@@ -127,14 +127,37 @@ and `vendor` (committed patched packages), with `list` for inspection. See the
127127 lockfile no longer points at a vendored entry in any ecosystem, not just
128128 Maven/Gradle, and reports lockfile references to ` .socket/vendor/ ` that no
129129 ledger entry owns as ` vendor_ledger_missing ` (#725 , #831 ).
130+ - Single-module Maven projects are vendored like reactors: the dependency is
131+ pinned to ` <version>-socket.<hex8> ` and served from a committed
132+ ` .socket/vendor/maven2/ ` tree, with ` .mvn/maven.config ` and a fallback
133+ ` socket-patch-vendor ` repository, replacing the same-version
134+ ` <repository> ` wiring and ` .socket/vendor/maven/<uuid>/ ` . A project
135+ vendored by an earlier release is refused with
136+ ` vendor_jvm_shape_unsupported ` (reason ` legacy_maven_root ` ) and nothing
137+ is written; run ` vendor --revert ` , then vendor again. ` remove ` ,
138+ ` rollback ` and hosted takeover still unwind the old wiring. VEX attests
139+ the new pin from ` .socket/vendor/state.json ` , so commit it. Without a
140+ Maven Wrapper, vendoring warns ` vendor_jvm_degraded ` ; several
141+ ` vendor_maven_* ` codes and ` vendor_gradle_unsupported ` are retired (see
142+ the migration guide) (#973 ).
143+ - A token whose organization cannot be resolved (no ` --org ` ,
144+ ` SOCKET_ORG_SLUG ` or socket-cli ` defaultOrg ` , and
145+ ` GET /v0/organizations ` fails) no longer queries ` /v0/orgs/default/… `
146+ while downloads go to the public proxy. The org is resolved once per run
147+ and the whole run uses the public proxy anonymously (free patches only),
148+ warning once; ` --json ` output of ` scan ` , ` get ` , ` apply ` , ` vendor ` , ` vex `
149+ and ` repair ` reports it as ` api_auth_fallback ` in ` warnings[] ` . An
150+ embedded ` --vex ` reuses the run's org instead of resolving it again
151+ (#648 ).
130152
131153### Added
132154
133155- Vendored Maven reactors, with committed repositories, reversible wiring,
134156 repair, rollback, and VEX. Reactors use suffixed versions; ` vendor --check `
135157 audits artifacts and wiring offline; ` --local-repo ` checks Maven cache
136158 conflicts and ` --maven-config=none ` selects the fallback file repository.
137- Single-POM vendoring is unchanged.
159+ Single-module ` pom.xml ` projects are vendored the same way, as a reactor
160+ of one (#973 ).
138161- Full Gradle support (6.8+, Groovy and Kotlin DSL; tested on 6.9 through 9.8)
139162 in every mode (#646 ):
140163 - Discovery reads Gradle's ` files-2.1 ` cache and ` GRADLE_RO_DEP_CACHE ` ,
@@ -411,6 +434,10 @@ limits, and required install commands.
411434 everywhere, so ` scan --prune ` no longer drops a live NuGet entry whose API
412435 and installed spellings differ, and ` remove ` /` rollback ` accept either
413436 spelling. Policy and rollout reports show the folded spelling (#1045 ).
437+ NuGet versions are also normalized (` 1.0.0.0 ` matches ` 1.0.0 ` ), so a
438+ package vendored under a 4-part ` packages.config ` version is no longer
439+ treated as unused by VEX and ` vendor --check ` , or reverted by
440+ ` scan --prune ` (#1202 ).
414441- Yarn classic ` file: ` , URL and hosted-git copies are no longer repointed at
415442 Socket's registry artifact (hosted or vendored); they are skipped with a
416443 stays-unpatched warning, and rollback refuses such a pin from an older
@@ -550,6 +577,42 @@ limits, and required install commands.
550577 - Vendoring a scoped package into a pnpm 7/8 lock quotes its ` name: ` , and a
551578 re-vendor fixes locks written by earlier releases (#956 ). Quoted scoped
552579 aliases are refused like unscoped ones (#957 ).
580+ - Hosted scans pin the per-member locks of a
581+ ` sharedWorkspaceLockfile: false ` workspace from the workspace root
582+ instead of reporting success with nothing pinned, and ` list ` , ` vex ` ,
583+ ` rollback ` and ` remove ` see those pins; an unlistable member set is
584+ refused with ` redirect_pnpm_member_locks_unresolved ` (#492 ). With
585+ ` gitBranchLockfile ` on and a ` pnpm-lock.<branch>.yaml ` present, hosted
586+ and vendored modes refuse (` redirect_pnpm_git_branch_lockfile ` /
587+ ` vendor_pnpm_git_branch_lockfile ` ) instead of pinning the stale
588+ ` pnpm-lock.yaml ` (#556 ).
589+ - A project under an ancestor ` pnpm-workspace.yaml ` whose ` packages: `
590+ globs do not list it (dot directories included) is patched standalone
591+ again instead of being refused as a member (#1006 ). On pnpm 9.0–10.4,
592+ where it would break ` pnpm add ` , the root-only ` pnpm-workspace.yaml `
593+ scaffold is no longer created (#734 ).
594+ - Rush: hosted runs on pnpm 11+ give a Rush-specific trust remedy
595+ (` pnpm_config_trust_lockfile=true rush install ` ,
596+ ` usePnpmFrozenLockfileForRushInstall ` ), re-issued on a re-run, and warn
597+ ` redirect_rush_repo_state_stale ` for subspace ` repo-state.json ` files
598+ (#713 , #714 ).
599+ - Hosted rollback and remove restore each entry from the registry the
600+ project resolves it against (` .npmrc ` ` registry ` / ` @scope:registry `
601+ and ` pnpm-workspace.yaml ` ` registry ` / ` registries ` , per pnpm major),
602+ and write ` tarball: ` fields only when the installed pnpm would, warning
603+ ` upstream_pnpm_tarball_setting_guessed ` when that is unknown (#919 ,
604+ #902 ).
605+ - Vendoring accepts a user's exact-version pin in ` pnpm-workspace.yaml `
606+ ` overrides: ` (quoted or commented too), edits only the project document
607+ of a pnpm 11+ two-document lock (others are refused with
608+ ` vendor_pnpm_lock_multi_document ` ), and reverting a vendored package no
609+ longer clobbers a vendored dependency's ref inside it (#854 , #466 ,
610+ #830 ). ` scan ` /` get --mode vendored --dry-run ` preview a refused
611+ hosted-to-vendored takeover as ` would_refuse ` (#853 ).
612+ - Agent mode: ` scan --mode agent <member-path> ` finds the member's linked
613+ copies (#778 ), ` apply ` and ` rollback ` no longer report a member-linked
614+ package twice (#633 ), and global scans of pnpm 11+ patch every
615+ ` pnpm add -g ` install's copy, not just one (#435 ).
553616- PyPI:
554617 - ` requirements.txt ` includes are followed the way pip reads them: ` -r ` after
555618 other options, quoted paths, ` ${VAR} ` expansion and UTF-16/BOM files
@@ -560,6 +623,18 @@ limits, and required install commands.
560623 skipped as absent by lock-only scans, and a UTF-16 export beside
561624 ` uv.lock ` is seen by vendored routing, ` vendor --check ` and ` vex `
562625 instead of being attested over (#1119 , #1120 ).
626+ - A plain-ASCII ` requirements.txt ` whose coding line names any
627+ ASCII-compatible codec Python knows (` iso-8859-15 ` , ` cp1250 ` ,
628+ ` mac-roman ` , ` gbk ` , …) is read instead of treated as unreadable, so
629+ scans no longer find nothing and ` vex ` and ` rollback ` see its hosted
630+ pins (#1212 ).
631+ - Pipenv projects with ` use_pylock = true ` are wired through
632+ ` Pipfile.lock ` , which Pipenv installs from, instead of ` pylock.toml ` ,
633+ and a pylock-only Pipenv checkout is refused
634+ (` redirect_pipenv_pylock_unsupported ` /
635+ ` pypi_pipenv_pylock_unsupported ` ) and not attested, instead of
636+ reporting success while ` pipenv sync ` installs the original release
637+ (#912 , #1122 ).
563638 - Hosted mode withholds platform-, ABI- and interpreter-bound wheels
564639 (` cp311-none-any ` , manylinux) from cross-platform locks with
565640 ` redirect_pypi_platform_wheel ` ; vendored mode gives ` vendor_platform_locked `
@@ -584,14 +659,14 @@ limits, and required install commands.
584659 4.0.19+ no longer fail with "Your lockfile needs to be updated"; locks
585660 left out of order by earlier runs are healed on the next scan (#1186 ).
586661- Project-mode crawls of a Cargo project with a ` Cargo.lock ` , a Go module
587- with a ` go.sum ` (and no ` go.work ` in effect), or a restored .NET project
588- (` obj/project.assets.json ` ) look up only the packages that project
589- resolves instead of walking the whole shared ` $CARGO_HOME ` registry,
590- ` GOMODCACHE ` or ` ~/.nuget/packages ` cache, so agent mode no longer
591- patches, and VEX no longer attests, packages other projects downloaded.
592- Projects without a readable lock or restore, Go workspaces, ` vendor/ `
593- trees, solution roots and global mode keep the full walk ( # 1204 , # 1207 ,
594- # 427 ).
662+ with a ` go.sum ` (and no ` go.work ` in effect), a restored .NET project
663+ (` obj/project.assets.json ` ) or a Deno project with a ` deno.lock ` look up
664+ only the packages that project resolves instead of walking the whole
665+ shared ` $CARGO_HOME ` registry, ` GOMODCACHE ` , ` ~/.nuget/packages ` or JSR
666+ cache, so scan and agent mode no longer patch, and VEX no longer
667+ attests, packages other projects downloaded. Projects without a readable
668+ lock or restore, Go workspaces, ` vendor/ ` trees, solution roots and
669+ global mode keep the full walk ( # 1204 , # 1207 , # 427 , # 1216 ).
595670- ` scan --mode agent --json ` and ` get --json ` report files whose contents
596671 matched neither patch hash and were overwritten, as
597672 ` content_mismatch_overwritten ` entries in ` warnings[] ` , as ` apply --json `
@@ -628,6 +703,8 @@ limits, and required install commands.
628703 - Hosted rollback/remove of Yarn Berry and vlt pins restore from the
629704 project's own registry (` npmRegistryServer ` , the vlt node's registry),
630705 falling back to the default with ` upstream_registry_fallback ` (#908 , #521 ).
706+ The warning no longer includes ` user:token@ ` credentials from the
707+ registry URL.
631708 - Vendored npm-family tarballs are protected from ` .gitignore ` rules such as
632709 ` *.tgz ` ; a vendor dir git would still ignore is refused up front with
633710 ` vendor_artifact_gitignored ` (#831 ).
0 commit comments