You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 369535c
Browse filesBrowse the repository at this point in the historyBrowse files
- Merged since the last entry: none of this routine's PRs. No register or doc rewrites needed. No `arch-refactor/*` PR was abandoned: every open one is `ready`.
5
+
- Ranking: 25 open `arch-refactor/*` / `agent/fix-*` / `arch-fix/*` / `ci*` PRs change 645 files, and #1126 alone covers most of `vex/discover/`, the crawlers and `vendor/`. #989, the manifest-load cluster, #717 and #1220 are still skipped. #1129 (E92) is blocked by `npm_crawler.rs` (#1007, #1009, #1126). #1202 (E93) won among free files (B 1, U 1, D 1, R L): `utils/purl_key.rs` is free, and the normalizer can be imported from `nuget_feed.rs` without editing it.
6
+
- PR: [#1230](https://github.com/SocketDev/socket-patch/pull/1230), `state: ready`, Bugbot requested. Production +37/−7, tests +242/−1. Clippy is clean. Core lib: 5890 passed, plus the 4 known root-only failures. Red→green: the 3 new tests fail with `main`'s rule. `in_process_scan` 27, `in_process_vendor` 130, `e2e_vex_redirect` 31 and `in_process_remote_ecosystems_apply` 12 passed.
7
+
- Claimed: #1202 (`PurlKey` slice; PR says `Refs`, so the issue stays open). Released: none.
8
+
- Register: E93 → in PR #1230 (`PurlKey` slice). The crawler directory lookup and the move to `formats::nuget` remain.
9
+
- Lessons: `test_support::service_fixture` builds a NuGet grant from `<id>.<purl version>.nupkg`, so a test that vendors a non-normalized version needs that file next to the normalized cache copy.
| E90 | 2 | Which gem homes Bundler loads has two answers: `vex` and agent `apply` use `get_gem_paths` (keeps `gem env` homes under an explicit `path`), only the stale guard uses `bundler_install_homes` (executed twice). | new finding |#1098| filed #1098|
88
88
| E91 | 3 | PyPI tool-lock precedence is written twice since #1044: the inventory keys on "yielded entries", the vendored router on presence. A package-less `poetry.lock`/`pdm.lock` beside `requirements.txt` makes scan offer a package vendored refuses (`pypi_poetry_lock_package_missing`; executed twice). | new finding |#1114| filed #1114|
89
89
| E92 | 3 | pnpm `modulesDir` is honored by the crawler but not by `pkg_managers`: `node-linker=pnp` + `modulesDir` is classified yarn PnP, so apply refuses (`yarn_pnp_unsupported`), vendored gives the yarn remedy and VEX reads the wrong loader (real pnpm 10.28, executed twice). | new finding |#1129| filed #1129|
90
-
| E93 | 3 | NuGet version identity: vendor normalizes (`normalize_nuget_version`), `PurlKey`/crawler only lowercase; a vendored `@13.0.3.0` is judged unused, so `scan --prune` reverts it (executed 3×). | new finding |#1202|filed #1202|
90
+
| E93 | 3 | NuGet version identity: vendor normalizes (`normalize_nuget_version`), `PurlKey`/crawler only lowercase; a vendored `@13.0.3.0` is judged unused, so `scan --prune` reverts it (executed 3×). | new finding |#1202|in PR #1230 (`PurlKey` slice; crawler lookup and the move to `formats::nuget` remain)|
-[#1230](https://github.com/SocketDev/socket-patch/pull/1230): `PurlKey` keys NuGet versions through the one `normalize_nuget_version` (`13.0.3.0` = `13.0.3`), so a vendored 4-part entry stays live for VEX, `vendor --check` and `scan --prune`. #1202 slice (E93). +37/−7 prod, +242/−1 tests. `state: ready`.
5
6
-[#1227](https://github.com/SocketDev/socket-patch/pull/1227): `common::detect_eol`, `pypi_uv::newline_of` and the `.npmrc` splice through `line_endings::terminator`. #815 slice 2 (E16). +25/−44 prod, +93 tests; golang golden re-blessed (mixed go.sum inputs only). `state: ready`.
**Queue** (B bugs closed, U unblocks, D duplication removed, R risk; score = 3B + 2U + 2D + S − risk). Since the 2026-10-08 backlog review, standalone refactor issues are closed as `not_planned` and kept as checklist items of their tracker; rank the tracker's next unchecked item.
| 1 |#989 item: one `vendor::revert::finish` for the 12 copied finish blocks | 0 | 1 | ≈12 | L | ≈26 | skipped: every backend file is in an open PR (#1007, #1009, #1026, #1036, #1041, #1161, #1187, #1193, #1211) |
26
24
| 2 |#931 + #998 + #1063 + #1123: one manifest load + error mapper for every command | 4 | 1 | ≈6 | M | ≈24 | skipped: `apply.rs`, `vendor.rs`, `repair.rs`, `remove.rs`, `rollback.rs`, `scan/`, `ledgers.rs`, `args.rs` all in open PRs |
| 4 |#815 (E16) slice 2: `detect_eol` + uv `newline_of` → `terminator`|0|1| ≈3| L | ≈8|**taken: #1227**; maven_reactor (#1036), `redirect/mod.rs`, upstream gem and the Gradle first-line rule remain|
29
-
| 5 |#1220 (C78): bound upstream-restore fan-out through `utils::concurrent::registry_concurrency`| 1 |0| ≈4| L | ≈11|skipped: `upstream/{npm,pypi,cargo,composer,mod}.rs`and `concurrent.rs` in open PRs|
26
+
| 4 |#1220 (C78): bound upstream-restore fan-out through `utils::concurrent::registry_concurrency`|1|0| ≈4| L | ≈11|skipped: `upstream/{npm,pypi,cargo,composer,mod}.rs`and `concurrent.rs` in open PRs|
27
+
| 5 |#1202 (E93): `PurlKey` NuGet identity through `normalize_nuget_version`| 1 |1| ≈1| L | ≈7|**taken: #1230**; crawler directory lookup (`nuget_crawler.rs`, #1126) and the move to `formats::nuget` (`nuget_feed.rs`, #1041/#1126) remain|
30
28
31
-
Re-ranked 2026-10-09T05:00Z at `f3c6313` against 19`arch-refactor/*` / `agent/fix-*` / `arch-fix/*` PRs changing 346 files; #914 skipped (`jvm_jar.rs` in #1041), #1144 (`vex.rs` in #1041). Free but lower: E16 remainder (`detect_eol` caller in `yarn_classic_lock.rs`, #1211), #1202 (`nuget_feed.rs` in #1041),#1014 (`.mill-version` needs a decision), #265 Maven crawl (no lockfile to scope by: risk H), E37 (`composer_crawler::normalize_version` ≡ `strip_leading_v`, D 1).
29
+
Re-ranked 2026-10-09T06:00Z at `f3c6313` against 25`arch-refactor/*` / `agent/fix-*` / `arch-fix/*` PRs (and `ci*`) changing 645 files; #914 skipped (`jvm_jar.rs` in #1041), #1144 (`vex.rs` in #1041). Free but lower: #1014 (`.mill-version` needs a decision), #265 Maven crawl (no lockfile to scope by: risk H), E37 (`composer_crawler::normalize_version` ≡ `strip_leading_v`, D 1).
32
30
33
31
**Notes:**
34
32
-`bench.yml` gates +10% per scenario: time a per-dep reader (hosted converge) in release against `main` before pushing.
@@ -51,6 +49,7 @@ Re-ranked 2026-10-09T05:00Z at `f3c6313` against 19 `arch-refactor/*` / `agent/f
51
49
-`redirect/pipenv.rs`, `vendor/pypi.rs` and `vendor/lock_inventory/vlt.rs` aren't rustfmt-clean on main: format only your own hunks there. Check `rustfmt --check` on the `main` copy before formatting a whole file.
52
50
-`lock_inventory/mod.rs``architecture_tests` forbid `hosted_patch_uuid*` in a format file's model section. Origin-policy helpers go after the `// ── registry view ──` marker.
53
51
- 2026-10-08: ~40 refactor issues were closed `not_planned` into trackers ("Consolidated work"); that is scheduling, not rejection. Claim/`Fixes` the item's issue only if still open, else reference the tracker.
52
+
- NuGet identity (#1230): `PurlKey` folds versions through `vendor::nuget_feed::normalize_nuget_version` (a utils→vendor import until `nuget_feed.rs` frees for the `formats::nuget` move). `test_support::service_fixture` builds its NuGet grant from `<id>.<purl version>.nupkg`, so a test vendoring a non-normalized version needs that file too.
54
53
- Pushes need verified signatures: commit with the session's default git identity, never an overridden `user.email`.
55
54
- Steering (2026-10-02, #569/#571): no size caps on trusted upstream data; stream, don't buffer.
56
55
-`tests/spawn_env_hygiene.rs` allowlists (`PENDING_RAW_SPAWNS` / `PENDING_SCRUB_COPIES`) fail on new **and** stale entries: drop a file when you migrate it.
0 commit comments