Skip to content

Commit fe293ed

Browse files
committed
Merge release/v5-prerelease (#296)
#296 drops DepOverride's berry_zip_url, so the goldens' input digests (which serialize the deps) are re-blessed: 1848 lines in 12 files change only their input digest, and every case key and output digest is unchanged, so the rewrites behave exactly as before. The two env-gated fixture tests #296 edited stay deleted here. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01N9YdJqaGiT9Jf5LN1hDFhB
2 parents 5e16953 + 1e3ace6 commit fe293ed

165 files changed

Lines changed: 3358 additions & 5365 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎CHANGELOG.md‎

Lines changed: 33 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -79,6 +79,33 @@ into the new version's section — see docs/releasing.md.
7979
`gem_setup` / `composer_setup` / `pth_hook` aliases are removed from
8080
`socket-patch-core`, along with the setup-only `npm_family` table column
8181
(`FileRow::detects_pnpm`) and `VLT_SETUP_MARKERS`.
82+
- **v3/v4 compatibility spellings are gone.**
83+
- The v3.0 legacy env names `SOCKET_PATCH_PROXY_URL`, `SOCKET_PATCH_DEBUG`
84+
and `SOCKET_PATCH_TELEMETRY_DISABLED` are no longer read and no longer
85+
print a deprecation warning. Use `SOCKET_PROXY_URL`, `SOCKET_DEBUG` and
86+
`SOCKET_TELEMETRY_DISABLED`.
87+
- The hidden `scan --redirect` flag (use `--mode hosted`) and the hidden
88+
no-op `scan --detached` flag (vendored mode is always manifest-free) are
89+
removed. Both are now unknown-flag usage errors (exit 2).
90+
- The hidden `--mode` values `host`, `redirect` and `vendor` on `scan` and
91+
`get` are rejected; only `hosted`, `vendored` and `agent` are accepted.
92+
The hidden `scan --apply` and `scan --vendor` spellings stay.
93+
- **`get --one-off` and `rollback --one-off`** (and `SOCKET_ONE_OFF`) are
94+
removed. They were never implemented and only failed with a usage error;
95+
`--one-off` is now an unknown-flag error (still exit 2) and
96+
`SOCKET_ONE_OFF` is ignored.
97+
- **`.socket/packages/` package archives are no longer read.** Nothing has
98+
written them for several releases. `apply`, `vendor` and `repair` stop
99+
probing and staging the directory, and `apply`'s JSON `appliedVia` loses
100+
its `"package"` value (`"diff"` or `"blob"` remain). The GC sweeps
101+
(`scan --prune`, `rollback`, `remove`, `repair`) delete any leftover
102+
`.socket/packages/` files whole (`rollback` and `scan --prune` still
103+
report them as `removedPackageArchives`).
104+
- **Core crate:** removed uncalled public helpers
105+
(`bun_lock::snapshot_binary_workspace_artifacts`, `vlt_lock_sniff_ok`,
106+
and several `lock_inventory::view` accessors) and the never-read
107+
`DepOverride::berry_zip_url` field (a `berryZipUrl` key in a patch
108+
reference still parses).
82109

83110
### Changed (BREAKING): patch UI streamlining
84111

@@ -96,10 +123,10 @@ into the new version's section — see docs/releasing.md.
96123
confirmation, in `--json` too (no `selection_required` outside agent
97124
mode). Agent-mode `get` keeps its picker and `Download and apply N
98125
patches?` prompt.
99-
- **`get` and `rollback` usage errors exit 2** (were 1): `get`'s
100-
`--id`/`--cve`/`--ghsa`/`--package` multi-select, `--one-off --save-only`,
101-
`--mode hosted|vendored --save-only`, `--one-off`, a malformed forced
102-
identifier, and `rollback --one-off`. Every usage error now exits 2.
126+
- **`get` usage errors exit 2** (were 1): `get`'s
127+
`--id`/`--cve`/`--ghsa`/`--package` multi-select,
128+
`--mode hosted|vendored --save-only` and a malformed forced identifier.
129+
Every usage error now exits 2.
103130
- **Human output:** warning lines no longer carry the `(code)` tag
104131
(`Warning: …`, `GC: skipped: …`); the codes stay in the JSON envelope.
105132
Error lines keep theirs (`Error (<code>): …`). Hosted mode is called "hosted", not "redirect", in human
@@ -502,9 +529,8 @@ into the new version's section — see docs/releasing.md.
502529
selected patch records are fetched into memory and every vendor-ledger entry
503530
carries `detached: true` plus the embedded `record` as its verification
504531
source, so a vendored project's footprint is `.socket/vendor/**` only. The
505-
former `--detached` opt-in is now the only vendored posture — the flag is
506-
hidden, accepted as a no-op for compatibility, and still a usage error
507-
without vendored mode. JSON uses the detached download vocabulary for both
532+
former `--detached` opt-in is now the only vendored posture, and the flag
533+
itself is removed (see "Removed"). JSON uses the detached download vocabulary for both
508534
commands (`downloaded: N`, `detached: true`, `patches[].action` =
509535
`downloaded` | `skipped` | `failed`). The vendor step vendors exactly what
510536
discovery selected — the "whole manifest is vendored" re-vendor from a

‎README.md‎

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -644,16 +644,15 @@ socket-patch scan [PATHS]... [options]
644644
|------|---------|-------------|
645645
| `--mode <hosted\|vendored\|agent>` | — | Selects one of the three [patch modes](#three-patch-modes) (default: `hosted`). Combining `--mode` with a legacy boolean flag of a *different* mode is an error (exit 2); the same mode spelled both ways is accepted. |
646646
| `--package <name\|purl>` | `SOCKET_SCAN_PACKAGES` | Only scan these packages: a name (`lodash`, `@scope/pkg`, `requests`; case-insensitive) or a purl with or without its version (`pkg:npm/lodash`, `pkg:pypi/requests@2.31.0`). Repeat the flag or separate with commas. |
647-
| `--prune` | — | Agent-mode garbage collection after the scan: remove manifest entries for packages no longer present in the crawl (installed trees + lockfiles — a wiped `node_modules` alone doesn't prune lockfile-listed entries) and delete orphan blob/diff/package-archive files. [Vendored](#vendor) packages are exempt from the crawl-based prune, but a vendored entry whose dependency has left the lockfile is reverted. Ignored, with a `redirect_prune_ignored` warning, in hosted mode; without a mode the scan is report-only. |
647+
| `--prune` | — | Agent-mode garbage collection after the scan: remove manifest entries for packages no longer present in the crawl (installed trees + lockfiles — a wiped `node_modules` alone doesn't prune lockfile-listed entries) and delete orphan blob/diff-archive files (plus any legacy package archives). [Vendored](#vendor) packages are exempt from the crawl-based prune, but a vendored entry whose dependency has left the lockfile is reverted. Ignored, with a `redirect_prune_ignored` warning, in hosted mode; without a mode the scan is report-only. |
648648
| `--sync` | — | Shorthand for `--mode agent --prune`: the one-flag agent-mode auto-update run. |
649649
| `--batch-size <n>` | `SOCKET_BATCH_SIZE` | Packages per API request (default: `500` on the authenticated API, `100` on the public proxy). A request whose body would exceed 256 KiB is split into smaller ones. |
650650
| `--all-releases` | `SOCKET_ALL_RELEASES` | Store patches for every release/distribution variant, not just the installed one — PyPI wheel/sdist, RubyGems platform, Maven classifier. Makes the manifest portable across environments (e.g. cross-platform CI caches). |
651651
| `--vex <path>` | `SOCKET_VEX` | On a successful scan, also write an OpenVEX 0.2.0 document to this path. See [Inline VEX](#inline-vex-on-apply--scan--vendor). |
652652
| `--vex-product`, `--vex-no-verify`, `--vex-doc-id`, `--vex-compact` | `SOCKET_VEX_*` | Passthrough to the embedded VEX builder; mirror the standalone [`vex`](#vex) knobs. Inert unless `--vex` is set. |
653653
654654
> Deprecated, hidden spellings (still accepted): `--apply` (== `--mode agent`) and
655-
> `--vendor` (== `--mode vendored`). `--detached` is a hidden no-op kept for compatibility (vendored mode is
656-
> always manifest-free); it is still an error without vendored mode.
655+
> `--vendor` (== `--mode vendored`).
657656
658657
**Examples:**
659658
```bash
@@ -901,7 +900,6 @@ socket-patch get <identifier> [options]
901900
| `--ghsa` | — | Force identifier to be treated as a GHSA ID. |
902901
| `-p, --package` | — | Force identifier to be treated as a package name. |
903902
| `--save-only` | `SOCKET_SAVE_ONLY` | Download the patch without applying it (alias: `--no-apply`). |
904-
| `--one-off` | `SOCKET_ONE_OFF` | Reserved (hidden from `--help`): apply the patch immediately without saving to the `.socket` folder. **Not yet implemented** — the command currently errors up front. |
905903
| `--all-releases` | `SOCKET_ALL_RELEASES` | Download patches for every release/distribution variant of a matched package (PyPI wheel/sdist, RubyGems platform, Maven classifier), not just the installed one. |
906904
| `--mode <hosted\|vendored\|agent>` | — | How to consume the patch; the same modes as `scan --mode` (default: `agent`). |
907905
@@ -1020,7 +1018,6 @@ socket-patch rollback [targets]... [options]
10201018
| Flag | Env var | Description |
10211019
|------|---------|-------------|
10221020
| `--preserve-state` | `SOCKET_PRESERVE_STATE` | Unpatch the system but keep the local patch state — manifest entries, vendored artifacts + ledger entries — for a later re-apply, and skip GC. Hosted patches have no preservable state (the lockfile is their only record) and are restored to upstream either way. |
1023-
| `--one-off` | `SOCKET_ONE_OFF` | Reserved: rollback by fetching original (`beforeHash`) files from the API, no manifest required. **Not yet implemented** — the command currently errors up front. |
10241021
10251022
**Examples:**
10261023
```bash

0 commit comments

Comments
 (0)