Skip to content

Commit 75d69ae

Browse files
mikolalysenkoclaude
andcommitted
Add #1007, #1036, #1041, #1193, #1217, #1218 and #1230 to the 5.0.0 release notes
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
1 parent 5088d2a commit 75d69ae

1 file changed

Lines changed: 86 additions & 9 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 86 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -127,14 +127,37 @@ and `vendor` (committed patched packages), with `list` for inspection. See the
127127
lockfile no longer points at a vendored entry in any ecosystem, not just
128128
Maven/Gradle, and reports lockfile references to `.socket/vendor/` that no
129129
ledger entry owns as `vendor_ledger_missing` (#725, #831).
130+
- Single-module Maven projects are vendored like reactors: the dependency is
131+
pinned to `<version>-socket.<hex8>` and served from a committed
132+
`.socket/vendor/maven2/` tree, with `.mvn/maven.config` and a fallback
133+
`socket-patch-vendor` repository, replacing the same-version
134+
`<repository>` wiring and `.socket/vendor/maven/<uuid>/`. A project
135+
vendored by an earlier release is refused with
136+
`vendor_jvm_shape_unsupported` (reason `legacy_maven_root`) and nothing
137+
is written; run `vendor --revert`, then vendor again. `remove`,
138+
`rollback` and hosted takeover still unwind the old wiring. VEX attests
139+
the new pin from `.socket/vendor/state.json`, so commit it. Without a
140+
Maven Wrapper, vendoring warns `vendor_jvm_degraded`; several
141+
`vendor_maven_*` codes and `vendor_gradle_unsupported` are retired (see
142+
the migration guide) (#973).
143+
- A token whose organization cannot be resolved (no `--org`,
144+
`SOCKET_ORG_SLUG` or socket-cli `defaultOrg`, and
145+
`GET /v0/organizations` fails) no longer queries `/v0/orgs/default/…`
146+
while downloads go to the public proxy. The org is resolved once per run
147+
and the whole run uses the public proxy anonymously (free patches only),
148+
warning once; `--json` output of `scan`, `get`, `apply`, `vendor`, `vex`
149+
and `repair` reports it as `api_auth_fallback` in `warnings[]`. An
150+
embedded `--vex` reuses the run's org instead of resolving it again
151+
(#648).
130152

131153
### Added
132154

133155
- Vendored Maven reactors, with committed repositories, reversible wiring,
134156
repair, rollback, and VEX. Reactors use suffixed versions; `vendor --check`
135157
audits artifacts and wiring offline; `--local-repo` checks Maven cache
136158
conflicts and `--maven-config=none` selects the fallback file repository.
137-
Single-POM vendoring is unchanged.
159+
Single-module `pom.xml` projects are vendored the same way, as a reactor
160+
of one (#973).
138161
- Full Gradle support (6.8+, Groovy and Kotlin DSL; tested on 6.9 through 9.8)
139162
in every mode (#646):
140163
- Discovery reads Gradle's `files-2.1` cache and `GRADLE_RO_DEP_CACHE`,
@@ -411,6 +434,10 @@ limits, and required install commands.
411434
everywhere, so `scan --prune` no longer drops a live NuGet entry whose API
412435
and installed spellings differ, and `remove`/`rollback` accept either
413436
spelling. Policy and rollout reports show the folded spelling (#1045).
437+
NuGet versions are also normalized (`1.0.0.0` matches `1.0.0`), so a
438+
package vendored under a 4-part `packages.config` version is no longer
439+
treated as unused by VEX and `vendor --check`, or reverted by
440+
`scan --prune` (#1202).
414441
- Yarn classic `file:`, URL and hosted-git copies are no longer repointed at
415442
Socket's registry artifact (hosted or vendored); they are skipped with a
416443
stays-unpatched warning, and rollback refuses such a pin from an older
@@ -550,6 +577,42 @@ limits, and required install commands.
550577
- Vendoring a scoped package into a pnpm 7/8 lock quotes its `name:`, and a
551578
re-vendor fixes locks written by earlier releases (#956). Quoted scoped
552579
aliases are refused like unscoped ones (#957).
580+
- Hosted scans pin the per-member locks of a
581+
`sharedWorkspaceLockfile: false` workspace from the workspace root
582+
instead of reporting success with nothing pinned, and `list`, `vex`,
583+
`rollback` and `remove` see those pins; an unlistable member set is
584+
refused with `redirect_pnpm_member_locks_unresolved` (#492). With
585+
`gitBranchLockfile` on and a `pnpm-lock.<branch>.yaml` present, hosted
586+
and vendored modes refuse (`redirect_pnpm_git_branch_lockfile` /
587+
`vendor_pnpm_git_branch_lockfile`) instead of pinning the stale
588+
`pnpm-lock.yaml` (#556).
589+
- A project under an ancestor `pnpm-workspace.yaml` whose `packages:`
590+
globs do not list it (dot directories included) is patched standalone
591+
again instead of being refused as a member (#1006). On pnpm 9.0–10.4,
592+
where it would break `pnpm add`, the root-only `pnpm-workspace.yaml`
593+
scaffold is no longer created (#734).
594+
- Rush: hosted runs on pnpm 11+ give a Rush-specific trust remedy
595+
(`pnpm_config_trust_lockfile=true rush install`,
596+
`usePnpmFrozenLockfileForRushInstall`), re-issued on a re-run, and warn
597+
`redirect_rush_repo_state_stale` for subspace `repo-state.json` files
598+
(#713, #714).
599+
- Hosted rollback and remove restore each entry from the registry the
600+
project resolves it against (`.npmrc` `registry` / `@scope:registry`
601+
and `pnpm-workspace.yaml` `registry` / `registries`, per pnpm major),
602+
and write `tarball:` fields only when the installed pnpm would, warning
603+
`upstream_pnpm_tarball_setting_guessed` when that is unknown (#919,
604+
#902).
605+
- Vendoring accepts a user's exact-version pin in `pnpm-workspace.yaml`
606+
`overrides:` (quoted or commented too), edits only the project document
607+
of a pnpm 11+ two-document lock (others are refused with
608+
`vendor_pnpm_lock_multi_document`), and reverting a vendored package no
609+
longer clobbers a vendored dependency's ref inside it (#854, #466,
610+
#830). `scan`/`get --mode vendored --dry-run` preview a refused
611+
hosted-to-vendored takeover as `would_refuse` (#853).
612+
- Agent mode: `scan --mode agent <member-path>` finds the member's linked
613+
copies (#778), `apply` and `rollback` no longer report a member-linked
614+
package twice (#633), and global scans of pnpm 11+ patch every
615+
`pnpm add -g` install's copy, not just one (#435).
553616
- PyPI:
554617
- `requirements.txt` includes are followed the way pip reads them: `-r` after
555618
other options, quoted paths, `${VAR}` expansion and UTF-16/BOM files
@@ -560,6 +623,18 @@ limits, and required install commands.
560623
skipped as absent by lock-only scans, and a UTF-16 export beside
561624
`uv.lock` is seen by vendored routing, `vendor --check` and `vex`
562625
instead of being attested over (#1119, #1120).
626+
- A plain-ASCII `requirements.txt` whose coding line names any
627+
ASCII-compatible codec Python knows (`iso-8859-15`, `cp1250`,
628+
`mac-roman`, `gbk`, …) is read instead of treated as unreadable, so
629+
scans no longer find nothing and `vex` and `rollback` see its hosted
630+
pins (#1212).
631+
- Pipenv projects with `use_pylock = true` are wired through
632+
`Pipfile.lock`, which Pipenv installs from, instead of `pylock.toml`,
633+
and a pylock-only Pipenv checkout is refused
634+
(`redirect_pipenv_pylock_unsupported` /
635+
`pypi_pipenv_pylock_unsupported`) and not attested, instead of
636+
reporting success while `pipenv sync` installs the original release
637+
(#912, #1122).
563638
- Hosted mode withholds platform-, ABI- and interpreter-bound wheels
564639
(`cp311-none-any`, manylinux) from cross-platform locks with
565640
`redirect_pypi_platform_wheel`; vendored mode gives `vendor_platform_locked`
@@ -584,14 +659,14 @@ limits, and required install commands.
584659
4.0.19+ no longer fail with "Your lockfile needs to be updated"; locks
585660
left out of order by earlier runs are healed on the next scan (#1186).
586661
- Project-mode crawls of a Cargo project with a `Cargo.lock`, a Go module
587-
with a `go.sum` (and no `go.work` in effect), or a restored .NET project
588-
(`obj/project.assets.json`) look up only the packages that project
589-
resolves instead of walking the whole shared `$CARGO_HOME` registry,
590-
`GOMODCACHE` or `~/.nuget/packages` cache, so agent mode no longer
591-
patches, and VEX no longer attests, packages other projects downloaded.
592-
Projects without a readable lock or restore, Go workspaces, `vendor/`
593-
trees, solution roots and global mode keep the full walk (#1204, #1207,
594-
#427).
662+
with a `go.sum` (and no `go.work` in effect), a restored .NET project
663+
(`obj/project.assets.json`) or a Deno project with a `deno.lock` look up
664+
only the packages that project resolves instead of walking the whole
665+
shared `$CARGO_HOME` registry, `GOMODCACHE`, `~/.nuget/packages` or JSR
666+
cache, so scan and agent mode no longer patch, and VEX no longer
667+
attests, packages other projects downloaded. Projects without a readable
668+
lock or restore, Go workspaces, `vendor/` trees, solution roots and
669+
global mode keep the full walk (#1204, #1207, #427, #1216).
595670
- `scan --mode agent --json` and `get --json` report files whose contents
596671
matched neither patch hash and were overwritten, as
597672
`content_mismatch_overwritten` entries in `warnings[]`, as `apply --json`
@@ -628,6 +703,8 @@ limits, and required install commands.
628703
- Hosted rollback/remove of Yarn Berry and vlt pins restore from the
629704
project's own registry (`npmRegistryServer`, the vlt node's registry),
630705
falling back to the default with `upstream_registry_fallback` (#908, #521).
706+
The warning no longer includes `user:token@` credentials from the
707+
registry URL.
631708
- Vendored npm-family tarballs are protected from `.gitignore` rules such as
632709
`*.tgz`; a vendor dir git would still ignore is refused up front with
633710
`vendor_artifact_gitignored` (#831).

0 commit comments

Comments
 (0)