@@ -57,11 +57,6 @@ and `vendor` (committed patched packages), with `list` for inspection. See the
5757 ` vendor ` , the unimplemented ` --one-off ` flags, and the three legacy
5858 ` SOCKET_PATCH_* ` environment aliases listed in the migration guide.
5959 ` .socket/packages/ ` archives are no longer consumed; cleanup removes leftovers.
60- - Hosted mode wires Gradle builds instead of printing a snippet. ` scan --mode hosted `
61- (the default) now writes ` .socket/gradle/ ` (an owned settings script and its
62- index), an apply line in each build's settings file, the patched GA's lock
63- entries and an existing ` gradle/verification-metadata.xml ` . Commit them with the
64- build. ` redirect_gradle_manual_snippet ` is only emitted after a refusal.
6560- ` list ` on an empty project exits 0; ` get ` usage errors exit 2. Human help and
6661 output are grouped by task, with diagnostic codes retained in JSON and verbose
6762 output. Hosted JSON identifies lockfiles instead of a ledger; rollback's
@@ -81,25 +76,6 @@ and `vendor` (committed patched packages), with `list` for inspection. See the
8176 existing verification metadata. ` vendor --check ` audits artifacts and wiring
8277 offline; ` --local-repo ` checks Maven cache conflicts and ` --maven-config=none `
8378 selects the fallback file repository. Single-POM vendoring is unchanged.
84- - Gradle 6.8+ in every mode, Groovy and Kotlin DSL, tested on Gradle 6.9.4, 7.6.6,
85- 8.14.3 and 9.8.0 on macOS.
86- - ` scan ` reads Gradle's cache, and the read-only cache, and resolves the Gradle
87- user home the way the JVM does. It reads ` ~/.m2 ` for a Gradle-only build only
88- when the build declares ` mavenLocal() ` . JSON marks lock membership (` inLock ` ).
89- - Agent mode patches every copy a build consumes and swaps whole jars for
90- jar-member records. It refuses builds with dependency verification and reports
91- read-only cache shadowing, stale transform copies and Windows daemon locks.
92- - Hosted mode adds an owned settings script that substitutes, rejects and trips
93- on the unpatched base version (higher upstream versions still resolve). It also
94- rewrites lock files and verification metadata, refuses what it cannot pin, and
95- restores without the network. It uses the suffixed Gradle module metadata when
96- the patch service serves it, and warns
97- ` redirect_gradle_module_metadata_unavailable ` when it does not.
98- - VEX re-hashes every copy, Gradle hash directories and derived caches included,
99- before it attests.
100-
101- New codes are listed in [ CLI_CONTRACT.md] ( crates/socket-patch-cli/CLI_CONTRACT.md#gradle-builds-v50 ) ;
102- see [ Gradle] ( docs/ecosystems.md#gradle ) .
10379- ` socket.yml ` patch policy for paths, ecosystems, packages, severity, and per-run
10480 limits. ` scan --package ` , ` --min-severity ` , ` --max-new-patches ` , and
10581 ` --no-socket-yml ` support targeted and gradual rollout. Already-patched packages
@@ -126,30 +102,6 @@ limits, and required install commands.
126102
127103### Fixed
128104
129- - ` scan ` reported success with 0 packages on a resolved Gradle project because it
130- never read Gradle's cache (#349 ).
131- - Agent ` apply ` in a Gradle-only project patched the ` ~/.m2 ` copy Gradle never
132- reads, and VEX attested it. It now patches the Gradle cache copies the build
133- loads and refuses an ` ~/.m2 ` -only install (` gradle_build_ignores_m2 ` ) (#551 ).
134- Records keyed by jar members, which ` vendor ` already accepted, now apply in agent
135- mode (#264 ).
136- - Hosted Gradle was not fail-closed. A transitive request for the base version won
137- conflict resolution (#347 ), the snippet was always Groovy (#348 ), and dependency
138- locking built the unpatched jar on every Gradle major (#396 ). The owned hosted
139- script and lock rewrites replace the snippet.
140- - Vendored Gradle fixes:
141- - A root with both ` pom.xml ` and a Gradle build now wires both instead of leaving
142- the Gradle build unpatched (#395 ).
143- - Running from a subproject is refused (` not_build_root ` ) instead of wiring a
144- nested settings file (#428 ).
145- - ` core.autocrlf ` checkouts pass ` --check ` and revert cleanly (#429 ).
146- - ` exclusiveContent ` conflicts in subproject scripts and convention plugins are
147- refused (#461 ).
148- - pgp-only verification entries get a checksum (#487 ).
149- - Version ranges keep resolving the vendored version through a derived
150- ` maven-metadata.xml ` (#511 ).
151- - Declared classifier jars are vendored or refused, and IDE sources are kept
152- (#533 ).
153105- Global mode (` -g ` ) finds npm, yarn, pnpm, bun, RubyGems and Composer on
154106 Windows, where they install as ` .cmd ` / ` .bat ` shims, instead of reporting
155107 an empty scan. The yarn and npm-family global lookups no longer run from the
0 commit comments