@@ -108,6 +108,11 @@ limits, and required install commands.
108108 scanned project, so a Yarn Berry project's ` global ` script can't run or pick
109109 the directory treated as the global install. Composer's global home also
110110 falls back to ` %APPDATA%\Composer ` and ` $XDG_CONFIG_HOME/composer ` .
111+ - Agent-mode PyPI ` apply ` patches every installed copy of a release, not just
112+ the first one found. A Pipenv project with both a WORKON_HOME venv and a
113+ ` ./.venv ` , or a global install with the same release in the user site and a
114+ system dir, no longer keeps the copy Python imports unpatched while ` vex `
115+ attests it (#529 , #501 ).
111116- Gem hosted and vendored modes wire only the manifest Bundler loads. A ` gems.rb `
112117 twin or a ` BUNDLE_GEMFILE ` setting (environment or ` .bundle/config ` ) no longer
113118 leads to an edit of an ignored ` Gemfile ` that reports success and attests an
@@ -175,6 +180,11 @@ limits, and required install commands.
175180- Transient apply locks are removed on normal command exit; no-op scans and full
176181 reversal avoid leaving unused ` .socket/ ` state. Terminal output, telemetry
177182 timeouts, and update-check handling are more consistent.
183+ - Agent mode finds transitive npm packages in npm's linked store
184+ (` install-strategy=linked ` , ` node_modules/.store ` ) and in a relocated pnpm
185+ ` virtualStoreDir ` , instead of reporting them ` package_not_installed ` (#359 ,
186+ #362 ). A store outside the project, such as pnpm's global virtual store, is
187+ shared with other projects and is still not patched in place.
178188- npm locks keep their own layout when edited. ` scan --mode hosted ` ,
179189 ` scan --mode vendored ` , ` rollback ` and ` vendor --revert `
180190 re-serialized ` package-lock.json ` / ` npm-shrinkwrap.json ` with LF line
@@ -184,6 +194,13 @@ limits, and required install commands.
184194 unparseable (hosted) or refused as ` vendor_lockfile_version_unsupported `
185195 (vendored). The lock now keeps its BOM, indent and line endings, and the
186196 undo is byte-exact (#324 ).
197+ - ` vendor ` under ` --global ` / ` --global-prefix ` (or ` SOCKET_GLOBAL ` /
198+ ` SOCKET_GLOBAL_PREFIX ` ) is now a usage error (exit 2,
199+ ` global_scope_unsupported ` ), like ` scan ` and ` get ` with ` --mode vendored ` .
200+ Run inside a project, ` vendor -g ` vendored the manifest's records into that
201+ project and rewired its lockfile, and ` vendor --revert -g ` unwound the
202+ project's vendoring, so its next frozen install was silently unpatched.
203+ Global installs have no project lockfile to vendor into (#498 ).
187204
188205### Maintenance
189206
0 commit comments