Skip to content

Commit 3deae85

Browse files
mikolalysenkoclaude
andcommitted
Drop CHANGELOG entry from this PR
Release notes are written when a release is cut, from the merged PR log and the code, so PRs no longer edit CHANGELOG.md. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
1 parent 3bd1e36 commit 3deae85

1 file changed

Lines changed: 0 additions & 48 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 0 additions & 48 deletions
Original file line numberDiff line numberDiff line change
@@ -57,11 +57,6 @@ and `vendor` (committed patched packages), with `list` for inspection. See the
5757
`vendor`, the unimplemented `--one-off` flags, and the three legacy
5858
`SOCKET_PATCH_*` environment aliases listed in the migration guide.
5959
`.socket/packages/` archives are no longer consumed; cleanup removes leftovers.
60-
- Hosted mode wires Gradle builds instead of printing a snippet. `scan --mode hosted`
61-
(the default) now writes `.socket/gradle/` (an owned settings script and its
62-
index), an apply line in each build's settings file, the patched GA's lock
63-
entries and an existing `gradle/verification-metadata.xml`. Commit them with the
64-
build. `redirect_gradle_manual_snippet` is only emitted after a refusal.
6560
- `list` on an empty project exits 0; `get` usage errors exit 2. Human help and
6661
output are grouped by task, with diagnostic codes retained in JSON and verbose
6762
output. Hosted JSON identifies lockfiles instead of a ledger; rollback's
@@ -81,25 +76,6 @@ and `vendor` (committed patched packages), with `list` for inspection. See the
8176
existing verification metadata. `vendor --check` audits artifacts and wiring
8277
offline; `--local-repo` checks Maven cache conflicts and `--maven-config=none`
8378
selects the fallback file repository. Single-POM vendoring is unchanged.
84-
- Gradle 6.8+ in every mode, Groovy and Kotlin DSL, tested on Gradle 6.9.4, 7.6.6,
85-
8.14.3 and 9.8.0 on macOS.
86-
- `scan` reads Gradle's cache, and the read-only cache, and resolves the Gradle
87-
user home the way the JVM does. It reads `~/.m2` for a Gradle-only build only
88-
when the build declares `mavenLocal()`. JSON marks lock membership (`inLock`).
89-
- Agent mode patches every copy a build consumes and swaps whole jars for
90-
jar-member records. It refuses builds with dependency verification and reports
91-
read-only cache shadowing, stale transform copies and Windows daemon locks.
92-
- Hosted mode adds an owned settings script that substitutes, rejects and trips
93-
on the unpatched base version (higher upstream versions still resolve). It also
94-
rewrites lock files and verification metadata, refuses what it cannot pin, and
95-
restores without the network. It uses the suffixed Gradle module metadata when
96-
the patch service serves it, and warns
97-
`redirect_gradle_module_metadata_unavailable` when it does not.
98-
- VEX re-hashes every copy, Gradle hash directories and derived caches included,
99-
before it attests.
100-
101-
New codes are listed in [CLI_CONTRACT.md](crates/socket-patch-cli/CLI_CONTRACT.md#gradle-builds-v50);
102-
see [Gradle](docs/ecosystems.md#gradle).
10379
- `socket.yml` patch policy for paths, ecosystems, packages, severity, and per-run
10480
limits. `scan --package`, `--min-severity`, `--max-new-patches`, and
10581
`--no-socket-yml` support targeted and gradual rollout. Already-patched packages
@@ -126,30 +102,6 @@ limits, and required install commands.
126102

127103
### Fixed
128104

129-
- `scan` reported success with 0 packages on a resolved Gradle project because it
130-
never read Gradle's cache (#349).
131-
- Agent `apply` in a Gradle-only project patched the `~/.m2` copy Gradle never
132-
reads, and VEX attested it. It now patches the Gradle cache copies the build
133-
loads and refuses an `~/.m2`-only install (`gradle_build_ignores_m2`) (#551).
134-
Records keyed by jar members, which `vendor` already accepted, now apply in agent
135-
mode (#264).
136-
- Hosted Gradle was not fail-closed. A transitive request for the base version won
137-
conflict resolution (#347), the snippet was always Groovy (#348), and dependency
138-
locking built the unpatched jar on every Gradle major (#396). The owned hosted
139-
script and lock rewrites replace the snippet.
140-
- Vendored Gradle fixes:
141-
- A root with both `pom.xml` and a Gradle build now wires both instead of leaving
142-
the Gradle build unpatched (#395).
143-
- Running from a subproject is refused (`not_build_root`) instead of wiring a
144-
nested settings file (#428).
145-
- `core.autocrlf` checkouts pass `--check` and revert cleanly (#429).
146-
- `exclusiveContent` conflicts in subproject scripts and convention plugins are
147-
refused (#461).
148-
- pgp-only verification entries get a checksum (#487).
149-
- Version ranges keep resolving the vendored version through a derived
150-
`maven-metadata.xml` (#511).
151-
- Declared classifier jars are vendored or refused, and IDE sources are kept
152-
(#533).
153105
- Global mode (`-g`) finds npm, yarn, pnpm, bun, RubyGems and Composer on
154106
Windows, where they install as `.cmd` / `.bat` shims, instead of reporting
155107
an empty scan. The yarn and npm-family global lookups no longer run from the

0 commit comments

Comments
 (0)