Skip to content

Commit dce7d1a

Browse files
committed
Merge origin/main to resolve CHANGELOG conflict
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KKwBoKTsqpGR3ZcCAcEyCA
2 parents 96097f3 + d63ae5f commit dce7d1a

36 files changed

Lines changed: 4144 additions & 317 deletions

‎.github/workflows/ci.yml‎

Lines changed: 37 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -261,24 +261,47 @@ jobs:
261261
cache: false
262262

263263
- name: Install vexctl
264-
# `go install` puts the binary in $(go env GOPATH)/bin; surface
265-
# that path to subsequent steps so `Command::new("vexctl")` in
266-
# the test resolves. Pinned to a tagged release rather than
267-
# @latest for reproducibility.
264+
# Linux / Windows: the v0.3.0 release binary, checked against the
265+
# sha256 pinned here (from the release's vexctl_checksums.txt).
266+
# Compiling it took ~80s on ubuntu and ~180s on windows, the
267+
# slowest job in this workflow.
268268
#
269-
# Retried: the install compiles sigstore/cosign, whose module
270-
# verification reads dozens of sum.golang.org checksum tiles, and
271-
# transient INTERNAL_ERROR stream resets there have failed this
272-
# step on otherwise-green runs. The backoff rides out short
273-
# resets; a persistent outage still fails loudly on the last
274-
# attempt. Follow-up option if this recurs: install the pinned
275-
# release BINARY (sha256-pinned) instead of compiling, which
276-
# sidesteps module verification and drops ~100s of compile time per
277-
# leg.
269+
# macOS still compiles: the release's darwin binaries are built
270+
# with go1.22.7 and have no LC_UUID, so the runner's dyld refuses
271+
# them (see the Go step above). The compile is retried: it builds
272+
# sigstore/cosign, whose module verification reads dozens of
273+
# sum.golang.org checksum tiles, and transient INTERNAL_ERROR
274+
# stream resets there have failed this step on otherwise-green
275+
# runs. The backoff rides out short resets; a persistent outage
276+
# still fails loudly on the last attempt.
277+
#
278+
# Either way the binary's directory goes on PATH so
279+
# `Command::new("vexctl")` in the tests resolves.
278280
shell: bash
281+
env:
282+
VEXCTL_VERSION: v0.3.0
283+
VEXCTL_SHA256_LINUX_AMD64: cd7f8b57d20642166ed4eb3dd1fd849bbb30bbd7c5b9f5b0316b6003b57ceaba
284+
VEXCTL_SHA256_WINDOWS_AMD64: 346fb3104b656fe1a407cbae88ea29a636b36f4569ec58a5a8dadca7343993ed
279285
run: |
286+
set -euo pipefail
287+
case "$RUNNER_OS" in
288+
Linux) asset=vexctl-linux-amd64 bin=vexctl sha="$VEXCTL_SHA256_LINUX_AMD64" ;;
289+
Windows) asset=vexctl-windows-amd64.exe bin=vexctl.exe sha="$VEXCTL_SHA256_WINDOWS_AMD64" ;;
290+
*) asset='' ;;
291+
esac
292+
if [ -n "$asset" ]; then
293+
dir="$RUNNER_TEMP/vexctl-bin"
294+
mkdir -p "$dir"
295+
curl -fsSL --retry 5 --retry-all-errors -o "$dir/$bin" \
296+
"https://github.com/openvex/vexctl/releases/download/$VEXCTL_VERSION/$asset"
297+
echo "$sha $dir/$bin" | sha256sum -c -
298+
chmod +x "$dir/$bin"
299+
"$dir/$bin" version
300+
echo "$dir" >> "$GITHUB_PATH"
301+
exit 0
302+
fi
280303
for attempt in 1 2 3 4 5; do
281-
if go install github.com/openvex/vexctl@v0.3.0; then
304+
if go install "github.com/openvex/vexctl@$VEXCTL_VERSION"; then
282305
break
283306
fi
284307
if [ "$attempt" = 5 ]; then

‎CHANGELOG.md‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -108,6 +108,11 @@ limits, and required install commands.
108108
scanned project, so a Yarn Berry project's `global` script can't run or pick
109109
the directory treated as the global install. Composer's global home also
110110
falls back to `%APPDATA%\Composer` and `$XDG_CONFIG_HOME/composer`.
111+
- Agent-mode PyPI `apply` patches every installed copy of a release, not just
112+
the first one found. A Pipenv project with both a WORKON_HOME venv and a
113+
`./.venv`, or a global install with the same release in the user site and a
114+
system dir, no longer keeps the copy Python imports unpatched while `vex`
115+
attests it (#529, #501).
111116
- Gem hosted and vendored modes wire only the manifest Bundler loads. A `gems.rb`
112117
twin or a `BUNDLE_GEMFILE` setting (environment or `.bundle/config`) no longer
113118
leads to an edit of an ignored `Gemfile` that reports success and attests an
@@ -175,6 +180,11 @@ limits, and required install commands.
175180
- Transient apply locks are removed on normal command exit; no-op scans and full
176181
reversal avoid leaving unused `.socket/` state. Terminal output, telemetry
177182
timeouts, and update-check handling are more consistent.
183+
- Agent mode finds transitive npm packages in npm's linked store
184+
(`install-strategy=linked`, `node_modules/.store`) and in a relocated pnpm
185+
`virtualStoreDir`, instead of reporting them `package_not_installed` (#359,
186+
#362). A store outside the project, such as pnpm's global virtual store, is
187+
shared with other projects and is still not patched in place.
178188
- npm locks keep their own layout when edited. `scan --mode hosted`,
179189
`scan --mode vendored`, `rollback` and `vendor --revert`
180190
re-serialized `package-lock.json` / `npm-shrinkwrap.json` with LF line
@@ -184,6 +194,13 @@ limits, and required install commands.
184194
unparseable (hosted) or refused as `vendor_lockfile_version_unsupported`
185195
(vendored). The lock now keeps its BOM, indent and line endings, and the
186196
undo is byte-exact (#324).
197+
- `vendor` under `--global` / `--global-prefix` (or `SOCKET_GLOBAL` /
198+
`SOCKET_GLOBAL_PREFIX`) is now a usage error (exit 2,
199+
`global_scope_unsupported`), like `scan` and `get` with `--mode vendored`.
200+
Run inside a project, `vendor -g` vendored the manifest's records into that
201+
project and rewired its lockfile, and `vendor --revert -g` unwound the
202+
project's vendoring, so its next frozen install was silently unpatched.
203+
Global installs have no project lockfile to vendor into (#498).
187204

188205
### Maintenance
189206

0 commit comments

Comments
 (0)