Commit 0f2de18
v5 design: staged patch rollout (socket.yml + scan limit) (#290)
* Plan staged patch rollout for v5
Adds the design for rolling Socket patches out gradually: a
`patches:` block in socket.yml that narrows what scan may patch
(paths, ecosystems, packages, severity floor, on/off), and a
severity-ordered per-run cap on new patches so each scan lands the
next few most critical fixes.
The plan splits the work into two parallel items with a frozen
interface, lists every hard-coded filter and where it belongs, and
covers the depscan autopatch follow-up. configuration.md now records
that socket-patch reads socket.yml for selection policy only, with
the trust boundary unchanged.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* Revise rollout plan after adversarial review
Three independent reviews (ambiguity, churn, trust boundary) found
gaps that would have let the two implementations disagree or let a
repo file widen or stall the rollout. The plan now:
- matches paths against marker files with the backend's top-down
gitignore rules, so projectIgnorePaths means the same everywhere
- uses one data source for severity, supersession and ordering
- spends the budget only on patches the planning pass proves can
land, and admits nothing new when a lookup failed
- uses the merged recorded view in every mode and engine
- has depscan read the policy from the base commit for PR jobs
- hardens file handling (regular files, aliases, size, encoding,
trusted repo root) and reports what a policy hides
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* Close interface gaps in the rollout plan
A final consistency pass found places where the two work items
would have produced incompatible code: base purls admitted in one
directory being charged again in the next, no defined hand-off of
the unfiltered offers from the severity filter to classification,
no shared repo-relative path helper, and override sources the JSON
must report but the interface could not carry. The shared contract
now defines each of these, and the parity tests match each engine's
budget scope.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* Clarify who shapes scan's selection output
The plan said both that the selector returns the shared offers
struct (work item A) and that it returns admitted/deferred rows
(work item B). The selector now returns the offers, and B adds the
rollout stage after it.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* Apply socket.yml policy in memory path selection
Bugbot on #290: the plan had the in-memory engine's path selector
apply only the built-in test/fixture ignores, because it runs before
socket.yml is read. A negation such as `!/e2e/tests/` could then
never bring those trees back in depscan, while it works on disk.
Selection is now two-phase: the caller fetches the root policy
file(s) first and passes their text to selectHostedScanPaths, which
applies the full path policy. A listed policy file that is not passed
fails closed. A new memory test covers the negation case.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>1 parent 388eea3 commit 0f2de18
3 files changed
Lines changed: 1089 additions & 14 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
4 | | - | |
5 | | - | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
6 | 7 | | |
7 | 8 | | |
8 | 9 | | |
| |||
69 | 70 | | |
70 | 71 | | |
71 | 72 | | |
72 | | - | |
73 | | - | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
74 | 77 | | |
75 | 78 | | |
76 | 79 | | |
77 | 80 | | |
78 | 81 | | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
79 | 116 | | |
80 | 117 | | |
81 | 118 | | |
82 | 119 | | |
83 | 120 | | |
84 | 121 | | |
85 | 122 | | |
86 | | - | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
87 | 126 | | |
88 | 127 | | |
89 | 128 | | |
90 | 129 | | |
91 | 130 | | |
92 | 131 | | |
93 | | - | |
94 | | - | |
95 | | - | |
96 | | - | |
97 | | - | |
98 | | - | |
99 | | - | |
100 | | - | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
101 | 138 | | |
102 | 139 | | |
103 | 140 | | |
| |||
0 commit comments