duplicate mapping key" after a successful scan #904, Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap) #907, After an agent→hosted migration, a superseding patch leaves the stale agent manifest record, so npm rollback exits 1 ("modified after patching") and remove refuses to un-host #933, Yarn classic VEX attests not_affected when yarn.lock also has a registry block for the patched name@version (e.g. afteryarn add -W <pkg> --exact), though yarn installs only the unpatched registry copy #938, Hosted scan/get run from a vlt workspace member reports success while pinning nothing: the #598 / #901 member refusal has no vlt.json case #942, Poetry 0.x vendored → hosted takeover un-vendors the package before hosted mode refuses the lock, while --dry-run previews a clean takeover (redirected: 1, exit 0) #945, Gem.bundle/configreader keeps a trailing# commentin the value, so a commentedBUNDLE_PATHis missed, agentapplypatches the system copy andvexattestsnot_affectedwhile Bundler loads the unpatched project copy #951, Vendored-reference scan never reads hatch.toml, so the orphan sweep deletes a wheel that a Hatch environment still installs #958, Vendored scan of a fresh uv checkout (uv.lock, no .venv yet) exits 1 on packages that exist only in the system Python, because the crawler falls back to the global site-packages (the uv side of #947) #964, Gem crawler ignores Bundler's.bundledefault install path (default_install_uses_pathon 2.x,simulate_version 5on 4.x), so agentapplypatches the system copy andvexattestsnot_affectedwhile Bundler loads the unpatched.bundle/ruby/<abi>copy #967, Yarn 4 node-modules / pnpm-linker projects migrated from Yarn 2 PnP keep a stale.pnp.js, and socket-patch refuses them as Plug'n'Play: agent and vendored exit 1, hosted warns "npm dependencies were NOT scanned" (regression since 3.3.0) #975, Vendoredvendor --dry-runpreviews success on a uv project with an inline[tool.uv]/sourcestable, but the real run refusespypi_uv_lock_parse_failed(exit 1) #979, Hosted gem stale-install guard flags an unused system gem-home copy when the project sets a Bundlerpaththat isn't installed yet, soscan --mode hosted --vexfails withno_applicable_patcheson fresh checkouts #1001, Hosted yarn classic offline-mirror refusal (#364 fix) only reads the project's own .yarnrc/.npmrc, so a mirror set in ~/.yarnrc, yarn's user config or a parent dir still breaks every install #1013,removeandrollbackdon't PEP 503-normalise PyPI purl identifiers, soremove pkg:pypi/typing_extensions@4.7.1exits 1 "No patch found" whilegetaccepts the same identifier #1024, Lock-only requirements.txt discovery skips a-rinclude that follows another option on the same line (--pre -r dev.txt,-i <url> -r dev.txt), so the scan exits 0 with "No patches" while pip installs the include #1028, Hosted Pipenv scan still pins an interpreter-boundcp311-none-anypatched wheel into Pipfile.lock with no warning, sopipenv syncfails on every other Python version (gap in the #932 fix) #1048, Hosted gem scan pins a version that only another project installed into the shared gem home, rewritinggem "x", "~> 1.0"to the older patched"0.8.1", so the prescribedbundle installdowngrades the project's locked gem #1055, Hosted scan/get from an npm workspace member still pins nothing and exits 0 when the root's workspaces glob uses braces or a character class (packages/{a,b}, packages/[a-c]), because the #884 refusal's matcher doesn't support them #1071, Hosted yarn classic offline-mirror refusal misses a project .yarnrc or .npmrc saved with a UTF-8 BOM, so the scan pins anyway and every install fails #1078)2026-10-06T13:22:24Z-2c1feaon Warn during pnpm scans when non-registry copies cannot be patched #935 and Yarn berry hosted and vendored scans miss afile:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939 (PR Fix VEX attesting beside an unpatched same-lock copy (#935, #938, #939) #940 merged asRefswith the VEX half only, no follow-up PR, claimer silent for more than 48h)fail)2026-10-05T11:56:39Z-93d7a1on Spawn every CLI test child through one hermetic Command builder; 10 test files inherit ambient SOCKET_* today #823 (Spawn CLI test children through one hermetic Command builder (#823) #850 merged slice 1 only, no follow-up PR, claimer silent for more than 48h)agent:claimedfrom 33 closed issues (closed by the 2026-10-07 11:48–12:40Z merge wave, plus Hosted yarn classic redirect breaks every install in projects with a yarn-offline-mirror: the mirror's upstream tarball shares the hosted URL's basename and fails the new integrity pin #364, Hosted and vendored Bun rewiring silently discards the project's ownbun patch(patchedDependencies): fresh frozen installs drop the user's patch with exit 0 #367, Hostedrollback,removeand the vendored takeover refuse a requirements.txt whose only requirements are hosted pins (six==1.16.0alone can be patched but never unpatched) #410, scan/get --json drop the agent-mode apply failure: exit 1 with failed: 0, the patch shown as "added", and no error anywhere (e.g. a read-only global ~/.m2) #424, A report-onlyscan -gtells you to runsocket-patch scan --mode agent [PATHS]without-g, so following the hint scans the cwd project instead of the global install #464, Agent-mode scan in a Pipenv project without a Pipenv venv patches the system Python's site-packages in place instead of the project's venv/ (regression from #388) #504 and vlt hosted rollback and remove rewrite slot [3] to a synthesized/<name>/-/<leaf>-<ver>.tgzURL instead of the registry's dist.tarball, so the next coldvlt ci404s #521, which were closed earlier)fail)abb5787asaid "Fixes Hosted scan/get run from a pnpm workspace member (or withlockfile-dir=..) ignores the parent pnpm-lock.yaml and reports success while pinning nothing #590 and Hosted cargo scan run from a workspace member treats it as a lockless project, rewrites only the member, and breaks every build of the workspace while reporting success #417", but only Hosted scan/get run from a pnpm workspace member (or withlockfile-dir=..) ignores the parent pnpm-lock.yaml and reports success while pinning nothing #590 auto-closed;cargo_hosted_scan_from_workspace_member_refuseson main)0c1e07b8said "Fixes Hosted NuGet mapping reads commented-out package sources #561 and Hosted NuGet splices the Socket source (and mapping) into a commented-out <packageSources> / <packageSourceMapping> block, so every restore fails NU1100 while scan reports success and its in-run VEX attests not_affected #585", but only Hosted NuGet mapping reads commented-out package sources #561 auto-closed; hosted NuGet anchors come fromformats::nuget::parse_config)applycan't apply Maven patch records keyed by jar member paths, althoughvendoraccepts the same record #264 as completed (PR Full Gradle support in agent, hosted and vendored modes #6460685ba8caddedpatch/jvm_jar.rs, a member-keyed Maven record jar swap inapply_maven_base; tests ingradle_agent_cli.rs)2026-10-04T03:20:54Z-020a8fon uv projects never pick up a superseding patch: hosted re-scan lists the upgrade in updates[] but refuses its own earlier [tool.uv.sources] pin (exit 0, still on the old uuid), and vendored re-scan fails pypi_uv_source_already_exists #742 and Hatch never picks up a superseding patch: re-scan refuses its own earlier wiring ("existing direct source must be reverted"), so hosted exits 0 still pinned to the old patch uuid #650 (only the hosted slice merged in Fix uv/Hatch hosted re-pin to a newer patch (#742, #650) #743, no vendored PR, claimer silent for more than 48h)agent:claimedfrom 34 closed issues (Hosted cargo scan run from a workspace member treats it as a lockless project, rewrites only the member, and breaks every build of the workspace while reporting success #417, plus 33 closed by the 2026-10-05 13:39–18:16Z merge wave)fail), Bug hunt ledger: vlt #307 (Hosted and vendored modes refuse vlt 1.3 locks whose nodes carry the new brotli flag (slot [0] = 4) #372), Bug hunt ledger: Bundler (RubyGems) #316 (Hosted gem VEX attestsnot_affectedfor an unpatched install when.bundle/configsets an out-of-treepath(absolute or~/…), because the skipped bundle root counts as "nothing installed" #709), Bug hunt ledger: NuGet / dotnet #320 (Vendored yarn classic replaces a symlinked yarn.lock with a regular file (hosted refuses the same lock), leaving the link's target unpatched; rollback never restores the link #627) and Bug hunt ledger: npm #302 (npm v2 lock: aliased packages stay on the registry in the legacy dependencies mirror (hosted silently, vendored with a warning), so npm 6 installs unpatched bytes while VEX attests not_affected #432)include-group#473 as completed (PR Fix uv hosted unwind declaration matching (#606, #473) #6259df2afa5said "Fixes Hosted uv rollback, remove and vendored takeover refuse when the patched package is declared with different specifiers independenciesand an extra (or under different markers), although each lock entry keeps its marker #606 and Hosted uv rollback and remove refuse when the patched package reaches a dependency group through PEP 735include-group#473", but only Hosted uv rollback, remove and vendored takeover refuse when the patched package is declared with different specifiers independenciesand an extra (or under different markers), although each lock entry keeps its marker #606 auto-closed;include_group_membertest on main)2465131e; site config layer read inpdm_global_site_packages_with).deno/<name>@<ver>_1copy is unpatched: the #517 every-copy check never sees store peer-variant copies #603 as completed (PR Fix npm store copies missed by agent apply and vex (#601, #603) #60546466931;verify_mode_requires_every_store_copy_patchedcovers the Deno_1case)agent:claimedfrom 49 closed issues (46 closed by the 11:13–13:20Z merge wave, plus Hosted uv rollback and remove refuse when the patched package reaches a dependency group through PEP 735include-group#473, Global scan (-g) ignores PDM's site-wide config, so a global project relocated in /etc/xdg/pdm/config.toml is never crawled and get -g reports "applied" while the copy PDM runs stays unpatched #566 and Agent-mode vex still attests not_affected when a Deno.deno/<name>@<ver>_1copy is unpatched: the #517 every-copy check never sees store peer-variant copies #603 above)fail)scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 for Windows)scan -gofficial-installer row isfailbut points only at closed Global scan (-g) never crawls pipx venvs, so the dependencies of a pipx-installed Hatch are never reported, patched or rolled back on any OS #415; no open issue tracks it)fail)agent:claimedfrom closed The patch API client has no request timeout, so scan, get and apply hang forever on a stalled server #570 (closed as completed by PR Bound patch API connects and stalled reads (#570) #581)agent:claimed(no PR for the remaining half, claimer silent for more than 48h)agent:claimedfrom closed Poetry hosted ⇄ vendored mode switch is refused, and blames a "user-authored" source that socket-patch wrote itself #328 (closed as completed, so the claim is finished)agent:claimedfrom closed Pipenv recognizes hosted PyPI patch URLs with two private grammars that disagree with the shared one #563 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted gem redirect appends a second declaration when the gem is declared througheval_gemfileor a loop, so everybundle installfails with "You cannot specify the same gem twice" #482 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted gem redirect rewrites only the first of a gem's declarations, so a gem listed in twogroupblocks makes everybundle installfail with "You cannot specify the same gem twice" #548 (closed as completed, so the claim is finished)fail)fail)fail)fail)fail)fail)agent:claimedfrom closed Bun isolated linker: transitive packages under node_modules/.bun are "not installed" in agent mode, and scan --mode agent exits 0 with them unpatched #366 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted → vendored takeover on yarn berry reverts the hosted redirect before a per-package vendor refusal, leaving the package unpatched in both modes #369 (closed as completed, so the claim is finished)agent:claimedfrom closed Deno nodeModulesDir: transitive npm packages under node_modules/.deno are "not installed", and apply/scan exit 0 leaving them unpatched #373 (closed as completed, so the claim is finished)agent:claimedfrom closed npm apply exits 1 when every patch targets a platform-skipped optional dependency (fsevents, @esbuild/*), so the setup hook fails npm ci and npm install on other OSes #403 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted yarn berry redirect makes yarn send the project's npm registry auth token to the patch host #404 (closed as completed, so the claim is finished)Deferred / unsure
file:directory copy of the patched package declared under another dependency name, soscan --vexand lock-onlyvexattest not_affected while that copy installs unpatched #1236 (claimer last spoke 2026-10-09 18:48Z), Hosted gem stale-install guard still flags an unused system gem-home copy under Bundlerdeploymentor the.bundledefault path, soscan --mode hosted --vexfails withno_applicable_patcheson fresh checkouts #1109 (16:09Z), Vendored yarn classic wiring breaks every install run from a workspace member directory: yarn resolves thefile:./.socket/vendor/…tarball against the member dir #691 (17:50Z), Tracking: share CLI test helpers through one test-support module instead of 100+ per-file copies #824 (19:01Z), Delete the vendored and hosted-vlt helpers left without a production caller by the v5 consolidation #782 (20:13Z), Read and splice nuget.config through formats::nuget in hosted, vendored and restore #594 (15:01Z), Consolidate remaining BOM stripping after the pnpm reader failures were fixed #905 (13:59Z).Needs a human
agent:needs-humandecisions: Vendored yarn classic wiring breaks every install run from a workspace member directory: yarn resolves thefile:./.socket/vendor/…tarball against the member dir #691, Self-update and install.sh trust an unsigned SHA256SUMS from the same release #1065, Decide: should hosted VEX require installed evidence by default instead of attesting from lockfile wiring? #1099, Hosted gem stale-install guard still flags an unused system gem-home copy under Bundlerdeploymentor the.bundledefault path, soscan --mode hosted --vexfails withno_applicable_patcheson fresh checkouts #1109, Decide: should hosted rollback keep an originals sidecar, or restore only formats whose original is a pure function of registry data? #1130, Decide: keep the in-memory hosted engine and napi addon as a supported product, or delete them #1200, CI perf (settings): merge queue builds 5 entries at a time — a 13-PR burst took 100 min to drain on a 21-min CI run (~21 min per PR past the 5th) #1248, Decide (post-v5): fix/undo/sync command model and exit 0 when there is nothing to undo #1352.janitor/ledgerbranch now requires signed commits; this run's pushes are signed with the session's commit key.Generated by Claude Code
All reactions